This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Oyodomo.com Redirect [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just noticed when I open IE10, the page I want is shown but a few moments pass and a pop up appears with oyodomo.com in the URL, then I get redirected to a similar page of my search.


I followed the instructions for posting a new topic in Virus, Spyware & Malware Removal and the test results are below.

Thanks in advanced for your help.

Mark

OTL logfile created on: 7/28/2013 11:52:59 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.52 Gb Available Physical Memory | 29.93% Memory free
3.46 Gb Paging File | 1.43 Gb Available in Paging File | 41.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 199.85 Gb Free Space | 70.13% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mark Hudson\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
PRC - C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Wajam)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
PRC - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Mark Hudson\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\83cfe0422e7e54f3f00107c15a63f1b4\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6da2afd0e57708d41892d9d3e32ba5a3\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f3770f9a13d7516e4c03f23dbd319cba\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\4572de8445038600e4552429b18fbe32\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7546a01feb9d477570b883eec56cc673\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\112f6448b7434699af4bcc05f25ce12b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\64b92e2a22bb8c1e86486bd22828acc5\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c1c41a9e1a25999e74defafecb2aa0bc\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\89445d5b924ad94744d00f1b6cd2285d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni.dll ()
MOD - C:\Program Files\Updater By SweetPacks\Extension32.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (Updater By SweetPacks) – C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (CxAudMsg) – C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (DefaultTabUpdate) – C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BingDesktopUpdate) – C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (WajamUpdater) – C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (CltMngSvc) – C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
SRV - (DefaultTabSearch) – C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe ()
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Neat Startup Service) – C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (UWS HiPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe (UltiDev LLC)
SRV - (UltiDev Web Server Pro) – C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe (UltiDev LLC)
SRV - (UWS LoPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe (UltiDev LLC)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NSL) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
SRV - (HP DS Service) – C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) – C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (tapklink) – C:\Windows\SysNative\drivers\tapklink.sys (Faveset LLC)
DRV:64bit: - (HPFXBULKLEDM) – C:\Windows\SysNative\drivers\hppdbulkio.sys (Hewlett Packard)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130727.004\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130727.004\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130726.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (lowpp) – C:\Windows\SysWOW64\drivers\lowpp.sys (Lowrance Electronics, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st;…7-0015830B13C0}
IE - HKLM\..\URLSearchHook: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://www.google.com
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com/?src=6&q;={…7-0015830B13C0}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\URLSearchHook: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://www.google.com
IE - HKCU\..\SearchScopes\{524497EB-7C75-4E81-88FB-A2EC225B518F}: "URL" = http://websearch.ask.com/redirect?client=i…66-F51B977C8DCB
IE - HKCU\..\SearchScopes\{8F1D75D1-7330-47BD-B5C8-C3BE1BAC82C8}: "URL" = http://search.conduit.com/ResultsExt.aspx?…amp;SSPV=TB_TIS
IE - HKCU\..\SearchScopes\{9001ECE5-27F9-7260-292B-CF945347FC97}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{ABD93EAF-D775-BC54-E63B-2804F22FD156}: "URL" = http://search.startnow.com/s/?q={searchTer…eferrer:source}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver;=1
IE - HKCU\..\SearchScopes\{C249B982-FC65-4460-98A6-ED6C092FD5FB}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
IE - HKCU\..\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com?src=6&q;={s…10045&st;=23
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..CT3241284.browser.search.defaultthis.engineName: "true"
FF - prefs.js..CT3289847.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaultthis.engineName: "WhiteSmoke New Customized Web Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://start.sweetpacks.com/?src=10&st;=12&crg;=3.5000006.10045&barid;={52F3DEE3-EFBE-11E2-BB67-0015830B13C0}"
FF - prefs.js..extensions.enabledAddons: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}:10.15.0.62
FF - prefs.js..extensions.enabledAddons: {739df940-c5ee-4bab-9d7e-270894ae687a}:10.14.380.14
FF - prefs.js..keyword.URL: "http://start.sweetpacks.com/?src=2&st;=12&crg;=3.5000006.10045&barid;={52F3DEE3-EFBE-11E2-BB67-0015830B13C0}&q;="
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3241284&octid;=CT3241284&SearchSource;=61&CUI;=UN13223289111417098&UM;=2&UP;=SPCF07C048-B569-4361-AC9C-2FA13162CCD6"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Ask.com"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Search Spin Customized Web Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI;=UN19338413015765794&UM;=2&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3241284&SearchSource;=2&CUI;=UN13223289111417098&UM;=2&q;="
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX [2013/07/18 10:38:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/08/19 14:23:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\IPSFFPlgn\ [2013/04/23 00:02:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox [2013/07/18 10:38:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/13 10:22:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/13 10:22:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi [2013/05/02 14:21:44 | 000,037,909 | —- | M] ()

[2013/07/18 10:40:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions
[2011/06/23 10:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/07/18 10:40:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions
[2013/07/18 10:40:37 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/04/29 09:56:58 | 000,000,000 | —D | M] (WhiteSmoke New) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}
[2013/04/10 21:04:33 | 000,000,000 | —D | M] (Search Spin) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}
[2013/07/18 10:40:56 | 000,029,621 | —- | M] () (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\[removed]
[2013/07/18 10:36:38 | 000,196,269 | —- | M] () (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2012/10/19 09:47:24 | 000,002,299 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\askcom.xml
[2013/07/24 10:13:09 | 000,001,793 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Bing.xml
[2013/05/05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml
[2013/03/27 23:15:47 | 000,002,356 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\startnow.xml
[2013/07/18 10:26:04 | 000,000,514 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\sweetim.xml
[2012/10/02 14:48:34 | 000,002,385 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Web Search.xml
[2012/10/19 10:38:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/12/21 02:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/20 23:30:41 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: TopArcadeHits = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0\
CHR - Extension: RealDownloader = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: DefaultTab = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.19_0\
CHR - Extension: WhiteSmoke New = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\klibnahbojhkanfgaglnlalfkgpcppfi\10.16.70.501_0\
CHR - Extension: Skype Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\
CHR - Extension: SweetPacks Chrome Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.4.0.3_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Updater By SweetPacks) - {7D4F1959-3F72-49d5-8E59-F02F8AA6815D} - C:\Program Files\Updater By SweetPacks\Extension64.dll ()
O2:64bit: - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\win64\vbobho.dll (FreePriceAlerts.com)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Updater By SweetPacks) - {7D4F1959-3F72-49d5-8E59-F02F8AA6815D} - C:\Program Files\Updater By SweetPacks\Extension32.dll ()
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Mark Hudson\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll (FreePriceAlerts.com)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (Search Spin Toolbar) - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Search Spin Toolbar) - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Spin Toolbar) - {FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKCU..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup File not found
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKCU..\Run: [SearchProtect] C:\Users\Mark Hudson\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: hostpilot.com ([ARCpoint] https in Local intranet)
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} http://192.168.2.119/web/WebClient.cab (WebClient Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.gunbroker.com/WebResource.axd?d…230999680000000 (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F22A54D-AEDC-4C91-AD17-7CB0657B12F0}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BFF0016-01B7-4FE7-8946-570FA6A6F5DC}: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF9E37F2-B89B-4AA7-BFEE-EEB3BF7AD7F4}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{010c100c-adc8-11e2-a83d-0015830b13c0}\Shell - "" = AutoRun
O33 - MountPoints2\{010c100c-adc8-11e2-a83d-0015830b13c0}\Shell\AutoRun\command - "" = D:\LaunchU3.exe -a
O33 - MountPoints2\{36fc71e4-c8d2-11e0-875e-0015830b13c0}\Shell - "" = AutoRun
O33 - MountPoints2\{36fc71e4-c8d2-11e0-875e-0015830b13c0}\Shell\AutoRun\command - "" = D:\MInst.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.L263 - lcodc26x2.dll File not found
Drivers32: vidc.LEAD - LCODCCMP2.DLL File not found
Drivers32: vidc.LSCR - C:\Program Files (x86)\Common Files\RZPPTCodec\Codec\LCodcScr2.dll ()
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/24 11:21:34 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Malwarebytes
[2013/07/24 11:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/24 11:21:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/24 11:21:01 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/24 11:21:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/24 11:20:21 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Programs
[2013/07/23 16:52:42 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\NPE
[2013/07/18 15:09:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealZeal Soft
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\RZPPTCodec
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\RealZeal Soft
[2013/07/18 10:48:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIViewer
[2013/07/18 10:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIViewer
[2013/07/18 10:42:01 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2013/07/18 10:42:00 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Wajam
[2013/07/18 10:41:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wajam
[2013/07/18 10:41:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\DefaultTab
[2013/07/18 10:40:57 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\DefaultTab
[2013/07/18 10:40:43 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
[2013/07/18 10:40:30 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\TopArcadeHits
[2013/07/18 10:38:54 | 000,000,000 | —D | C] – C:\Program Files\Updater By SweetPacks
[2013/07/18 10:31:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetIM
[2013/07/18 10:26:52 | 000,000,000 | —D | C] – C:\Windows\SysWow64\jmdp
[2013/07/18 10:26:26 | 000,033,792 | —- | C] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[2013/07/18 10:26:26 | 000,000,000 | —D | C] – C:\Windows\SysWow64\ARFC
[2013/07/18 10:26:24 | 000,000,000 | —D | C] – C:\Windows\SysWow64\WNLT
[2013/07/11 14:35:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 14:35:31 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 14:35:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 14:35:29 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 14:35:28 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 14:35:28 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 14:35:28 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 14:35:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 14:35:28 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 14:35:24 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 14:35:23 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 14:35:23 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 14:35:21 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 11:00:42 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/11 11:00:42 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/11 11:00:40 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/11 11:00:39 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:59:26 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/07/10 22:08:27 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\{E1329CDF-0089-4C1A-8203-569D344EFC15}
[2013/07/09 22:48:19 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\{88AF779D-7D50-4883-A2FB-9F6C99632C30}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/28 11:48:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/28 11:44:00 | 000,000,288 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
[2013/07/28 11:35:01 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2013/07/28 11:34:01 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/28 11:13:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/28 10:35:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2013/07/27 16:34:15 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/27 10:07:40 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:06:01 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/27 09:57:55 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/27 09:57:55 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/27 09:46:19 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2013/07/24 11:21:11 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/23 10:27:35 | 000,797,524 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/23 10:27:35 | 000,674,654 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/23 10:27:35 | 000,125,872 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/23 10:27:00 | 000,020,992 | —- | M] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/22 12:20:29 | 000,000,358 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2013/07/22 12:20:29 | 000,000,139 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2013/07/22 12:10:02 | 000,000,018 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2013/07/18 15:09:18 | 000,002,805 | —- | M] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:05 | 026,710,528 | —- | M] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | M] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/16 22:01:33 | 000,001,732 | —- | M] () – C:\Users\Mark Hudson\Desktop\DvrClient.cfg
[2013/07/16 09:50:52 | 000,006,087 | —- | M] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/07/15 15:01:01 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/07/15 15:01:01 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/07/15 10:49:49 | 000,002,403 | —- | M] () – C:\Users\Mark Hudson\Desktop\Google Chrome.lnk
[2013/07/11 15:37:03 | 000,417,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/30 11:10:30 | 001,645,360 | —- | M] () – C:\Windows\SysNative\dmwu.exe
[2013/06/30 11:07:42 | 000,033,792 | —- | M] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/27 10:07:38 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:05:57 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/18 15:30:50 | 000,020,992 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/18 15:09:15 | 000,002,805 | —- | C] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:30 | 026,710,528 | —- | C] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | C] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/18 10:40:30 | 000,000,288 | —- | C] () – C:\Windows\tasks\TopArcadeHits.job
[2013/07/18 10:26:26 | 001,645,360 | —- | C] () – C:\Windows\SysNative\dmwu.exe
[2013/07/16 09:50:52 | 000,006,087 | —- | C] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/22 20:43:48 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/05/22 20:43:48 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/05/22 20:43:48 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/05/22 20:43:48 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/04/19 10:44:01 | 000,000,358 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2012/10/02 09:00:38 | 000,000,000 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\bibstats
[2012/09/07 08:12:25 | 000,001,940 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2012/09/04 16:02:25 | 000,060,304 | —- | C] () – C:\Users\Mark Hudson\g2mdlhlpx.exe
[2012/07/23 13:22:39 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2012/07/23 13:22:38 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2012/07/23 13:20:41 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2012/07/23 13:20:39 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2012/07/23 13:20:39 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2012/06/10 21:12:47 | 000,004,096 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\keyfile3.drm
[2012/03/27 22:35:43 | 000,000,139 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2012/03/27 22:34:52 | 000,000,018 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2012/02/19 17:31:33 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/02/09 18:20:06 | 000,102,912 | —- | C] () – C:\Windows\agent_x64.exe
[2011/11/17 15:12:42 | 000,000,247 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\kclientgui.ini
[2011/10/10 12:41:33 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/10/10 12:41:33 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/07/29 11:01:50 | 000,007,598 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\Resmon.ResmonCfg

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/02/19 16:39:25 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Babylon
[2013/01/14 20:09:30 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Canon
[2013/07/27 13:21:41 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Clip Art Collection
[2011/07/07 11:59:23 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013/07/18 10:40:57 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\DefaultTab
[2011/12/27 10:20:46 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\IrfanView
[2013/07/25 18:48:53 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\MyPhoneExplorer
[2012/02/09 18:34:40 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Neat
[2012/02/09 18:34:19 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Nuance
[2011/10/17 10:29:37 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\OpenCandy
[2011/07/07 12:14:06 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PDF Writer
[2013/06/21 22:35:09 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PPTRemote
[2013/06/26 21:04:03 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Samsung
[2013/04/29 10:02:45 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\SearchProtect
[2012/05/12 16:13:42 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\SmartDraw
[2013/05/15 18:09:28 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Strongvault
[2012/02/21 23:58:38 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Systweak
[2012/03/08 16:15:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\TaxCut
[2011/06/23 10:48:11 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Thunderbird
[2012/10/06 09:42:48 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Tific
[2012/03/21 09:50:21 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\WeatherBug
[2012/11/15 16:13:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\webex
[2012/03/27 10:14:31 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Winff

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 02:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 22:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 22:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 02:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 02:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 02:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 02:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2013/07/27 18:27:56 | 000,113,338 | —- | M] () MD5=94404E6BF55D3977A08C9CD3C3B2551F – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: EXPLORER.ZIP >
[2009/06/03 21:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012/06/02 06:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 20:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/05/17 18:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/29 00:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012/08/24 02:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2013/02/22 02:04:50 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_0d238c71808d94e7\iexplore.exe
[2012/05/17 17:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/10/08 03:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/06/11 23:41:27 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=2A5F565327BFD679EC5F790DC15BBF25 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2012/08/24 06:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013/04/05 00:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/06/11 19:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/06/11 19:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/02/21 23:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_177836c3b4ee56e2\iexplore.exe
[2012/06/02 04:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2013/05/16 20:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2013/02/21 23:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_17f703a2ce14129d\iexplore.exe
[2012/10/08 07:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/05/17 21:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012/08/24 05:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 21:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 07:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012/08/24 02:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/04/30 08:17:39 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/02/02 03:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 22:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013/05/16 22:02:08 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2011/10/17 10:35:25 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/06/28 20:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013/06/11 21:28:00 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Program Files\Internet Explorer\iexplore.exe
[2013/06/11 21:28:00 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2013/04/05 01:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/02/22 02:17:45 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=B21A57AA4CB928059A0C0C58A9E77A02 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_0da2595099b350a2\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/06/02 03:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 22:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/06/12 02:51:43 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=CA88A25280B1D85ED0BC26B042ABBCCF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2013/04/05 02:53:33 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2012/10/08 03:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 02:23:03 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2013/04/30 08:17:47 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2012/06/28 18:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/01/08 19:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/10/17 10:35:15 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/10/08 06:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/05/17 20:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.412.DMP >
[2013/07/28 11:35:28 | 003,849,852 | —- | M] () MD5=7C1462F4CCEAEBD2B8BCD7E7EE2A9743 – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\ErrMgmt\Queue\Incoming\SQ_{0F194DF1-0D0D-4D06-BAEA-66121915089E}\iexplore.exe.412.dmp
[2013/07/28 11:35:28 | 003,849,852 | —- | M] () MD5=7C1462F4CCEAEBD2B8BCD7E7EE2A9743 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.412.dmp
[2013/07/28 11:35:28 | 003,849,852 | —- | M] () MD5=7C1462F4CCEAEBD2B8BCD7E7EE2A9743 – C:\Users\All Users\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\ErrMgmt\Queue\Incoming\SQ_{0F194DF1-0D0D-4D06-BAEA-66121915089E}\iexplore.exe.412.dmp
[2013/07/28 11:35:28 | 003,849,852 | —- | M] () MD5=7C1462F4CCEAEBD2B8BCD7E7EE2A9743 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.412.dmp

< MD5 for: IEXPLORE.EXE.MUI >
[2011/10/17 10:35:16 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/10/17 10:35:26 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/04/30 08:17:50 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/04/30 08:17:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/04/30 08:17:50 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Users\Mark Hudson\AppData\Local\Temp\iexplore.exe.mui
[2013/04/30 08:17:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/04/30 08:17:50 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/07/28 11:50:05 | 000,257,726 | —- | M] () MD5=84F049B82C20042452004A16BDFC629A – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2013/05/10 02:57:30 | 000,558,879 | —- | M] () MD5=3679F8D3253DC110D1D8F2AE115EE00C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.DLL >
[2013/04/25 11:54:23 | 000,007,680 | —- | M] () MD5=89408795F143525890BBDA9281C42F45 – C:\Users\Mark Hudson\AppData\Local\Temp\nswF364.tmp\services.dll

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 02:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 02:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.JS >
[2013/06/20 11:12:52 | 000,001,083 | —- | M] () MD5=18272708A717583EBB2AE9712FDA65CD – C:\Program Files (x86)\Microsoft\BingDesktop\Apps\runtime\mocks\services.js
[2010/08/16 14:07:26 | 000,018,674 | —- | M] () MD5=7209830374F12E59D7802B687A5F0542 – C:\Program Files (x86)\Barnes & Noble\BNDesktopReader\HTML\js\services.js

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 02:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 02:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 02:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 02:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 02:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 02:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 02:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 02:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 02:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2011/03/30 05:13:11 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2013/07/27 09:46:19 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2011/09/19 10:15:31 | 000,000,040 | —- | M] () – C:\log.txt
[2005/09/23 01:39:38 | 000,894,976 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2013/07/27 09:46:37 | 1856,925,696 | -HS- | M] () – C:\pagefile.sys
[2012/02/19 16:39:55 | 000,000,237 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is ACC5-3247
Directory of C:\
07/14/2009 12:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\Program Files\UltiDev
06/28/2012 10:41 PM Web Server [\??\C:\Program Files (x86)\UltiDev\Web Server]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM All Users [C:\ProgramData]
07/14/2009 12:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:08 AM My Music [C:\Users\Default\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Mark Hudson
06/21/2011 04:40 PM Application Data [C:\Users\Mark Hudson\AppData\Roaming]
06/21/2011 04:40 PM Cookies [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Cookies]
06/21/2011 04:40 PM Local Settings [C:\Users\Mark Hudson\AppData\Local]
06/21/2011 04:40 PM My Documents [C:\Users\Mark Hudson\Documents]
06/21/2011 04:40 PM NetHood [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/21/2011 04:40 PM PrintHood [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/21/2011 04:40 PM Recent [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Recent]
06/21/2011 04:40 PM SendTo [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\SendTo]
06/21/2011 04:40 PM Start Menu [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Start Menu]
06/21/2011 04:40 PM Templates [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Mark Hudson\AppData\Local
06/21/2011 04:40 PM Application Data [C:\Users\Mark Hudson\AppData\Local]
06/21/2011 04:40 PM History [C:\Users\Mark Hudson\AppData\Local\Microsoft\Windows\History]
06/21/2011 04:40 PM Temporary Internet Files [C:\Users\Mark Hudson\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Mark Hudson\Documents
06/21/2011 04:40 PM My Music [C:\Users\Mark Hudson\Music]
06/21/2011 04:40 PM My Pictures [C:\Users\Mark Hudson\Pictures]
06/21/2011 04:40 PM My Videos [C:\Users\Mark Hudson\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
51 Dir(s) 216,535,425,024 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/09/12 15:07:55 | 000,000,221 | -HS- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/07 00:37:46 | 002,846,720 | —- | M] (微软中国) – C:\Users\Mark Hudson\Desktop\Southcross Cameras.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >







.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 12:54:24.66 on Sun 07/28/2013
Internet Explorer: 9.10.9200.16635
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1771.410 [GMT -5:00]
.
AV: Norton AntiVirus *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton AntiVirus *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
C:\Windows\system32\CxAudMsg64.exe
C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
C:\Program Files (x86)\Launch Manager\dsiwmis.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\Launch Manager\LMutilps32.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\Neat\exec\NeatStartupService.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe
C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\UltiDev\Web Server\UWS.AppHost.Clr2.AnyCpu.exe
C:\Program Files\UltiDev\Web Server\UWS.AppHost.Clr2.AnyCpu.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\MsSpellCheckingFacility.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Mark Hudson\Downloads\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.arcpointlabs.com/south-san-antonio
uDefault_Page_URL = hxxp://acer.msn.com
uSearch Bar = hxxp://www.google.com
mStart Page = hxxp://start.sweetpacks.com/?src=10&st;=12&crg;=3.5000006.10045&barid;={52F3DEE3-EFBE-11E2-BB67-0015830B13C0}
uSearchAssistant = hxxp://www.google.com
uURLSearchHooks: Search Spin Toolbar: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll
mURLSearchHooks: Search Spin Toolbar: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll
mWinlogon: Userinit=userinit.exe,
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll
BHO: MSS+ Identifier: {0e8a89ad-95d7-40eb-8d9d-083ef7066a01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\IPS\IPSBHO.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
BHO: Updater By SweetPacks: {7d4f1959-3f72-49d5-8e59-f02f8aa6815d} - C:\Program Files\Updater By SweetPacks\Extension32.dll
BHO: DefaultTab Browser Helper: {7f6afbf1-e065-4627-a2fd-810366367d01} - C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Wajam: {a7a6995d-6ee1-4fd1-a258-49395d5bf99c} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
BHO: TopArcadeHits Games: {a7a9d7e7-e0c0-4202-9f13-6a06bd073cda} - C:\Users\Mark Hudson\AppData\Local\TopArcadeHits\Toparcadehits.dll
BHO: FreePriceAlerts: {a7c0a55c-300e-4193-8fb5-5db8e6533d35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: SweetPacks Browser Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
BHO: Norton Safe Web Lite BHO: {f0da78e9-6b60-42fb-bc26-ef2cfb8c8ff3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
BHO: Search Spin Toolbar: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll
TB: Norton Safe Web Lite: {30ceeea2-3742-40e4-85dd-812bf1cbb83d} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
{ae07101b-46d4-4a98-af68-0333ea26e113}
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
TB: Search Spin Toolbar: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: SweetPacks Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
uRun: [Google Update] "C:\Users\Mark Hudson\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
uRun: [SearchProtect] C:\Users\Mark Hudson\AppData\Roaming\SearchProtect\bin\cltmng.exe
uRun: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
uRun: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
uRun: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: []
mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
mRun: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
dRun: [SearchProtect] \SearchProtect\bin\cltmng.exe
dRunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid}
StartupFolder: C:\Users\MARKHU~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ACERVC~1.LNK - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} - hxxp://192.168.2.119/web/WebClient.cab
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.gunbroker.com/WebResource.axd?d=Qydpf0KIwF1Fr6RRPI2vp09Qx7960W1PefrwdgTL1YWRWyUo6in6PN6VS7m59gst6zjhnPK4xtevtk
kiPAeNbVdLz1lm1BKvO-eVx_B2d1Lb7EFrywmMr-EfCQUqniwFPL_qr5-6LT50B9lSJqZDgme2Vksu6ajL4Qvm6a-2VX8ROm8K0&t;=634230999680000000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://labcorp.webex.com/client/WBXclient-T27L10NSP32EP1-13926/training/ieatgpc1.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
mASetup: Neat ADF Scanner 2008 - reg copy "HKLM\Software\Wow6432Node\The Neat Company\Neat ADF Scanner 2008" "HKCU\Software\The Neat Company\Neat ADF Scanner 2008" /s /f
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Updater By SweetPacks: {7D4F1959-3F72-49d5-8E59-F02F8AA6815D} - C:\Program Files\Updater By SweetPacks\Extension64.dll
BHO-X64: Updater By SweetPacks Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: FreePriceAlerts: {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\win64\vbobho.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
TB-X64: {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB-X64: {FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C} - No File
EB-X64: {21347690-EC41-4F9A-8887-1F4AEE672439} - No File
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\MARKHU~1\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://start.sweetpacks.com/?src=10&st;=12&crg;=3.5000006.10045&barid;={52F3DEE3-EFBE-11E2-BB67-0015830B13C0}
FF - prefs.js: keyword.URL - hxxp://start.sweetpacks.com/?src=2&st;=12&crg;=3.5000006.10045&barid;={52F3DEE3-EFBE-11E2-BB67-0015830B13C0}&q;=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}\plugins\np-mswmp.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a}\plugins\npConduitFirefoxPlugin.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}\plugins\np-mswmp.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}\plugins\npConduitFirefoxPlugin.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108317
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - acc5324700000000000000ff2f22a54d
FF - user.js: extensions.BabylonToolbar_i.hardId - acc5324700000000000000ff2f22a54d
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15389
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:39:41
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NAVx64\1404000.028\symds64.sys [2013-6-17 493656]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NAVx64\1404000.028\symefa64.sys [2013-6-17 1139800]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [2013-7-16 1393240]
R1 ccSet_NAV;Norton AntiVirus Settings Manager;C:\Windows\System32\drivers\NAVx64\1404000.028\ccsetx64.sys [2013-6-17 169048]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130726.001\IDSviA64.sys [2013-7-27 513184]
R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2011-3-30 22912]
R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2011-3-30 20328]
R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2011-3-30 62584]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NAVx64\1404000.028\ironx64.sys [2013-6-17 224416]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\NAVx64\1404000.028\symnets.sys [2013-6-17 433752]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-5-10 65640]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-3-30 203776]
R2 BingDesktopUpdate;Bing Desktop Update service;C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2013-6-20 173192]
R2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [2013-3-6 93984]
R2 CxAudMsg;Conexant Audio Message Service;C:\Windows\System32\CxAudMsg64.exe [2011-4-28 198784]
R2 DefaultTabUpdate;DefaultTabUpdate;C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [2013-7-18 107520]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2011-3-30 352336]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-4-28 868224]
R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584]
R2 HP DS Service;HP DS Service;C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [2010-10-27 13824]
R2 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-3-30 244624]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-7-24 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-7-24 701512]
R2 NAV;Norton AntiVirus;C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe [2013-6-17 144368]
R2 Neat Startup Service;Neat Startup Service;C:\Program Files (x86)\Neat\exec\NeatStartupService.exe [2012-12-7 6144]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
R2 NSL;Norton Safe Web Lite;C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe [2011-8-19 130000]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]
R2 RS_Service;Raw Socket Service;C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2011-3-30 260640]
R2 UltiDev Web Server Pro;UltiDev Web Server Pro;C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe [2012-5-9 64512]
R2 Updater By SweetPacks;Updater By SweetPacks;C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe [2013-7-18 188760]
R2 UWS HiPriv Services;UWS HiPriv Services;C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe [2012-5-9 48128]
R2 UWS LoPriv Services;UWS LoPriv Services;C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe [2012-5-9 44032]
R2 WajamUpdater;WajamUpdater;C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [2013-4-22 109064]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2011-3-30 8122368]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-3-30 290816]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-3-30 115216]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-4-23 138912]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-3-30 77424]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-7-24 25928]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2011-3-30 250984]
R3 tapklink;Klink Virtual Network Adapter;C:\Windows\System32\drivers\tapklink.sys [2011-10-23 31232]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2011-4-28 44672]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
R3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\System32\drivers\WSDPrint.sys [2009-7-13 23040]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 DefaultTabSearch;DefaultTabSearch;C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [2013-2-11 572928]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-29 136176]
S2 HP LaserJet Service;HP LaserJet Service;C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-27 145920]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-29 257416]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-1 183560]
S3 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-9-27 172912]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-29 136176]
S3 HPFXBULKLEDM;HPFXBULKLEDM;C:\Windows\System32\drivers\hppdbulkio.sys [2012-8-23 22040]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" –> C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-9-20 30785672]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-6-22 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2013-07-24 16:21:34 ——– d—–w- C:\Users\MARKHU~1\AppData\Roaming\Malwarebytes
2013-07-24 16:21:04 ——– d—–w- C:\PROGRA~3\Malwarebytes
2013-07-24 16:21:01 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys
2013-07-24 16:21:00 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-24 16:20:21 ——– d—–w- C:\Users\MARKHU~1\AppData\Local\Programs
2013-07-23 21:52:42 ——– d—–w- C:\Users\MARKHU~1\AppData\Local\NPE
2013-07-18 20:08:37 ——– d—–w- C:\Program Files (x86)\RealZeal Soft
2013-07-18 20:08:37 ——– d—–w- C:\Program Files (x86)\Common Files\RZPPTCodec
2013-07-18 15:48:15 ——– d—–w- C:\Program Files (x86)\AIViewer
2013-07-18 15:42:00 ——– d—–w- C:\Users\MARKHU~1\AppData\Local\Wajam
2013-07-18 15:41:28 ——– d—–w- C:\Program Files (x86)\Wajam
2013-07-18 15:41:11 ——– d—–w- C:\Program Files (x86)\DefaultTab
2013-07-18 15:40:57 ——– d—–w- C:\Users\MARKHU~1\AppData\Roaming\DefaultTab
2013-07-18 15:40:30 ——– d—–w- C:\Users\MARKHU~1\AppData\Local\TopArcadeHits
2013-07-18 15:38:54 ——– d—–w- C:\Program Files\Updater By SweetPacks
2013-07-18 15:31:37 ——– d—–w- C:\Program Files (x86)\SweetIM
2013-07-18 15:26:52 ——– d—–w- C:\Windows\SysWow64\jmdp
2013-07-18 15:26:26 33792 —-a-w- C:\Windows\System32\ImHttpComm.dll
2013-07-18 15:26:26 1645360 —-a-w- C:\Windows\System32\dmwu.exe
2013-07-18 15:26:26 ——– d—–w- C:\Windows\SysWow64\ARFC
2013-07-18 15:26:24 ——– d—–w- C:\Windows\SysWow64\WNLT
2013-07-11 16:00:45 9216 —-a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll
2013-07-11 16:00:45 571904 —-a-w- C:\Program Files\Windows Defender\MpClient.dll
2013-07-11 16:00:45 54784 —-a-w- C:\Program Files (x86)\Windows Defender\MpOAV.dll
2013-07-11 16:00:45 4608 —-a-w- C:\Program Files (x86)\Windows Defender\MsMpLics.dll
2013-07-11 16:00:45 392704 —-a-w- C:\Program Files (x86)\Windows Defender\MpClient.dll
2013-07-11 16:00:45 314880 —-a-w- C:\Program Files\Windows Defender\MpCommu.dll
2013-07-11 16:00:45 1011712 —-a-w- C:\Program Files\Windows Defender\MpSvc.dll
2013-07-11 16:00:42 624128 —-a-w- C:\Windows\System32\qedit.dll
2013-07-11 16:00:42 509440 —-a-w- C:\Windows\SysWow64\qedit.dll
2013-07-11 16:00:40 1887744 —-a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-11 16:00:39 1620480 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-11 15:59:48 1732608 —-a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-11 15:59:48 1393152 —-a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-11 15:59:48 1367040 —-a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 15:59:47 936448 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 15:59:47 1402880 —-a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-11 15:59:42 3153920 —-a-w- C:\Windows\System32\win32k.sys
2013-07-11 15:59:26 1643520 —-a-w- C:\Windows\System32\DWrite.dll
2013-07-11 15:59:25 1247744 —-a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-11 03:08:27 ——– d—–w- C:\Users\MARKHU~1\AppData\Local\{E1329CDF-0089-4C1A-8203-569D344EFC15}
2013-07-10 03:48:19 ——– d—–w- C:\Users\MARKHU~1\AppData\Local\{88AF779D-7D50-4883-A2FB-9F6C99632C30}
.
==================== Find3M ====================
.
2013-07-15 20:01:01 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-15 20:01:01 692104 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-06-17 22:04:48 177312 —-a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2013-06-11 23:43:37 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll
2013-06-11 23:42:58 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-06-11 23:42:58 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-06-11 23:26:20 2241024 —-a-w- C:\Windows\System32\wininet.dll
2013-06-11 23:25:16 3958784 —-a-w- C:\Windows\System32\jscript9.dll
2013-06-11 23:25:13 67072 —-a-w- C:\Windows\System32\iesetup.dll
2013-06-11 23:25:13 136704 —-a-w- C:\Windows\System32\iesysprep.dll
2013-06-11 22:51:45 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-06-11 22:50:58 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-07 03:22:18 2706432 —-a-w- C:\Windows\System32\mshtml.tlb
2013-06-07 02:37:52 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-05-23 05:25:28 1139800 —-a-w- C:\Windows\System32\drivers\NAVx64\1404000.028\symefa64.sys
2013-05-23 01:33:50 4659712 —-a-w- C:\Windows\SysWow64\Redemption.dll
2013-05-21 05:02:00 493656 —-a-w- C:\Windows\System32\drivers\NAVx64\1404000.028\symds64.sys
2013-05-16 05:02:14 796760 —-a-w- C:\Windows\System32\drivers\NAVx64\1404000.028\srtsp64.sys
2013-05-13 05:51:01 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 —-a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 —-a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 —-a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 —-a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 —-a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 —-a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 —-a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 —-a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 —-a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 —-a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 12:57:35.59 ===============






OTL Extras logfile created on: 7/28/2013 11:53:00 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.52 Gb Available Physical Memory | 29.93% Memory free
3.46 Gb Paging File | 1.43 Gb Available in Paging File | 41.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 199.85 Gb Free Space | 70.13% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [UWS_CLR1] – "C:\Program Files (x86)\UltiDev\Web Server\\UWS.InteractiveServer.Clr2x86.exe" "/path:%1" /port:0 /vdir:/ /dirbrowsing:yes (UltiDev LLC)
Directory [UWS_CLR2] – "C:\Program Files (x86)\UltiDev\Web Server\\UWS.InteractiveServer.Clr2AnyCPU.exe" "/path:%1" /port:0 /vdir:/ /dirbrowsing:yes (UltiDev LLC)
Directory [UWS_CLR4] – "C:\Program Files (x86)\UltiDev\Web Server\\UWS.InteractiveServer.Clr4AnyCPU.exe" "/path:%1" /port:0 /vdir:/ /dirbrowsing:yes (UltiDev LLC)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [UWS_CLR1] – "C:\Program Files (x86)\UltiDev\Web Server\\UWS.InteractiveServer.Clr2x86.exe" "/path:%1" /port:0 /vdir:/ /dirbrowsing:yes (UltiDev LLC)
Directory [UWS_CLR2] – "C:\Program Files (x86)\UltiDev\Web Server\\UWS.InteractiveServer.Clr2AnyCPU.exe" "/path:%1" /port:0 /vdir:/ /dirbrowsing:yes (UltiDev LLC)
Directory [UWS_CLR4] – "C:\Program Files (x86)\UltiDev\Web Server\\UWS.InteractiveServer.Clr4AnyCPU.exe" "/path:%1" /port:0 /vdir:/ /dirbrowsing:yes (UltiDev LLC)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{023227C2-138F-4F87-BF31-5CB51A789575}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{02756F77-7342-4339-90F9-3EB00D5974BB}" = lport=138 | protocol=17 | dir=in | app=system |
"{02B3034A-ED8E-4303-A812-6D55A2156529}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A63C339-6054-4314-9E5E-02E514876137}" = rport=138 | protocol=17 | dir=out | app=system |
"{0FB22F85-E9B9-418E-9C33-83F05DBA6A64}" = lport=445 | protocol=6 | dir=in | app=system |
"{1068D5DE-465C-4109-8841-BB74763CF770}" = lport=8784 | protocol=6 | dir=in | name=ultidev web server pro |
"{27A0FC73-90E1-4D5D-BAEA-0A96B3980583}" = rport=137 | protocol=17 | dir=out | app=system |
"{2E93DA86-95DA-427D-B8F8-8C310D904B53}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3F26400D-B54C-4BC7-9D8A-9C185238572E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4672D127-2570-430F-BE75-6C6F6886ED7A}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{47F5F1AA-92A9-474C-A953-7B88E015B3B3}" = lport=7756 | protocol=6 | dir=in | name=ultidev web server pro |
"{486DF1A6-B5BA-4D7C-94A2-12FD893DE4B5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5FB03A0E-5DEB-48C5-92E9-FD1C25A10D92}" = lport=10243 | protocol=6 | dir=in | app=system |
"{635FA051-69F2-4754-8AB5-94B784CF8803}" = lport=5677 | protocol=6 | dir=in | name=ultidev web server pro |
"{66DE9810-7C5D-4E61-B2CB-11F4BFCB289C}" = rport=139 | protocol=6 | dir=out | app=system |
"{6F9BBA09-4EDD-401E-850A-604B8BA58EE2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{8C085B03-6ADF-40CD-B101-CFA2673DE4BD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9549AC83-1143-4184-8D1C-43903A4CFC20}" = lport=137 | protocol=17 | dir=in | app=system |
"{9927C8A6-A25E-4842-AB41-A617B92C2AED}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9DD3E3C3-B898-4D0D-8BB2-2227C297DE17}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{A12260E1-D9CC-4E35-B192-6467F03DCEB8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BDC87095-181A-433C-B5DB-18A250AF9762}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C110136D-1772-459D-AA55-FBD0911CE0F3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C156432B-1497-48BD-A92A-0FCA73AE79F9}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{C4710494-E398-442D-A25B-13067A8E6090}" = rport=445 | protocol=6 | dir=out | app=system |
"{E692A24A-D9E0-44A0-92EA-9F3BB7F00FCE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ECD19249-2B35-4F49-9EA5-3D3C7C21FBA4}" = lport=56777 | protocol=6 | dir=in | name=ultidev web server pro |
"{EDB98539-FA0B-45E3-BA1E-02162DE233DF}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FA829B69-AF86-445D-8AE1-C4DA0104F1D8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FB8F2F8F-E46D-452F-96A7-3B2236C9E7BD}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0FA3CE53-AC7D-40CF-9087-E38B9107F4EA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0FAABB53-2DDC-4BC1-B45B-FE38BE0A445C}" = protocol=6 | dir=out | app=system |
"{1E3B4DE3-696A-4C06-9E25-0F9AA572F7FE}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{2571266D-CA26-491D-84A0-4991A4C1DDB6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{301C11CD-E8B5-4488-B78F-36D88F5D1A36}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{355EE929-3F75-434A-ACCB-2DB449697DA1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3D2E34B4-58FB-40DD-B788-3243AFB8435F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3EC5F082-8ABD-47FC-93B1-2A93BCBA4AA6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{43DE960F-927E-4DDA-BD39-BAC570D1DF32}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5013612F-C3DF-4C64-BDCA-EF8424535E67}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{528427D5-AC2E-4B63-9CA8-958B456DA2F2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{60519913-4EE5-4CB2-9F05-FEC89863BAD5}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{63624D0E-A46A-4239-B05E-E9E2D801A3B0}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6F178909-610F-4A2D-A798-46C69C53D049}" = protocol=17 | dir=in | app=c:\hp_si_965d0289-10e1-45ec-b11f-a60ac9ae8d4d\7zs1d66\installer\hpbcsiinstaller.exe |
"{7CC29D47-10C1-40DB-BD0F-74DBDC13B9DF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7EB81CD6-A9E0-4BDB-94B7-B1F509CFCC77}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7EEF5132-C0E6-4FEE-BD72-D837642427E8}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{8099B053-658E-48D3-BA14-7A3404E399A4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{895B4547-2DEB-446C-ACBB-F8EB6ABE66CF}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{8C6369CB-6C61-4A96-A34F-5F2DC0CFF611}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{915D6400-2985-497B-AF30-35C696F12E8A}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{919F161F-F51B-4C67-97FB-6BA090B743C4}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{92B32EEC-A685-48E4-8049-19400C41649D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9544C75C-588F-4222-9461-A6ED71571F79}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{97AAC169-0394-4D02-AF81-AB047E12C365}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{A4295107-F9D6-4C68-AB7D-A560B141176B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B346B6E9-982D-4217-A6FB-E0E59E27D257}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B91AF252-41B8-4E5F-BD77-71DAAC08F763}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C4ACE889-DA6E-4490-930A-F0B55801DB79}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{C8453550-FC3D-4F17-9C8A-E80F2F904DC6}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{CCD14719-0D2D-4A07-B91B-D74F3D8D6DFC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D4AB3ABA-056B-477F-8F73-C1A29CA4357F}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{D5180D9A-95A7-44E9-90C3-44F5F19B8B34}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{D6A6D1AA-4124-40AC-8C58-4FAEDFCFD817}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{DD0C7751-CB16-41AA-A758-1FD0806EFBAC}" = protocol=6 | dir=in | app=c:\hp_si_965d0289-10e1-45ec-b11f-a60ac9ae8d4d\7zs1d66\installer\hpbcsiinstaller.exe |
"{DD46F72A-FFB8-471D-8D35-EAE4005FECDB}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{E20AEB3E-7B07-408C-98DF-08C019EACBDE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E2AB218B-DB80-4562-AE66-F8A60D967046}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{E447C146-1B93-4688-A2FF-52982534D502}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{EC6F68C7-EE14-45E3-A074-2D30AD2F5C4F}" = dir=in | app=c:\program files (x86)\acer\acer vcm\rs_service.exe |
"{EE1D831D-E1C3-4E41-B0D9-E22AC12F740C}" = dir=in | app=c:\program files (x86)\acer\acer vcm\vc.exe |
"{F7BD5F41-9352-4FA5-BE79-DC08F2F6A8B0}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{FA68302A-B3CE-4518-A803-3EEA75E82D52}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"TCP Query User{02781703-226B-4BAC-A93B-84FAEA5DDA88}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{774F09B9-60E5-472C-A5FE-95E7FE8DA22B}C:\users\mark hudson\appdata\local\temp\yoicsconnect\yoicsconnect-x86.exe" = protocol=6 | dir=in | app=c:\users\mark hudson\appdata\local\temp\yoicsconnect\yoicsconnect-x86.exe |
"TCP Query User{DA52B9C0-97FF-4230-A544-DF1B36DFE8E6}C:\users\mark hudson\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\mark hudson\appdata\local\google\chrome\application\chrome.exe |
"TCP Query User{EAF18ECF-A865-48A0-BDC0-646AD5D7F591}C:\program files (x86)\ppt remote\pptremote.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ppt remote\pptremote.exe |
"UDP Query User{4FAC578B-174A-46B5-A6CC-35E8B3F22301}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{9A1AF63D-B8B2-4AEA-93F5-7A0332E54FA9}C:\program files (x86)\ppt remote\pptremote.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ppt remote\pptremote.exe |
"UDP Query User{BC99B93D-D0E1-40DD-900D-6EED5ECCA0A9}C:\users\mark hudson\appdata\local\temp\yoicsconnect\yoicsconnect-x86.exe" = protocol=17 | dir=in | app=c:\users\mark hudson\appdata\local\temp\yoicsconnect\yoicsconnect-x86.exe |
"UDP Query User{F7E46CB8-A3F3-41C2-9B9E-D0F9F1C164FA}C:\users\mark hudson\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\mark hudson\appdata\local\google\chrome\application\chrome.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2100_series" = Canon MG2100 series MP Drivers
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{37C766E1-E99B-2013-6919-379F3A84016E}" = WMV9/VC-1 Video Playback
"{4129CA8E-7E75-4eee-BAE5-AA7707AA7708}" = Canon MF4400 Series
"{4292776A-4F23-E108-83B2-2C27398E8BCF}" = ATI Catalyst Install Manager
"{4697255C-D5C6-D6C9-E096-7CC558199D87}" = ccc-utility64
"{5737101A-27C4-408A-8A57-D1DC78DF84B4}" = 64 Bit HP CIO Components Installer
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}_is1" = Updater By SweetPacks 2.0.0.608
"{7EA2D88A-C8B7-4102-8644-0A437B6FC143}" = Neat Mobile Scanner Driver
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A2BC7D4-A7D3-45D5-B3D2-394718C53C41}" = Neat ADF Scanner 2008 Driver
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}" = Microsoft SQL Server Native Client
"{A55F1206-BFA7-4027-92B8-CE4EFDBC3CF2}" = Neat ADF Scanner Driver
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B636C9B9-A3F2-4DCE-ADCC-72E095018385}" = Microsoft SQL Server VSS Writer
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D1108D4B-72F8-419F-88C5-ABB8DC09B3C7}" = Neat Mobile Scanner (Silver) Driver
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DC3381CB-10D4-431D-B9B3-7DB84B00645F}" = FreePriceAlerts 2.3.5
"{DDE25FC9-892D-4D24-9325-3BAA5C15ACA9}" = Neat Mobile Scanner 2008 Driver
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 7.2.0.1304
"CNXT_AUDIO_HDA" = Conexant HD Audio
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01F1591E-6496-FE89-75F0-51D9992A381C}" = CCC Help Russian
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"{020B8383-8F4E-4ADD-8D61-5ADEB1EBBC70}" = hppM175LaserJetService
"{03026BBB-B089-478C-2880-D8EA8563DB3E}" = CCC Help Chinese Standard
"{03CB6116-BE2E-D1E6-9B5D-68EA24C3E561}" = CCC Help Swedish
"{04182C2A-1DAD-C2AF-ACEE-200758F8FAE3}" = ccc-core-static
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{141B1D71-D320-0AB2-AAFB-3132F27A004D}" = Catalyst Control Center InstallProxy
"{158104AB-D92E-45BC-8268-5D351C95F6AD}" = Clip Art Collection
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19542156-285B-458C-994D-2A21889001DF}" = HPLaserJet100ColorMFPM175_HelpLearnCenter_SI
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}" = Bing Bar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{229D6185-BD7E-494B-A73B-C5215BE0690E}" = HPLJUT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{297F0B9D-CB90-1E15-084B-F433F37B5EF8}" = CCC Help Thai
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{3C87F2A9-639E-33C7-AE09-FF86B6FAFEF6}" = CCC Help Greek
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{491ADA37-04EE-2ECE-9F86-DDC0106047AC}" = Times Reader
"{49EF2D49-3171-E160-13FD-F7E8C51E197E}" = CCC Help Polish
"{4DBD79A4-0A02-4E26-8102-EB142EE52F58}" = SprinxCRM
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{4F05AC7F-63EE-DB64-C863-FA3CAD346893}" = CCC Help Hungarian
"{50732772-D6E1-9C37-C056-73CEB6FD32DE}" = CCC Help Spanish
"{50F74F5A-EF47-CEB5-C887-96E30144208B}" = CCC Help Norwegian
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5FFA2820-C030-F2A5-3BFB-7EB2ABAB90F1}" = Catalyst Control Center Graphics Previews Common
"{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}" = newsXpresso
"{621F8F71-4D04-4862-A258-D4895DE676D6}" = hppLaserJetService
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{6767DFEE-8909-453A-B553-C7693912B2EB}" = Canon MF Toolbox 4.9.1.1.mf11
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6D2A900D-EB39-3386-8D9F-3B8F069C57A5}" = Google Talk Plugin
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{708A6AC6-03EC-11D5-AA9A-00C0DF245F7E}" = FloorPlan 3D v7
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App (Acer Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7330262C-0A1C-4B3B-ACFF-7EEC5BF65CCF}" = H&R; Block Deluxe + Efile 2011
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{76362863-572A-0592-E2B2-B1CB7CC8E85D}" = CCC Help Portuguese
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BC00AC5-47B4-C1D0-07E2-F50D79565226}" = CCC Help Danish
"{7C891636-F91F-4B74-8919-A7DDC0DDF764}" = ToolboxProxy
"{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}" = Bing Desktop
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{8190F7B6-BFCE-4F60-8670-59F1709BFF9F}" = Catalyst Control Center - Branding
"{82AD8F8E-B613-42C2-A85A-F8C23F28E1E2}_is1" = Wallpaper Changer Installer
"{82B5618C-75E8-52ED-9F03-44E26AC32611}" = CCC Help Japanese
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8C8292F3-7D93-4D40-9738-B24165D7E7CD}_is1" = AI Viewer
"{8D7330B0-8CAC-4B44-A6ED-AFAA004B3974}" = MapCreate 6
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8DF7FD9F-1248-0DFD-18A7-C192909FEF21}" = CCC Help French
"{8F9AD9CF-0FF9-4723-A946-B4C9F76E7DFA}" = UltiDev Web Server Pro
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{919B2CAA-1047-48E6-B7BF-C218796303E9}" = PPT Remote
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{945A6A95-5209-70AE-C6FC-6FA468DF00B8}" = CCC Help Finnish
"{94D643DE-8288-BC80-8BD8-8D04F30169D7}" = CCC Help Italian
"{95054BE0-C381-3334-CED1-B706ADE954BD}" = CCC Help Dutch
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{965D0289-10E1-45ec-B11F-A60AC9AE8D4D}" = HP LaserJet 100 color MFP M175
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{9767CBB5-2A81-427D-8F05-497737D56AA0}" = hpbDSService
"{99432E4C-1189-4887-9D75-DAA796015FFD}" = Neat Core Files
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A5949B71-46FB-43F3-8852-4E74D9FC7564}" = hpbM175DSService
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A82D0C46-EBDF-4B27-A731-D06EF2056E81}" = HP FWUpdateEDO3
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)
"{AF1DE214-DD95-0EDE-F573-3A219AE9850D}" = CCC Help Czech
"{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}" = RealDownloader
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{C2530D63-B66B-48B5-BB50-7C6281FE7AA6}" = Brother MFL-Pro Suite MFC-7220
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C3529014-BB16-4933-83FE-9BC9D79619F5}" = HP LJ100 M175 HP Scan
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C84CCA99-1E54-C443-0A6C-AB32954EA785}" = CCC Help Korean
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{C8FB74E8-AD41-01F1-4265-11F4F9FA02F5}" = CCC Help Chinese Traditional
"{C9B4E19B-FBC2-51FF-C390-B251D2AA7E57}" = CCC Help English
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1BD4EEC-8C99-4E83-B7DE-AE10F9D8D5B6}" = InstanceFinder
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E062BB1F-6F04-4543-3FB4-58489D9552E0}" = CCC Help German
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{EAD033C2-EB20-A100-41FB-12371D707E83}" = Catalyst Control Center Localization All
"{EB78B192-FBE7-4CCD-A7A6-FF4E6F88CEA1}" = RZPowerPointConverter
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F4E33CE5-A7AB-4F68-A7E7-F0AA84EF2D9E}" = Internet Explorer Toolbar 4.9 by SweetPacks
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 4.65
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"ActiveTouchMeetingClient" = Cisco WebEx Meetings
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"BabylonToolbar" = Babylon toolbar on IE
"BN_DesktopReader" = NOOK for PC
"Business-in-a-Box" = Business-in-a-Box
"Canon MG2100 series On-screen Manual" = Canon MG2100 series On-screen Manual
"Canon MG2100 series User Registration" = Canon MG2100 series User Registration
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CKZ Time Clock" = CKZ Time Clock 4.12.03
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader
"DefaultTab" = DefaultTab
"DomaIQ Uninstaller" = DomaIQ
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Faveset Klink" = Faveset Klink
"freeocr_is1" = FreeOCR v4.2
"GoVisual Diagram Editor_is1" = GoVisual Diagram Editor 1.3
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"Identity Card" = Identity Card
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}" = newsXpresso
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"IrfanView" = IrfanView (remove only)
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"Mozilla Thunderbird 11.0.1 (x86 en-US)" = Mozilla Thunderbird 11.0.1 (x86 en-US)
"MP Navigator EX 5.0" = Canon MP Navigator EX 5.0
"MPE" = MyPhoneExplorer
"NAV" = Norton AntiVirus
"Neat" = Neat
"NST" = Norton Safe Web Lite
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"RealPlayer 16.0" = RealPlayer
"Search_Spin Toolbar" = Search Spin Toolbar
"SearchProtect" = Search Protect by conduit
"Wajam" = Wajam
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.10 (32-bit)
"WNLT" = SweetPacks Updater Service
"WTA-02e95d1c-90f8-410b-b360-b5d2d8f411c4" = Diner Dash 2 Restaurant Rescue
"WTA-1b24e505-a6a1-4989-9c48-0b6ad019523d" = Agatha Christie - 4:50 from Paddington
"WTA-1eb4cc37-7941-4a1f-a069-6bccd265d5f4" = Bejeweled 2 Deluxe
"WTA-2432f49a-f212-48d9-87dd-697db80a0869" = Chuzzle Deluxe
"WTA-2cbc85c2-a0e2-4e1a-9b62-17d269f79efa" = Jewel Quest Heritage
"WTA-374b19d1-b6ee-4a90-85c7-9612f7efea58" = Virtual Villagers 4 - The Tree of Life
"WTA-3dae70eb-11f7-428c-87e4-47baa2ffe0b2" = FATE - The Traitor Soul
"WTA-41a32dfd-32b2-4fe3-b22a-ed3e5c8aff51" = Final Drive: Nitro
"WTA-4a7cd701-efe3-4a10-a29b-976069c87155" = Penguins!
"WTA-594dd252-4e24-4ea4-adcc-8212e3e8a17b" = Dora's World Adventure
"WTA-5981e280-31a3-4293-b892-5808a3f69c61" = Mystery P.I. - Stolen in San Francisco
"WTA-99e0dd4d-6d27-4686-88bc-bca7e0c8f38e" = Plants vs. Zombies - Game of the Year
"WTA-aaf37107-18c0-4e68-bee2-054bc68daf81" = Polar Bowler
"WTA-affedb24-f4c5-4047-bf48-0ad5313bec30" = Namco All-Stars: PAC-MAN
"WTA-b54baf62-9e83-4c62-bfa7-3f3f47bfcb14" = Zuma's Revenge
"WTA-cb31b00b-39c6-4ee9-8da3-711d720c152c" = Polar Golfer
"WTA-d586dfb6-c417-4d1d-abb7-06d49f7fff7c" = Torchlight
"WTA-ddb69d8f-0c46-44f7-a575-b3125c308492" = Poker Superstars III
"WTA-e837fa67-143d-4cb2-89cd-27d15bb0c4ff" = Build-a-lot 2
"xvid" = Xvid MPEG-4 Video Codec
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{C1C3E833-420E-4D78-9BA7-86AEBB272384}" = TopArcadeHits
"be747e9c9e2e034e" = Intermedia Single Sign-On
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 5.4.0.1082
"MyFreeCodec" = MyFreeCodec

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/27/2013 10:47:51 AM | Computer Name = MarkHudson-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Faulting module name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Exception code: 0xc0000005 Fault offset: 0x00002c60 Faulting
process id: 0x56c Faulting application start time: 0x01ce8ad839add551 Faulting application
path: C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe Faulting module path:
C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe Report Id: 82a426bb-f6cb-11e2-bce8-0015830b13c0

Error - 7/27/2013 10:48:15 AM | Computer Name = MarkHudson-PC | Source = HPLaserJetService | ID = 0
Description = Service cannot be started. The service process could not connect to
the service controller

Error - 7/27/2013 10:49:28 AM | Computer Name = MarkHudson-PC | Source = WinMgmt | ID = 10
Description =

Error - 7/27/2013 11:15:26 AM | Computer Name = MarkHudson-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 7/27/2013 2:15:49 PM | Computer Name = MarkHudson-PC | Source = Application Error | ID = 1000
Description = Faulting application name: PmmUpdate.exe, version: 1.1.36.0, time
stamp: 0x4c932097 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x00627113 Faulting process id: 0x920 Faulting application
start time: 0x01ce8ad8501dadc1 Faulting application path: C:\Program Files (x86)\EgisTec
IPS\PmmUpdate.exe Faulting module path: unknown Report Id: 9017cdd1-f6e8-11e2-bce8-0015830b13c0

Error - 7/27/2013 2:26:27 PM | Computer Name = MarkHudson-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 7/28/2013 11:37:05 AM | Computer Name = MarkHudson-PC | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 7/28/2013 12:35:17 PM | Computer Name = MarkHudson-PC | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16635,
time stamp: 0x51b7a921 Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x7449e2d4 Faulting process id:
0x19c Faulting application start time: 0x01ce8bb05b643e30 Faulting application path:
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: unknown
Report
Id: af72a4d4-f7a3-11e2-bce8-0015830b13c0

Error - 7/28/2013 12:39:18 PM | Computer Name = MarkHudson-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1d80 Start
Time: 01ce8bb049af7db9 Termination Time: 0 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 7/28/2013 12:40:46 PM | Computer Name = MarkHudson-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1acc Start
Time: 01ce8bb100c89aa4 Termination Time: 0 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

[ System Events ]
Error - 7/27/2013 2:14:50 PM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 7/27/2013 3:15:55 PM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 7/27/2013 4:16:59 PM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 7/27/2013 5:17:03 PM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 7/27/2013 7:13:34 PM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 7/27/2013 10:45:19 PM | Computer Name = MarkHudson-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the NSL service.

Error - 7/27/2013 10:45:28 PM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 7/27/2013 10:46:46 PM | Computer Name = MarkHudson-PC | Source = DCOM | ID = 10010
Description =

Error - 7/28/2013 10:47:56 AM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 7/28/2013 11:48:01 AM | Computer Name = MarkHudson-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.


< End of report >


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:50:54 PM, on 7/28/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Mark Hudson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y0VM3S91\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st;…7-0015830B13C0}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Spin Toolbar - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (file missing)
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\IPS\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: Updater By SweetPacks Helper - {7D4F1959-3F72-49d5-8E59-F02F8AA6815D} - C:\Program Files\Updater By SweetPacks\Extension32.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
O2 - BHO: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Mark Hudson\AppData\Local\TopArcadeHits\Toparcadehits.dll
O2 - BHO: FreePriceAlerts - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O2 - BHO: Norton Safe Web Lite BHO - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O2 - BHO: Search Spin - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Norton Safe Web Lite - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: Search Spin Toolbar - {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} - C:\Program Files (x86)\Search_Spin\prxtbSear.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
O4 - HKLM\..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Mark Hudson\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [SearchProtect] C:\Users\Mark Hudson\AppData\Roaming\SearchProtect\bin\cltmng.exe
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKUS\S-1-5-18\..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [SearchProtect] \SearchProtect\bin\cltmng.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} (WebClient Control) - http://192.168.2.119/web/WebClient.cab
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} (Image Uploader Control) - http://www.gunbroker.com/WebResource.axd?d…230999680000000
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: DefaultTabSearch - Unknown owner - C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe
O23 - Service: DefaultTabUpdate - Unknown owner - C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP DS Service - Hewlett-Packard Company - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe
O23 - Service: Neat Startup Service - The Neat Company - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: Norton Safe Web Lite (NSL) - Symantec Corporation - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: UltiDev Web Server Pro - UltiDev LLC - C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe
O23 - Service: Updater By SweetPacks - Unknown owner - C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
O23 - Service: UWS HiPriv Services - UltiDev LLC - C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe
O23 - Service: UWS LoPriv Services - UltiDev LLC - C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: WajamUpdater - Wajam - C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 18591 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, mwh986

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello,

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

Download TDSSKiller.exe and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

===================================================

On your next reply please post :
aswMBR log
MBR.dat (attachment)
TDSS Killer log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Conspire,

Thanks for the assistance on this issue. I appreciate your time and skills.

As requested you will find the following attached:

aswMBR log
MBR.dat (attachment)
TDSS Killer log (Returned No Threats)

Thanks Again.

Mark

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-07-29 20:44:14
—————————–
20:44:14.448 OS Version: Windows x64 6.1.7601 Service Pack 1
20:44:14.448 Number of processors: 2 586 0x100
20:44:14.448 ComputerName: MARKHUDSON-PC UserName: Mark Hudson
20:44:41.280 Initialize success
20:47:51.128 AVAST engine defs: 13072901
20:47:58.272 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:47:58.272 Disk 0 Vendor: Hitachi_HTS545032B9A300 PB3OC60F Size: 305245MB BusType: 11
20:47:58.428 Disk 0 MBR read successfully
20:47:58.444 Disk 0 MBR scan
20:47:58.522 Disk 0 Windows 7 default MBR code
20:47:58.553 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048
20:47:58.584 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024
20:47:58.600 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 291831 MB offset 27469824
20:47:58.740 Disk 0 scanning C:\Windows\system32\drivers
20:48:20.596 Service scanning
20:49:33.511 Modules scanning
20:49:33.526 Disk 0 trace - called modules:
20:49:33.542
20:49:34.587 AVAST engine scan C:\Windows
20:49:39.251 AVAST engine scan C:\Windows\system32
20:56:40.390 AVAST engine scan C:\Windows\system32\drivers
20:57:20.248 AVAST engine scan C:\Users\Mark Hudson
21:01:35.324 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:01:35.339 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-07-29 20:44:14
—————————–
20:44:14.448 OS Version: Windows x64 6.1.7601 Service Pack 1
20:44:14.448 Number of processors: 2 586 0x100
20:44:14.448 ComputerName: MARKHUDSON-PC UserName: Mark Hudson
20:44:41.280 Initialize success
20:47:51.128 AVAST engine defs: 13072901
20:47:58.272 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:47:58.272 Disk 0 Vendor: Hitachi_HTS545032B9A300 PB3OC60F Size: 305245MB BusType: 11
20:47:58.428 Disk 0 MBR read successfully
20:47:58.444 Disk 0 MBR scan
20:47:58.522 Disk 0 Windows 7 default MBR code
20:47:58.553 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048
20:47:58.584 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024
20:47:58.600 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 291831 MB offset 27469824
20:47:58.740 Disk 0 scanning C:\Windows\system32\drivers
20:48:20.596 Service scanning
20:49:33.511 Modules scanning
20:49:33.526 Disk 0 trace - called modules:
20:49:33.542
20:49:34.587 AVAST engine scan C:\Windows
20:49:39.251 AVAST engine scan C:\Windows\system32
20:56:40.390 AVAST engine scan C:\Windows\system32\drivers
20:57:20.248 AVAST engine scan C:\Users\Mark Hudson
21:01:35.324 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:01:35.339 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"
21:01:53.850 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:01:53.897 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-07-29 20:44:14
—————————–
20:44:14.448 OS Version: Windows x64 6.1.7601 Service Pack 1
20:44:14.448 Number of processors: 2 586 0x100
20:44:14.448 ComputerName: MARKHUDSON-PC UserName: Mark Hudson
20:44:41.280 Initialize success
20:47:51.128 AVAST engine defs: 13072901
20:47:58.272 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:47:58.272 Disk 0 Vendor: Hitachi_HTS545032B9A300 PB3OC60F Size: 305245MB BusType: 11
20:47:58.428 Disk 0 MBR read successfully
20:47:58.444 Disk 0 MBR scan
20:47:58.522 Disk 0 Windows 7 default MBR code
20:47:58.553 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048
20:47:58.584 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024
20:47:58.600 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 291831 MB offset 27469824
20:47:58.740 Disk 0 scanning C:\Windows\system32\drivers
20:48:20.596 Service scanning
20:49:33.511 Modules scanning
20:49:33.526 Disk 0 trace - called modules:
20:49:33.542
20:49:34.587 AVAST engine scan C:\Windows
20:49:39.251 AVAST engine scan C:\Windows\system32
20:56:40.390 AVAST engine scan C:\Windows\system32\drivers
20:57:20.248 AVAST engine scan C:\Users\Mark Hudson
21:01:35.324 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:01:35.339 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"
21:01:53.850 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:01:53.897 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"
21:02:03.091 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:02:03.137 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-07-29 20:44:14
—————————–
20:44:14.448 OS Version: Windows x64 6.1.7601 Service Pack 1
20:44:14.448 Number of processors: 2 586 0x100
20:44:14.448 ComputerName: MARKHUDSON-PC UserName: Mark Hudson
20:44:41.280 Initialize success
20:47:51.128 AVAST engine defs: 13072901
20:47:58.272 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
20:47:58.272 Disk 0 Vendor: Hitachi_HTS545032B9A300 PB3OC60F Size: 305245MB BusType: 11
20:47:58.428 Disk 0 MBR read successfully
20:47:58.444 Disk 0 MBR scan
20:47:58.522 Disk 0 Windows 7 default MBR code
20:47:58.553 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048
20:47:58.584 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024
20:47:58.600 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 291831 MB offset 27469824
20:47:58.740 Disk 0 scanning C:\Windows\system32\drivers
20:48:20.596 Service scanning
20:49:33.511 Modules scanning
20:49:33.526 Disk 0 trace - called modules:
20:49:33.542
20:49:34.587 AVAST engine scan C:\Windows
20:49:39.251 AVAST engine scan C:\Windows\system32
20:56:40.390 AVAST engine scan C:\Windows\system32\drivers
20:57:20.248 AVAST engine scan C:\Users\Mark Hudson
21:01:35.324 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:01:35.339 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"
21:01:53.850 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:01:53.897 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"
21:02:03.091 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:02:03.137 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"
21:03:04.351 Disk 0 MBR has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\MBR.dat"
21:03:04.382 The log file has been saved successfully to "C:\Users\Mark Hudson\Documents\Spa - Copy\aswMBR.txt"


21:12:21.0899 7952 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:12:22.0538 7952 ============================================================
21:12:22.0538 7952 Current date / time: 2013/07/29 21:12:22.0538
21:12:22.0538 7952 SystemInfo:
21:12:22.0538 7952
21:12:22.0538 7952 OS Version: 6.1.7601 ServicePack: 1.0
21:12:22.0538 7952 Product type: Workstation
21:12:22.0538 7952 ComputerName: MARKHUDSON-PC
21:12:22.0538 7952 UserName: Mark Hudson
21:12:22.0538 7952 Windows directory: C:\Windows
21:12:22.0538 7952 System windows directory: C:\Windows
21:12:22.0538 7952 Running under WOW64
21:12:22.0538 7952 Processor architecture: Intel x64
21:12:22.0538 7952 Number of processors: 2
21:12:22.0538 7952 Page size: 0x1000
21:12:22.0538 7952 Boot type: Normal boot
21:12:22.0538 7952 ============================================================
21:12:25.0003 7952 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:12:25.0050 7952 Drive \Device\Harddisk1\DR1 - Size: 0x3D680000 (0.96 Gb), SectorSize: 0x200, Cylinders: 0x7D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:12:25.0066 7952 ============================================================
21:12:25.0066 7952 \Device\Harddisk0\DR0:
21:12:25.0066 7952 MBR partitions:
21:12:25.0066 7952 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1A00800, BlocksNum 0x32000
21:12:25.0066 7952 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1A32800, BlocksNum 0x239FB800
21:12:25.0066 7952 \Device\Harddisk1\DR1:
21:12:25.0066 7952 MBR partitions:
21:12:25.0066 7952 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x6, StartLBA 0xF3, BlocksNum 0x1EB30D
21:12:25.0066 7952 ============================================================
21:12:25.0112 7952 C: <-> \Device\Harddisk0\DR0\Partition2
21:12:25.0112 7952 ============================================================
21:12:25.0112 7952 Initialize success
21:12:25.0112 7952 ============================================================
21:12:27.0983 5296 ============================================================
21:12:27.0983 5296 Scan started
21:12:27.0983 5296 Mode: Manual;
21:12:27.0983 5296 ============================================================
21:12:29.0340 5296 ================ Scan system memory ========================
21:12:29.0340 5296 System memory - ok
21:12:29.0340 5296 ================ Scan services =============================
21:12:29.0636 5296 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
21:12:29.0652 5296 1394ohci - ok
21:12:29.0714 5296 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
21:12:29.0714 5296 ACPI - ok
21:12:29.0777 5296 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
21:12:29.0777 5296 AcpiPmi - ok
21:12:29.0917 5296 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:12:29.0917 5296 AdobeARMservice - ok
21:12:30.0120 5296 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:12:30.0120 5296 AdobeFlashPlayerUpdateSvc - ok
21:12:30.0214 5296 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
21:12:30.0229 5296 adp94xx - ok
21:12:30.0307 5296 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
21:12:30.0323 5296 adpahci - ok
21:12:30.0416 5296 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
21:12:30.0432 5296 adpu320 - ok
21:12:30.0494 5296 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:12:30.0494 5296 AeLookupSvc - ok
21:12:30.0635 5296 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
21:12:30.0650 5296 AFD - ok
21:12:30.0697 5296 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
21:12:30.0713 5296 agp440 - ok
21:12:30.0791 5296 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
21:12:30.0806 5296 ALG - ok
21:12:30.0853 5296 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
21:12:30.0853 5296 aliide - ok
21:12:30.0931 5296 [ 0497E13936E43065C85BE3C9CDC0258B ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:12:30.0931 5296 AMD External Events Utility - ok
21:12:30.0978 5296 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
21:12:30.0978 5296 amdide - ok
21:12:31.0040 5296 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
21:12:31.0040 5296 AmdK8 - ok
21:12:31.0306 5296 [ 679999D8808C1784DCB9BD59C19AE32F ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
21:12:31.0587 5296 amdkmdag - ok
21:12:31.0743 5296 [ A4769EAF3936DA861B9B1C9E5BD2FC52 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
21:12:31.0805 5296 amdkmdap - ok
21:12:31.0883 5296 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
21:12:31.0883 5296 AmdPPM - ok
21:12:31.0961 5296 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
21:12:31.0977 5296 amdsata - ok
21:12:32.0055 5296 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
21:12:32.0070 5296 amdsbs - ok
21:12:32.0133 5296 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
21:12:32.0148 5296 amdxata - ok
21:12:32.0257 5296 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
21:12:32.0273 5296 AppID - ok
21:12:32.0320 5296 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
21:12:32.0320 5296 AppIDSvc - ok
21:12:32.0398 5296 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
21:12:32.0413 5296 Appinfo - ok
21:12:32.0491 5296 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
21:12:32.0491 5296 arc - ok
21:12:32.0538 5296 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
21:12:32.0554 5296 arcsas - ok
21:12:32.0601 5296 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
21:12:32.0616 5296 AsyncMac - ok
21:12:32.0632 5296 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
21:12:32.0647 5296 atapi - ok
21:12:32.0725 5296 [ 4BF5BCA6E2608CD8A00BC4A6673A9F47 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
21:12:32.0725 5296 AtiHDAudioService - ok
21:12:32.0819 5296 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:12:32.0835 5296 AudioEndpointBuilder - ok
21:12:32.0866 5296 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
21:12:32.0866 5296 AudioSrv - ok
21:12:32.0959 5296 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
21:12:32.0975 5296 AxInstSV - ok
21:12:33.0053 5296 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
21:12:33.0069 5296 b06bdrv - ok
21:12:33.0209 5296 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
21:12:33.0225 5296 b57nd60a - ok
21:12:33.0381 5296 [ 93EE7D9C35AE7E9FFDA148D7805F1421 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
21:12:33.0381 5296 BBSvc - ok
21:12:33.0568 5296 [ 85111026F1C5A1C4CCE3697F0DA7BC1A ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
21:12:33.0755 5296 BCM43XX - ok
21:12:33.0817 5296 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
21:12:33.0833 5296 BDESVC - ok
21:12:33.0895 5296 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
21:12:33.0895 5296 Beep - ok
21:12:33.0989 5296 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
21:12:34.0005 5296 BFE - ok
21:12:34.0270 5296 [ 6E10DB69DB1AA96207F4B14B18FF12F8 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys
21:12:34.0301 5296 BHDrvx64 - ok
21:12:34.0410 5296 [ 65608C44E71D7BA056C9EFCD8A00A7FE ] BingDesktopUpdate C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
21:12:34.0426 5296 BingDesktopUpdate - ok
21:12:34.0504 5296 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
21:12:34.0519 5296 BITS - ok
21:12:34.0582 5296 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
21:12:34.0597 5296 blbdrive - ok
21:12:34.0644 5296 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
21:12:34.0660 5296 bowser - ok
21:12:34.0722 5296 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
21:12:34.0722 5296 BrFiltLo - ok
21:12:34.0769 5296 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
21:12:34.0769 5296 BrFiltUp - ok
21:12:34.0847 5296 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
21:12:34.0847 5296 Browser - ok
21:12:34.0909 5296 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\system32\DRIVERS\BrSerId.sys
21:12:34.0925 5296 Brserid - ok
21:12:34.0972 5296 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
21:12:34.0972 5296 BrSerWdm - ok
21:12:35.0034 5296 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
21:12:35.0034 5296 BrUsbMdm - ok
21:12:35.0065 5296 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\DRIVERS\BrUsbSer.sys
21:12:35.0065 5296 BrUsbSer - ok
21:12:35.0175 5296 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
21:12:35.0190 5296 BthEnum - ok
21:12:35.0221 5296 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
21:12:35.0221 5296 BTHMODEM - ok
21:12:35.0284 5296 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
21:12:35.0284 5296 BthPan - ok
21:12:35.0346 5296 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
21:12:35.0362 5296 BTHPORT - ok
21:12:35.0424 5296 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
21:12:35.0440 5296 bthserv - ok
21:12:35.0549 5296 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
21:12:35.0549 5296 BTHUSB - ok
21:12:35.0705 5296 [ 56685951208AC81CF923B9B08BEDF3B7 ] ccSet_NAV C:\Windows\system32\drivers\NAVx64\1404000.028\ccSetx64.sys
21:12:35.0721 5296 ccSet_NAV - ok
21:12:35.0814 5296 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
21:12:35.0814 5296 cdfs - ok
21:12:35.0877 5296 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
21:12:35.0892 5296 cdrom - ok
21:12:35.0939 5296 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
21:12:35.0955 5296 CertPropSvc - ok
21:12:36.0001 5296 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
21:12:36.0001 5296 circlass - ok
21:12:36.0064 5296 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
21:12:36.0079 5296 CLFS - ok
21:12:36.0157 5296 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:12:36.0173 5296 clr_optimization_v2.0.50727_32 - ok
21:12:36.0220 5296 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:12:36.0220 5296 clr_optimization_v2.0.50727_64 - ok
21:12:36.0345 5296 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:12:36.0360 5296 clr_optimization_v4.0.30319_32 - ok
21:12:36.0423 5296 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:12:36.0438 5296 clr_optimization_v4.0.30319_64 - ok
21:12:36.0532 5296 [ 09D38AEC081F064FD67B8B9C49790020 ] CltMngSvc C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
21:12:36.0547 5296 CltMngSvc - ok
21:12:36.0594 5296 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
21:12:36.0594 5296 CmBatt - ok
21:12:36.0641 5296 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
21:12:36.0641 5296 cmdide - ok
21:12:36.0719 5296 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
21:12:36.0719 5296 CNG - ok
21:12:36.0906 5296 [ 64EE11CBF385CA6F170FBE93B329B4E0 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys
21:12:36.0937 5296 CnxtHdAudService - ok
21:12:36.0984 5296 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
21:12:36.0984 5296 Compbatt - ok
21:12:37.0031 5296 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
21:12:37.0047 5296 CompositeBus - ok
21:12:37.0093 5296 COMSysApp - ok
21:12:37.0125 5296 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
21:12:37.0125 5296 crcdisk - ok
21:12:37.0203 5296 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll
21:12:37.0203 5296 CryptSvc - ok
21:12:37.0265 5296 [ 9D0D050170D47E778B624A28C90F23DE ] CxAudMsg C:\Windows\system32\CxAudMsg64.exe
21:12:37.0281 5296 CxAudMsg - ok
21:12:37.0343 5296 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
21:12:37.0359 5296 DcomLaunch - ok
21:12:37.0546 5296 [ 2D7C1661961CE19085B6A968B1B293D4 ] DefaultTabSearch C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe
21:12:37.0577 5296 DefaultTabSearch - ok
21:12:37.0827 5296 [ 34AE0DFA3EE3B5B9975042D87332D0B7 ] DefaultTabUpdate C:\Users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
21:12:37.0842 5296 DefaultTabUpdate - ok
21:12:37.0905 5296 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
21:12:37.0920 5296 defragsvc - ok
21:12:37.0951 5296 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
21:12:37.0967 5296 DfsC - ok
21:12:38.0029 5296 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
21:12:38.0045 5296 Dhcp - ok
21:12:38.0061 5296 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
21:12:38.0076 5296 discache - ok
21:12:38.0107 5296 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
21:12:38.0107 5296 Disk - ok
21:12:38.0154 5296 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
21:12:38.0154 5296 Dnscache - ok
21:12:38.0263 5296 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
21:12:38.0279 5296 dot3svc - ok
21:12:38.0326 5296 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
21:12:38.0341 5296 DPS - ok
21:12:38.0404 5296 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
21:12:38.0419 5296 drmkaud - ok
21:12:38.0513 5296 [ 4AB2A58816CC6BE771F1D8C768B804C5 ] DsiWMIService C:\Program Files (x86)\Launch Manager\dsiwmis.exe
21:12:38.0529 5296 DsiWMIService - ok
21:12:38.0685 5296 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
21:12:38.0716 5296 DXGKrnl - ok
21:12:38.0778 5296 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
21:12:38.0794 5296 EapHost - ok
21:12:39.0121 5296 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
21:12:39.0231 5296 ebdrv - ok
21:12:39.0449 5296 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
21:12:39.0465 5296 eeCtrl - ok
21:12:39.0527 5296 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
21:12:39.0543 5296 EFS - ok
21:12:39.0667 5296 [ 03E6888DA1A85ACF14AC2A3C328A9E62 ] EgisTec Ticket Service C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
21:12:39.0667 5296 EgisTec Ticket Service - ok
21:12:39.0823 5296 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
21:12:39.0839 5296 ehRecvr - ok
21:12:39.0901 5296 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
21:12:39.0995 5296 ehSched - ok
21:12:40.0120 5296 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
21:12:40.0135 5296 elxstor - ok
21:12:40.0369 5296 [ 753FAD8FD476116FA93799B0DB77702B ] ePowerSvc C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
21:12:40.0385 5296 ePowerSvc - ok
21:12:40.0510 5296 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:12:40.0525 5296 EraserUtilRebootDrv - ok
21:12:40.0572 5296 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
21:12:40.0588 5296 ErrDev - ok
21:12:40.0697 5296 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
21:12:40.0697 5296 EventSystem - ok
21:12:40.0759 5296 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
21:12:40.0775 5296 exfat - ok
21:12:40.0822 5296 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
21:12:40.0822 5296 fastfat - ok
21:12:40.0947 5296 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
21:12:40.0978 5296 Fax - ok
21:12:41.0025 5296 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
21:12:41.0025 5296 fdc - ok
21:12:41.0103 5296 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
21:12:41.0103 5296 fdPHost - ok
21:12:41.0134 5296 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
21:12:41.0149 5296 FDResPub - ok
21:12:41.0196 5296 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
21:12:41.0212 5296 FileInfo - ok
21:12:41.0259 5296 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
21:12:41.0259 5296 Filetrace - ok
21:12:41.0305 5296 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
21:12:41.0305 5296 flpydisk - ok
21:12:41.0383 5296 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
21:12:41.0383 5296 FltMgr - ok
21:12:41.0508 5296 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
21:12:41.0555 5296 FontCache - ok
21:12:41.0649 5296 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:12:41.0664 5296 FontCache3.0.0.0 - ok
21:12:41.0711 5296 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
21:12:41.0742 5296 FsDepends - ok
21:12:41.0789 5296 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
21:12:41.0805 5296 Fs_Rec - ok
21:12:41.0914 5296 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
21:12:41.0961 5296 fvevol - ok
21:12:42.0070 5296 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
21:12:42.0117 5296 gagp30kx - ok
21:12:42.0273 5296 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
21:12:42.0288 5296 GamesAppService - ok
21:12:42.0413 5296 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
21:12:42.0444 5296 gpsvc - ok
21:12:42.0538 5296 [ 0191DEE9B9EB7902AF2CF4F67301095D ] GREGService C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
21:12:42.0569 5296 GREGService - ok
21:12:42.0725 5296 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:12:42.0725 5296 gupdate - ok
21:12:42.0772 5296 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:12:42.0772 5296 gupdatem - ok
21:12:42.0881 5296 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
21:12:42.0897 5296 gusvc - ok
21:12:42.0943 5296 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
21:12:42.0959 5296 hcw85cir - ok
21:12:43.0021 5296 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:12:43.0037 5296 HdAudAddService - ok
21:12:43.0084 5296 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
21:12:43.0099 5296 HDAudBus - ok
21:12:43.0146 5296 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
21:12:43.0146 5296 HidBatt - ok
21:12:43.0193 5296 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
21:12:43.0209 5296 HidBth - ok
21:12:43.0271 5296 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
21:12:43.0271 5296 HidIr - ok
21:12:43.0333 5296 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
21:12:43.0349 5296 hidserv - ok
21:12:43.0443 5296 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
21:12:43.0443 5296 HidUsb - ok
21:12:43.0489 5296 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
21:12:43.0505 5296 hkmsvc - ok
21:12:43.0567 5296 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:12:43.0567 5296 HomeGroupListener - ok
21:12:43.0630 5296 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:12:43.0661 5296 HomeGroupProvider - ok
21:12:43.0879 5296 [ F5F4818A15AF6128A2BADD1B1F102413 ] HP DS Service C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe
21:12:43.0926 5296 HP DS Service - ok
21:12:44.0067 5296 [ 3BF3B2F977115DD06475983790032BA7 ] HP LaserJet Service C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
21:12:44.0067 5296 HP LaserJet Service - ok
21:12:44.0129 5296 [ E325F85012E793CEE74B73C4F22AE311 ] HPFXBULKLEDM C:\Windows\system32\drivers\hppdbulkio.sys
21:12:44.0160 5296 HPFXBULKLEDM - ok
21:12:44.0207 5296 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
21:12:44.0238 5296 HpSAMD - ok
21:12:44.0347 5296 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
21:12:44.0363 5296 HTTP - ok
21:12:44.0410 5296 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
21:12:44.0425 5296 hwpolicy - ok
21:12:44.0457 5296 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
21:12:44.0472 5296 i8042prt - ok
21:12:44.0503 5296 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
21:12:44.0519 5296 iaStorV - ok
21:12:44.0628 5296 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:12:44.0659 5296 idsvc - ok
21:12:44.0893 5296 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130727.001\IDSvia64.sys
21:12:44.0925 5296 IDSVia64 - ok
21:12:44.0956 5296 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
21:12:44.0971 5296 iirsp - ok
21:12:45.0034 5296 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
21:12:45.0049 5296 IKEEXT - ok
21:12:45.0112 5296 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
21:12:45.0112 5296 intelide - ok
21:12:45.0143 5296 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\drivers\intelppm.sys
21:12:45.0143 5296 intelppm - ok
21:12:45.0190 5296 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
21:12:45.0205 5296 IPBusEnum - ok
21:12:45.0252 5296 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:12:45.0268 5296 IpFilterDriver - ok
21:12:45.0330 5296 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
21:12:45.0346 5296 iphlpsvc - ok
21:12:45.0393 5296 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
21:12:45.0393 5296 IPMIDRV - ok
21:12:45.0439 5296 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
21:12:45.0439 5296 IPNAT - ok
21:12:45.0486 5296 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
21:12:45.0486 5296 IRENUM - ok
21:12:45.0533 5296 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
21:12:45.0549 5296 isapnp - ok
21:12:45.0595 5296 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
21:12:45.0658 5296 iScsiPrt - ok
21:12:45.0705 5296 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
21:12:45.0705 5296 kbdclass - ok
21:12:45.0751 5296 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
21:12:45.0767 5296 kbdhid - ok
21:12:45.0798 5296 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
21:12:45.0798 5296 KeyIso - ok
21:12:45.0876 5296 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
21:12:45.0876 5296 KSecDD - ok
21:12:45.0907 5296 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
21:12:45.0907 5296 KSecPkg - ok
21:12:45.0954 5296 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
21:12:45.0954 5296 ksthunk - ok
21:12:46.0001 5296 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
21:12:46.0017 5296 KtmRm - ok
21:12:46.0110 5296 [ 6DD5383C9413AAE3113FAF89E345663D ] L1C C:\Windows\system32\DRIVERS\L1C62x64.sys
21:12:46.0110 5296 L1C - ok
21:12:46.0188 5296 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
21:12:46.0204 5296 LanmanServer - ok
21:12:46.0235 5296 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:12:46.0251 5296 LanmanWorkstation - ok
21:12:46.0344 5296 [ 6BCEE9C766815BFFF89DE7D81AF34CE1 ] Live Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
21:12:46.0360 5296 Live Updater Service - ok
21:12:46.0407 5296 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
21:12:46.0407 5296 lltdio - ok
21:12:46.0469 5296 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
21:12:46.0469 5296 lltdsvc - ok
21:12:46.0531 5296 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
21:12:46.0531 5296 lmhosts - ok
21:12:46.0609 5296 lowpp - ok
21:12:46.0672 5296 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
21:12:46.0672 5296 LSI_FC - ok
21:12:46.0719 5296 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
21:12:46.0719 5296 LSI_SAS - ok
21:12:46.0765 5296 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
21:12:46.0765 5296 LSI_SAS2 - ok
21:12:46.0812 5296 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
21:12:46.0812 5296 LSI_SCSI - ok
21:12:46.0875 5296 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
21:12:46.0875 5296 luafv - ok
21:12:46.0984 5296 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
21:12:46.0984 5296 MBAMProtector - ok
21:12:47.0062 5296 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
21:12:47.0062 5296 MBAMScheduler - ok
21:12:47.0155 5296 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
21:12:47.0171 5296 MBAMService - ok
21:12:47.0280 5296 McComponentHostService - ok
21:12:47.0343 5296 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
21:12:47.0343 5296 Mcx2Svc - ok
21:12:47.0421 5296 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
21:12:47.0421 5296 megasas - ok
21:12:47.0467 5296 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
21:12:47.0467 5296 MegaSR - ok
21:12:47.0561 5296 Microsoft SharePoint Workspace Audit Service - ok
21:12:47.0608 5296 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
21:12:47.0608 5296 MMCSS - ok
21:12:47.0655 5296 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
21:12:47.0655 5296 Modem - ok
21:12:47.0701 5296 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
21:12:47.0701 5296 monitor - ok
21:12:47.0748 5296 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
21:12:47.0764 5296 mouclass - ok
21:12:47.0795 5296 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
21:12:47.0811 5296 mouhid - ok
21:12:47.0873 5296 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
21:12:47.0873 5296 mountmgr - ok
21:12:47.0920 5296 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
21:12:47.0935 5296 mpio - ok
21:12:47.0982 5296 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:12:47.0982 5296 mpsdrv - ok
21:12:48.0263 5296 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
21:12:48.0294 5296 MpsSvc - ok
21:12:48.0325 5296 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:12:48.0341 5296 MRxDAV - ok
21:12:48.0403 5296 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:12:48.0419 5296 mrxsmb - ok
21:12:48.0497 5296 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:12:48.0497 5296 mrxsmb10 - ok
21:12:48.0559 5296 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:12:48.0575 5296 mrxsmb20 - ok
21:12:48.0637 5296 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
21:12:48.0653 5296 msahci - ok
21:12:48.0684 5296 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
21:12:48.0715 5296 msdsm - ok
21:12:48.0747 5296 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
21:12:48.0778 5296 MSDTC - ok
21:12:48.0825 5296 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:12:48.0856 5296 Msfs - ok
21:12:48.0887 5296 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
21:12:48.0887 5296 mshidkmdf - ok
21:12:48.0918 5296 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
21:12:48.0918 5296 msisadrv - ok
21:12:49.0012 5296 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:12:49.0012 5296 MSiSCSI - ok
21:12:49.0043 5296 msiserver - ok
21:12:49.0090 5296 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:12:49.0090 5296 MSKSSRV - ok
21:12:49.0137 5296 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:12:49.0137 5296 MSPCLOCK - ok
21:12:49.0168 5296 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:12:49.0183 5296 MSPQM - ok
21:12:49.0215 5296 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:12:49.0246 5296 MsRPC - ok
21:12:49.0293 5296 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
21:12:49.0293 5296 mssmbios - ok
21:12:49.0402 5296 MSSQL$SQLEXPRESS - ok
21:12:49.0495 5296 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe
21:12:49.0495 5296 MSSQLServerADHelper - ok
21:12:49.0558 5296 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:12:49.0558 5296 MSTEE - ok
21:12:49.0605 5296 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
21:12:49.0605 5296 MTConfig - ok
21:12:49.0651 5296 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
21:12:49.0683 5296 Mup - ok
21:12:49.0745 5296 [ 9B1EAC6FAF6F37305E822F5588DC8056 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
21:12:49.0761 5296 mwlPSDFilter - ok
21:12:49.0807 5296 [ AD55C1524B296280ED9C6E0D730D35DA ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
21:12:49.0807 5296 mwlPSDNServ - ok
21:12:49.0870 5296 [ 2B599E6EC8843637BDD62E7F8F3BA201 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
21:12:49.0885 5296 mwlPSDVDisk - ok
21:12:50.0041 5296 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
21:12:50.0057 5296 napagent - ok
21:12:50.0197 5296 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:12:50.0197 5296 NativeWifiP - ok
21:12:50.0541 5296 [ 1BF9D6476061B31CD7FC2BF848529A56 ] NAV C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe
21:12:50.0556 5296 NAV - ok
21:12:50.0712 5296 [ 56540E526B46E379A476FB5BC381B290 ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130729.007\ENG64.SYS
21:12:50.0728 5296 NAVENG - ok
21:12:50.0868 5296 [ 8A19D3991F9F14B885CDE8BC640F6B68 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130729.007\EX64.SYS
21:12:50.0915 5296 NAVEX15 - ok
21:12:51.0009 5296 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
21:12:51.0024 5296 NDIS - ok
21:12:51.0087 5296 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
21:12:51.0102 5296 NdisCap - ok
21:12:51.0149 5296 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:12:51.0149 5296 NdisTapi - ok
21:12:51.0196 5296 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:12:51.0196 5296 Ndisuio - ok
21:12:51.0243 5296 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:12:51.0243 5296 NdisWan - ok
21:12:51.0289 5296 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:12:51.0289 5296 NDProxy - ok
21:12:51.0383 5296 [ F3A74A9E27D68726E69C642578CB8B32 ] Neat Startup Service C:\Program Files (x86)\Neat\exec\NeatStartupService.exe
21:12:51.0399 5296 Neat Startup Service - ok
21:12:51.0461 5296 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
21:12:51.0477 5296 Net Driver HPZ12 - ok
21:12:51.0523 5296 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:12:51.0539 5296 NetBIOS - ok
21:12:51.0586 5296 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
21:12:51.0601 5296 NetBT - ok
21:12:51.0648 5296 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
21:12:51.0648 5296 Netlogon - ok
21:12:51.0726 5296 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
21:12:51.0742 5296 Netman - ok
21:12:51.0789 5296 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
21:12:51.0804 5296 netprofm - ok
21:12:51.0851 5296 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:12:51.0851 5296 NetTcpPortSharing - ok
21:12:51.0929 5296 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
21:12:51.0929 5296 nfrd960 - ok
21:12:52.0038 5296 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
21:12:52.0038 5296 NlaSvc - ok
21:12:52.0210 5296 [ 5839A8027D6D324A7CD494051A96628C ] NOBU C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
21:12:52.0272 5296 NOBU - ok
21:12:52.0319 5296 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:12:52.0319 5296 Npfs - ok
21:12:52.0366 5296 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
21:12:52.0366 5296 nsi - ok
21:12:52.0397 5296 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:12:52.0397 5296 nsiproxy - ok
21:12:52.0491 5296 [ 18654D5E0DC33B7F0F895264A5DE80DA ] NSL C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
21:12:52.0491 5296 NSL - ok
21:12:52.0631 5296 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:12:52.0662 5296 Ntfs - ok
21:12:52.0709 5296 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
21:12:52.0709 5296 Null - ok
21:12:52.0771 5296 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:12:52.0771 5296 nvraid - ok
21:12:52.0803 5296 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:12:52.0803 5296 nvstor - ok
21:12:52.0834 5296 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
21:12:52.0849 5296 nv_agp - ok
21:12:52.0881 5296 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
21:12:52.0881 5296 ohci1394 - ok
21:12:52.0943 5296 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:12:52.0959 5296 ose - ok
21:12:53.0224 5296 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:12:53.0411 5296 osppsvc - ok
21:12:53.0458 5296 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
21:12:53.0473 5296 p2pimsvc - ok
21:12:53.0520 5296 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
21:12:53.0536 5296 p2psvc - ok
21:12:53.0598 5296 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
21:12:53.0614 5296 Parport - ok
21:12:53.0661 5296 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:12:53.0661 5296 partmgr - ok
21:12:53.0723 5296 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
21:12:53.0723 5296 PcaSvc - ok
21:12:53.0785 5296 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
21:12:53.0785 5296 pci - ok
21:12:53.0832 5296 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
21:12:53.0832 5296 pciide - ok
21:12:53.0879 5296 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
21:12:53.0879 5296 pcmcia - ok
21:12:53.0926 5296 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
21:12:53.0926 5296 pcw - ok
21:12:53.0973 5296 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:12:53.0988 5296 PEAUTH - ok
21:12:54.0160 5296 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
21:12:54.0160 5296 PerfHost - ok
21:12:54.0300 5296 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
21:12:54.0409 5296 pla - ok
21:12:54.0503 5296 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:12:54.0519 5296 PlugPlay - ok
21:12:54.0581 5296 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
21:12:54.0581 5296 Pml Driver HPZ12 - ok
21:12:54.0628 5296 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
21:12:54.0628 5296 PNRPAutoReg - ok
21:12:54.0675 5296 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
21:12:54.0690 5296 PNRPsvc - ok
21:12:54.0815 5296 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:12:54.0831 5296 PolicyAgent - ok
21:12:54.0893 5296 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
21:12:54.0893 5296 Power - ok
21:12:54.0971 5296 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:12:54.0971 5296 PptpMiniport - ok
21:12:55.0002 5296 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
21:12:55.0018 5296 Processor - ok
21:12:55.0080 5296 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
21:12:55.0096 5296 ProfSvc - ok
21:12:55.0189 5296 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:12:55.0189 5296 ProtectedStorage - ok
21:12:55.0236 5296 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
21:12:55.0252 5296 Psched - ok
21:12:55.0392 5296 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
21:12:55.0439 5296 ql2300 - ok
21:12:55.0470 5296 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
21:12:55.0486 5296 ql40xx - ok
21:12:55.0579 5296 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
21:12:55.0579 5296 QWAVE - ok
21:12:55.0626 5296 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:12:55.0657 5296 QWAVEdrv - ok
21:12:55.0689 5296 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:12:55.0689 5296 RasAcd - ok
21:12:55.0751 5296 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
21:12:55.0767 5296 RasAgileVpn - ok
21:12:55.0798 5296 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
21:12:55.0813 5296 RasAuto - ok
21:12:55.0845 5296 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:12:55.0845 5296 Rasl2tp - ok
21:12:55.0907 5296 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
21:12:55.0907 5296 RasMan - ok
21:12:55.0938 5296 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:12:55.0954 5296 RasPppoe - ok
21:12:56.0001 5296 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:12:56.0001 5296 RasSstp - ok
21:12:56.0063 5296 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:12:56.0079 5296 rdbss - ok
21:12:56.0110 5296 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
21:12:56.0110 5296 rdpbus - ok
21:12:56.0172 5296 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
21:12:56.0172 5296 RDPCDD - ok
21:12:56.0203 5296 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
21:12:56.0219 5296 RDPENCDD - ok
21:12:56.0235 5296 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
21:12:56.0235 5296 RDPREFMP - ok
21:12:56.0328 5296 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:12:56.0328 5296 RDPWD - ok
21:12:56.0391 5296 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
21:12:56.0391 5296 rdyboost - ok
21:12:56.0469 5296 [ A0FF419B61AE47E26ADF3BB15DB4F2FE ] RealNetworks Downloader Resolver Service C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
21:12:56.0469 5296 RealNetworks Downloader Resolver Service - ok
21:12:56.0531 5296 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
21:12:56.0531 5296 RemoteAccess - ok
21:12:56.0593 5296 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:12:56.0593 5296 RemoteRegistry - ok
21:12:56.0703 5296 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
21:12:56.0703 5296 RFCOMM - ok
21:12:56.0749 5296 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
21:12:56.0749 5296 RpcEptMapper - ok
21:12:56.0781 5296 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
21:12:56.0796 5296 RpcLocator - ok
21:12:56.0843 5296 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
21:12:56.0859 5296 RpcSs - ok
21:12:56.0905 5296 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:12:56.0921 5296 rspndr - ok
21:12:57.0015 5296 [ 135A64530D7699AD48F29D73A658DD11 ] RSUSBSTOR C:\Windows\System32\Drivers\RtsUStor.sys
21:12:57.0015 5296 RSUSBSTOR - ok
21:12:57.0139 5296 [ 7CB9F0FDD730F4A4ECF6CDE15EA12E8A ] RS_Service C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
21:12:57.0155 5296 RS_Service - ok
21:12:57.0186 5296 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
21:12:57.0202 5296 SamSs - ok
21:12:57.0233 5296 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
21:12:57.0249 5296 sbp2port - ok
21:12:57.0327 5296 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:12:57.0327 5296 SCardSvr - ok
21:12:57.0373 5296 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
21:12:57.0373 5296 scfilter - ok
21:12:57.0451 5296 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
21:12:57.0483 5296 Schedule - ok
21:12:57.0529 5296 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
21:12:57.0529 5296 SCPolicySvc - ok
21:12:57.0561 5296 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:12:57.0561 5296 SDRSVC - ok
21:12:57.0670 5296 [ CC781378E7EDA615D2CDCA3B17829FA4 ] SeaPort C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
21:12:57.0670 5296 SeaPort - ok
21:12:57.0732 5296 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:12:57.0732 5296 secdrv - ok
21:12:57.0795 5296 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
21:12:57.0795 5296 seclogon - ok
21:12:57.0841 5296 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
21:12:57.0841 5296 SENS - ok
21:12:57.0904 5296 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
21:12:57.0904 5296 SensrSvc - ok
21:12:57.0935 5296 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
21:12:57.0951 5296 Serenum - ok
21:12:57.0997 5296 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
21:12:58.0013 5296 Serial - ok
21:12:58.0044 5296 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
21:12:58.0044 5296 sermouse - ok
21:12:58.0122 5296 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
21:12:58.0138 5296 SessionEnv - ok
21:12:58.0169 5296 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
21:12:58.0185 5296 sffdisk - ok
21:12:58.0216 5296 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
21:12:58.0216 5296 sffp_mmc - ok
21:12:58.0247 5296 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
21:12:58.0263 5296 sffp_sd - ok
21:12:58.0278 5296 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
21:12:58.0294 5296 sfloppy - ok
21:12:58.0356 5296 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:12:58.0356 5296 SharedAccess - ok
21:12:58.0419 5296 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:12:58.0434 5296 ShellHWDetection - ok
21:12:58.0465 5296 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
21:12:58.0481 5296 SiSRaid2 - ok
21:12:58.0512 5296 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
21:12:58.0512 5296 SiSRaid4 - ok
21:12:58.0621 5296 [ 0F575481EAD4CDD41AA82ED38BC8F6B3 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
21:12:58.0637 5296 SkypeUpdate - ok
21:12:58.0699 5296 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
21:12:58.0699 5296 Smb - ok
21:12:58.0777 5296 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:12:58.0793 5296 SNMPTRAP - ok
21:12:58.0809 5296 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
21:12:58.0824 5296 spldr - ok
21:12:58.0902 5296 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
21:12:58.0918 5296 Spooler - ok
21:12:59.0074 5296 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
21:12:59.0214 5296 sppsvc - ok
21:12:59.0245 5296 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
21:12:59.0261 5296 sppuinotify - ok
21:12:59.0339 5296 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
21:12:59.0339 5296 SQLBrowser - ok
21:12:59.0448 5296 [ 3C432A96363097870995E2A3C8B66ABD ] SQLWriter c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
21:12:59.0464 5296 SQLWriter - ok
21:12:59.0729 5296 [ 2FD9346F9D76CB4192D37329CFA47A82 ] SRTSP C:\Windows\System32\Drivers\NAVx64\1404000.028\SRTSP64.SYS
21:12:59.0745 5296 SRTSP - ok
21:12:59.0807 5296 [ 0E76CEF892C45734F7AED09FDDF35D4D ] SRTSPX C:\Windows\system32\drivers\NAVx64\1404000.028\SRTSPX64.SYS
21:12:59.0807 5296 SRTSPX - ok
21:12:59.0901 5296 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
21:12:59.0916 5296 srv - ok
21:12:59.0963 5296 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:12:59.0979 5296 srv2 - ok
21:13:00.0041 5296 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:13:00.0072 5296 srvnet - ok
21:13:00.0181 5296 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:13:00.0181 5296 SSDPSRV - ok
21:13:00.0213 5296 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:13:00.0228 5296 SstpSvc - ok
21:13:00.0275 5296 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
21:13:00.0275 5296 stexstor - ok
21:13:00.0369 5296 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
21:13:00.0384 5296 stisvc - ok
21:13:00.0431 5296 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
21:13:00.0431 5296 swenum - ok
21:13:00.0493 5296 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
21:13:00.0509 5296 swprv - ok
21:13:00.0603 5296 [ 52DC0048D667757A8A2E4C87182890AC ] SymDS C:\Windows\system32\drivers\NAVx64\1404000.028\SYMDS64.SYS
21:13:00.0618 5296 SymDS - ok
21:13:00.0805 5296 [ 599872BAD7CFB45C7CE47CDED4B726D8 ] SymEFA C:\Windows\system32\drivers\NAVx64\1404000.028\SYMEFA64.SYS
21:13:00.0821 5296 SymEFA - ok
21:13:00.0946 5296 [ F19E5E37ED8134B9E5F6287F2D3A75D7 ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
21:13:00.0961 5296 SymEvent - ok
21:13:01.0024 5296 [ ADF37F1A715D6C56C8E065FD8569A9A4 ] SymIRON C:\Windows\system32\drivers\NAVx64\1404000.028\Ironx64.SYS
21:13:01.0039 5296 SymIRON - ok
21:13:01.0102 5296 [ 9CDCA70485BD6B9D230365F67C31F132 ] SymNetS C:\Windows\System32\Drivers\NAVx64\1404000.028\SYMNETS.SYS
21:13:01.0117 5296 SymNetS - ok
21:13:01.0211 5296 [ 02364D8BE46A51361B0905736C3F7438 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
21:13:01.0258 5296 SynTP - ok
21:13:01.0351 5296 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
21:13:01.0398 5296 SysMain - ok
21:13:01.0429 5296 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:13:01.0445 5296 TabletInputService - ok
21:13:01.0492 5296 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
21:13:01.0507 5296 TapiSrv - ok
21:13:01.0570 5296 [ 9C9C8BBCB6E6E1CBDAA10A5EAEA9FEAC ] tapklink C:\Windows\system32\DRIVERS\tapklink.sys
21:13:01.0570 5296 tapklink - ok
21:13:01.0601 5296 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
21:13:01.0617 5296 TBS - ok
21:13:01.0741 5296 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:13:01.0788 5296 Tcpip - ok
21:13:01.0913 5296 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
21:13:01.0960 5296 TCPIP6 - ok
21:13:02.0038 5296 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:13:02.0038 5296 tcpipreg - ok
21:13:02.0116 5296 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
21:13:02.0116 5296 TDPIPE - ok
21:13:02.0163 5296 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
21:13:02.0178 5296 TDTCP - ok
21:13:02.0225 5296 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:13:02.0225 5296 tdx - ok
21:13:02.0272 5296 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
21:13:02.0272 5296 TermDD - ok
21:13:02.0397 5296 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
21:13:02.0412 5296 TermService - ok
21:13:02.0443 5296 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
21:13:02.0475 5296 Themes - ok
21:13:02.0506 5296 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
21:13:02.0506 5296 THREADORDER - ok
21:13:02.0553 5296 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
21:13:02.0568 5296 TrkWks - ok
21:13:02.0755 5296 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:13:02.0771 5296 TrustedInstaller - ok
21:13:02.0818 5296 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
21:13:02.0833 5296 tssecsrv - ok
21:13:02.0865 5296 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
21:13:02.0880 5296 TsUsbFlt - ok
21:13:02.0927 5296 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
21:13:02.0943 5296 TsUsbGD - ok
21:13:03.0005 5296 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:13:03.0005 5296 tunnel - ok
21:13:03.0052 5296 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
21:13:03.0052 5296 uagp35 - ok
21:13:03.0114 5296 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:13:03.0130 5296 udfs - ok
21:13:03.0192 5296 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:13:03.0208 5296 UI0Detect - ok
21:13:03.0255 5296 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
21:13:03.0270 5296 uliagpkx - ok
21:13:03.0379 5296 [ E3116A36EF4F36D6C9E2BA2776D192FE ] UltiDev Web Server Pro C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe
21:13:03.0379 5296 UltiDev Web Server Pro - ok
21:13:03.0411 5296 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
21:13:03.0411 5296 umbus - ok
21:13:03.0457 5296 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
21:13:03.0457 5296 UmPass - ok
21:13:03.0598 5296 [ 656DFA3375E72EDDBBB06769828C9C9F ] Updater By SweetPacks C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
21:13:03.0613 5296 Updater By SweetPacks - ok
21:13:03.0691 5296 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
21:13:03.0707 5296 upnphost - ok
21:13:03.0769 5296 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
21:13:03.0769 5296 usbccgp - ok
21:13:03.0832 5296 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
21:13:03.0832 5296 usbcir - ok
21:13:03.0879 5296 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
21:13:03.0879 5296 usbehci - ok
21:13:03.0972 5296 [ 76E2FFAD301490BA27B947C6507752FB ] usbfilter C:\Windows\system32\DRIVERS\usbfilter.sys
21:13:03.0972 5296 usbfilter - ok
21:13:04.0050 5296 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
21:13:04.0081 5296 usbhub - ok
21:13:04.0113 5296 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
21:13:04.0113 5296 usbohci - ok
21:13:04.0191 5296 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
21:13:04.0191 5296 usbprint - ok
21:13:04.0269 5296 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
21:13:04.0284 5296 usbscan - ok
21:13:04.0347 5296 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:13:04.0347 5296 USBSTOR - ok
21:13:04.0393 5296 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
21:13:04.0393 5296 usbuhci - ok
21:13:04.0503 5296 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
21:13:04.0503 5296 usbvideo - ok
21:13:04.0565 5296 [ D5029C4310A0FC75E467E612B9B4CF15 ] UWS HiPriv Services C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe
21:13:04.0565 5296 UWS HiPriv Services - ok
21:13:04.0627 5296 [ DA0143FD21717756B4553F71675D11D3 ] UWS LoPriv Services C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe
21:13:04.0627 5296 UWS LoPriv Services - ok
21:13:04.0674 5296 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
21:13:04.0690 5296 UxSms - ok
21:13:04.0705 5296 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
21:13:04.0705 5296 VaultSvc - ok
21:13:04.0768 5296 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
21:13:04.0768 5296 vdrvroot - ok
21:13:04.0846 5296 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
21:13:04.0861 5296 vds - ok
21:13:04.0908 5296 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
21:13:04.0908 5296 vga - ok
21:13:04.0955 5296 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
21:13:04.0971 5296 VgaSave - ok
21:13:05.0002 5296 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
21:13:05.0017 5296 vhdmp - ok
21:13:05.0064 5296 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
21:13:05.0064 5296 viaide - ok
21:13:05.0127 5296 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
21:13:05.0127 5296 volmgr - ok
21:13:05.0173 5296 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:13:05.0173 5296 volmgrx - ok
21:13:05.0267 5296 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
21:13:05.0283 5296 volsnap - ok
21:13:05.0329 5296 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
21:13:05.0329 5296 vsmraid - ok
21:13:05.0423 5296 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
21:13:05.0470 5296 VSS - ok
21:13:05.0501 5296 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
21:13:05.0517 5296 vwifibus - ok
21:13:05.0579 5296 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
21:13:05.0579 5296 vwififlt - ok
21:13:05.0626 5296 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
21:13:05.0626 5296 vwifimp - ok
21:13:05.0673 5296 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
21:13:05.0688 5296 W32Time - ok
21:13:05.0719 5296 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
21:13:05.0719 5296 WacomPen - ok
21:13:05.0860 5296 [ 4AA2CC5979AFF984227364F2C23B04F3 ] WajamUpdater C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
21:13:05.0875 5296 WajamUpdater - ok
21:13:05.0938 5296 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
21:13:05.0953 5296 WANARP - ok
21:13:05.0969 5296 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:13:05.0985 5296 Wanarpv6 - ok
21:13:06.0094 5296 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
21:13:06.0125 5296 WatAdminSvc - ok
21:13:06.0234 5296 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
21:13:06.0265 5296 wbengine - ok
21:13:06.0312 5296 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
21:13:06.0328 5296 WbioSrvc - ok
21:13:06.0375 5296 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:13:06.0390 5296 wcncsvc - ok
21:13:06.0421 5296 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:13:06.0437 5296 WcsPlugInService - ok
21:13:06.0468 5296 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
21:13:06.0468 5296 Wd - ok
21:13:06.0546 5296 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:13:06.0562 5296 Wdf01000 - ok
21:13:06.0609 5296 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:13:06.0609 5296 WdiServiceHost - ok
21:13:06.0655 5296 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:13:06.0655 5296 WdiSystemHost - ok
21:13:06.0702 5296 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
21:13:06.0718 5296 WebClient - ok
21:13:06.0811 5296 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:13:06.0827 5296 Wecsvc - ok
21:13:06.0858 5296 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:13:06.0858 5296 wercplsupport - ok
21:13:06.0905 5296 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
21:13:06.0921 5296 WerSvc - ok
21:13:06.0967 5296 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
21:13:06.0967 5296 WfpLwf - ok
21:13:07.0092 5296 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
21:13:07.0092 5296 WIMMount - ok
21:13:07.0139 5296 WinDefend - ok
21:13:07.0155 5296 WinHttpAutoProxySvc - ok
21:13:07.0233 5296 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:13:07.0233 5296 Winmgmt - ok
21:13:07.0373 5296 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
21:13:07.0420 5296 WinRM - ok
21:13:07.0498 5296 [ FE88B288356E7B47B74B13372ADD906D ] WinUSB C:\Windows\system32\DRIVERS\WinUSB.sys
21:13:07.0513 5296 WinUSB - ok
21:13:07.0607 5296 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
21:13:07.0623 5296 Wlansvc - ok
21:13:07.0779 5296 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
21:13:07.0779 5296 wlcrasvc - ok
21:13:08.0028 5296 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:13:08.0106 5296 wlidsvc - ok
21:13:08.0169 5296 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
21:13:08.0169 5296 WmiAcpi - ok
21:13:08.0293 5296 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:13:08.0293 5296 wmiApSrv - ok
21:13:08.0356 5296 WMPNetworkSvc - ok
21:13:08.0403 5296 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:13:08.0418 5296 WPCSvc - ok
21:13:08.0434 5296 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:13:08.0449 5296 WPDBusEnum - ok
21:13:08.0496 5296 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:13:08.0512 5296 ws2ifsl - ok
21:13:08.0543 5296 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
21:13:08.0543 5296 wscsvc - ok
21:13:08.0590 5296 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
21:13:08.0590 5296 WSDPrintDevice - ok
21:13:08.0605 5296 WSearch - ok
21:13:08.0777 5296 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
21:13:08.0871 5296 wuauserv - ok
21:13:08.0917 5296 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:13:08.0917 5296 WudfPf - ok
21:13:08.0949 5296 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
21:13:08.0964 5296 WUDFRd - ok
21:13:08.0995 5296 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:13:09.0011 5296 wudfsvc - ok
21:13:09.0058 5296 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll
21:13:09.0073 5296 WwanSvc - ok
21:13:09.0214 5296 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
21:13:09.0229 5296 YahooAUService - ok
21:13:09.0339 5296 ================ Scan global ===============================
21:13:09.0385 5296 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
21:13:09.0541 5296 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
21:13:09.0573 5296 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
21:13:09.0619 5296 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
21:13:09.0760 5296 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
21:13:09.0775 5296 [Global] - ok
21:13:09.0775 5296 ================ Scan MBR ==================================
21:13:09.0807 5296 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:13:10.0228 5296 \Device\Harddisk0\DR0 - ok
21:13:10.0275 5296 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
21:13:10.0462 5296 \Device\Harddisk1\DR1 - ok
21:13:10.0462 5296 ================ Scan VBR ==================================
21:13:10.0477 5296 [ 533C67492E47AF4FE57B7954D7FFA8F2 ] \Device\Harddisk0\DR0\Partition1
21:13:10.0477 5296 \Device\Harddisk0\DR0\Partition1 - ok
21:13:10.0509 5296 [ 7E1DE7DDF2F4DAE24FF5E1384C87F785 ] \Device\Harddisk0\DR0\Partition2
21:13:10.0509 5296 \Device\Harddisk0\DR0\Partition2 - ok
21:13:10.0540 5296 [ 82D68E75194A211756AA341CB5692B86 ] \Device\Harddisk1\DR1\Partition1
21:13:10.0540 5296 \Device\Harddisk1\DR1\Partition1 - ok
21:13:10.0540 5296 ============================================================
21:13:10.0540 5296 Scan finished
21:13:10.0540 5296 ============================================================
21:13:10.0587 7412 Detected object count: 0
21:13:10.0587 7412 Actual detected object count: 0
21:18:10.0809 8744 Deinitialize success

Attachments:

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Conspire, OK, ran ComboFix successfully. The results are below. Mark ComboFix 13-07-27.01 - Mark Hudson 07/29/2013 22:48:22.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1771.721 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Norton AntiVirus *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Norton AntiVirus *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Mark Hudson\AppData\Local\Microsoft\Windows\Temporary Internet Files\{6503D4DA-447D-45D2-AABE-1D04BD9D97EB}.xps c:\users\Mark Hudson\AppData\Local\Microsoft\Windows\Temporary Internet Files\{CF7485FE-DB99-4ABF-885D-A22A63ADF428}.xps c:\users\Mark Hudson\g2mdlhlpx.exe c:\windows\SysWow64\muzapp.exe c:\windows\Tasks\TopArcadeHits.job c:\windows\wininit.ini . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_DefaultTabSearch ——-\Service_DefaultTabUpdate . . ((((((((((((((((((((((((( Files Created from 2013-06-28 to 2013-07-30 ))))))))))))))))))))))))))))))) . . 2013-07-30 04:16 . 2013-07-30 04:16 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-24 16:21 . 2013-07-24 16:21 ——– d—–w- c:\users\Mark Hudson\AppData\Roaming\Malwarebytes 2013-07-24 16:21 . 2013-07-24 16:21 ——– d—–w- c:\programdata\Malwarebytes 2013-07-24 16:21 . 2013-04-04 19:50 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-07-24 16:21 . 2013-07-24 16:21 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-07-24 16:20 . 2013-07-24 16:20 ——– d—–w- c:\users\Mark Hudson\AppData\Local\Programs 2013-07-23 21:52 . 2013-07-23 22:41 ——– d—–w- c:\users\Mark Hudson\AppData\Local\NPE 2013-07-18 20:08 . 2013-07-18 20:08 ——– d—–w- c:\program files (x86)\RealZeal Soft 2013-07-18 20:08 . 2013-07-18 20:08 ——– d—–w- c:\program files (x86)\Common Files\RZPPTCodec 2013-07-18 15:48 . 2013-07-18 15:48 ——– d—–w- c:\program files (x86)\AIViewer 2013-07-18 15:42 . 2013-07-18 15:42 ——– d—–w- c:\users\Mark Hudson\AppData\Local\Wajam 2013-07-18 15:41 . 2013-07-18 15:46 ——– d—–w- c:\program files (x86)\Wajam 2013-07-18 15:41 . 2013-07-18 15:41 ——– d—–w- c:\program files (x86)\DefaultTab 2013-07-18 15:40 . 2013-07-18 15:40 ——– d—–w- c:\users\Mark Hudson\AppData\Roaming\DefaultTab 2013-07-18 15:40 . 2013-07-28 19:03 ——– d—–w- c:\users\Mark Hudson\AppData\Local\TopArcadeHits 2013-07-18 15:38 . 2013-07-18 15:38 ——– d—–w- c:\program files\Updater By SweetPacks 2013-07-18 15:31 . 2013-07-18 15:31 ——– d—–w- c:\program files (x86)\SweetIM 2013-07-18 15:26 . 2013-07-18 21:26 ——– d—–w- c:\windows\SysWow64\jmdp 2013-07-18 15:26 . 2013-07-18 15:26 ——– d—–w- c:\windows\SysWow64\ARFC 2013-07-18 15:26 . 2013-06-30 16:10 1645360 —-a-w- c:\windows\system32\dmwu.exe 2013-07-18 15:26 . 2013-06-30 16:07 33792 —-a-w- c:\windows\system32\ImHttpComm.dll 2013-07-18 15:26 . 2013-07-18 15:26 ——– d—–w- c:\windows\SysWow64\WNLT 2013-07-11 16:00 . 2013-05-27 05:50 1011712 —-a-w- c:\program files\Windows Defender\MpSvc.dll 2013-07-11 16:00 . 2013-05-27 05:50 571904 —-a-w- c:\program files\Windows Defender\MpClient.dll 2013-07-11 16:00 . 2013-05-27 05:50 314880 —-a-w- c:\program files\Windows Defender\MpCommu.dll 2013-07-11 16:00 . 2013-05-27 04:57 4608 —-a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll 2013-07-11 16:00 . 2013-05-27 04:57 54784 —-a-w- c:\program files (x86)\Windows Defender\MpOAV.dll 2013-07-11 16:00 . 2013-05-27 04:57 392704 —-a-w- c:\program files (x86)\Windows Defender\MpClient.dll 2013-07-11 16:00 . 2013-05-27 03:15 9216 —-a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll 2013-07-11 16:00 . 2013-06-04 06:00 624128 —-a-w- c:\windows\system32\qedit.dll 2013-07-11 16:00 . 2013-06-04 04:53 509440 —-a-w- c:\windows\SysWow64\qedit.dll 2013-07-11 16:00 . 2013-05-06 06:03 1887744 —-a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-11 16:00 . 2013-05-06 04:56 1620480 —-a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-11 15:59 . 2013-04-10 05:48 1732608 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-11 15:59 . 2013-04-10 05:46 1393152 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-11 15:59 . 2013-04-10 05:46 1367040 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 15:59 . 2013-04-10 05:46 1402880 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-11 15:59 . 2013-04-10 05:03 936448 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 15:59 . 2013-06-05 03:34 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-07-11 15:59 . 2013-04-02 22:51 1643520 —-a-w- c:\windows\system32\DWrite.dll 2013-07-11 15:59 . 2013-04-09 23:34 1247744 —-a-w- c:\windows\SysWow64\DWrite.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-15 20:01 . 2012-03-29 13:54 692104 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-07-15 20:01 . 2011-07-07 21:56 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-07-11 19:38 . 2011-06-22 19:36 78185248 —-a-w- c:\windows\system32\MRT.exe 2013-06-17 22:04 . 2013-04-23 05:01 177312 —-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2013-05-23 05:25 . 2013-06-17 22:04 1139800 —-a-w- c:\windows\system32\drivers\NAVx64\1404000.028\symefa64.sys 2013-05-23 01:43 . 2013-05-23 01:43 90112 —-a-w- c:\windows\MAMCityDownload.ocx 2013-05-23 01:43 . 2013-05-23 01:43 30568 —-a-w- c:\windows\MusiccityDownload.exe 2013-05-23 01:43 . 2013-05-23 01:43 330240 —-a-w- c:\windows\MASetupCaller.dll 2013-05-23 01:43 . 2013-05-23 01:43 974848 —-a-w- c:\windows\SysWow64\cis-2.4.dll 2013-05-23 01:43 . 2013-05-23 01:43 81920 —-a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll 2013-05-23 01:43 . 2013-05-23 01:43 65536 —-a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll 2013-05-23 01:43 . 2013-05-23 01:43 57344 —-a-w- c:\windows\SysWow64\MTXSYNCICON.dll 2013-05-23 01:43 . 2013-05-23 01:43 57344 —-a-w- c:\windows\SysWow64\MK_Lyric.dll 2013-05-23 01:43 . 2013-05-23 01:43 57344 —-a-w- c:\windows\SysWow64\issacapi_se-2.3.dll 2013-05-23 01:43 . 2013-05-23 01:43 569344 —-a-w- c:\windows\SysWow64\muzdecode.ax 2013-05-23 01:43 . 2013-05-23 01:43 491520 —-a-w- c:\windows\SysWow64\muzapp.dll 2013-05-23 01:43 . 2013-05-23 01:43 49152 —-a-w- c:\windows\SysWow64\MaJGUILib.dll 2013-05-23 01:43 . 2013-05-23 01:43 45320 —-a-w- c:\windows\SysWow64\MAMACExtract.dll 2013-05-23 01:43 . 2013-05-23 01:43 45056 —-a-w- c:\windows\SysWow64\MaXMLProto.dll 2013-05-23 01:43 . 2013-05-23 01:43 45056 —-a-w- c:\windows\SysWow64\MACXMLProto.dll 2013-05-23 01:43 . 2013-05-23 01:43 40960 —-a-w- c:\windows\SysWow64\MTTELECHIP.dll 2013-05-23 01:43 . 2013-05-23 01:43 352256 —-a-w- c:\windows\SysWow64\MSLUR71.dll 2013-05-23 01:43 . 2013-05-23 01:43 258048 —-a-w- c:\windows\SysWow64\muzoggsp.ax 2013-05-23 01:43 . 2013-05-23 01:43 245760 —-a-w- c:\windows\SysWow64\MSCLib.dll 2013-05-23 01:43 . 2013-05-23 01:43 24576 —-a-w- c:\windows\SysWow64\MASetupCleaner.exe 2013-05-23 01:43 . 2013-05-23 01:43 200704 —-a-w- c:\windows\SysWow64\muzwmts.dll 2013-05-23 01:43 . 2013-05-23 01:43 155648 —-a-w- c:\windows\SysWow64\MSFLib.dll 2013-05-23 01:43 . 2013-05-23 01:43 143360 —-a-w- c:\windows\SysWow64\3DAudio.ax 2013-05-23 01:43 . 2013-05-23 01:43 135168 —-a-w- c:\windows\SysWow64\muzaf1.dll 2013-05-23 01:43 . 2013-05-23 01:43 131072 —-a-w- c:\windows\SysWow64\muzmpgsp.ax 2013-05-23 01:43 . 2013-05-23 01:43 122880 —-a-w- c:\windows\SysWow64\muzeffect.ax 2013-05-23 01:43 . 2013-05-23 01:43 118784 —-a-w- c:\windows\SysWow64\MaDRM.dll 2013-05-23 01:43 . 2013-05-23 01:43 110592 —-a-w- c:\windows\SysWow64\muzmp4sp.ax 2013-05-23 01:43 . 2013-06-27 01:52 821824 —-a-w- c:\windows\SysWow64\dgderapi.dll 2013-05-23 01:33 . 2013-06-27 01:54 4659712 —-a-w- c:\windows\SysWow64\Redemption.dll 2013-05-21 05:02 . 2013-06-17 22:04 493656 —-a-w- c:\windows\system32\drivers\NAVx64\1404000.028\symds64.sys 2013-05-16 05:02 . 2013-06-17 22:04 796760 —-a-w- c:\windows\system32\drivers\NAVx64\1404000.028\srtsp64.sys 2013-05-13 05:51 . 2013-06-12 19:12 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2013-05-13 05:51 . 2013-06-12 19:12 1464320 —-a-w- c:\windows\system32\crypt32.dll 2013-05-13 05:51 . 2013-06-12 19:12 139776 —-a-w- c:\windows\system32\cryptnet.dll 2013-05-13 05:50 . 2013-06-12 19:12 52224 —-a-w- c:\windows\system32\certenc.dll 2013-05-13 04:45 . 2013-06-12 19:12 1160192 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-05-13 04:45 . 2013-06-12 19:12 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2013-05-13 04:45 . 2013-06-12 19:12 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-05-13 03:43 . 2013-06-12 19:12 1192448 —-a-w- c:\windows\system32\certutil.exe 2013-05-13 03:08 . 2013-06-12 19:12 903168 —-a-w- c:\windows\SysWow64\certutil.exe 2013-05-13 03:08 . 2013-06-12 19:12 43008 —-a-w- c:\windows\SysWow64\certenc.dll 2013-05-10 05:49 . 2013-06-12 19:13 30720 —-a-w- c:\windows\system32\cryptdlg.dll 2013-05-10 03:20 . 2013-06-12 19:13 24576 —-a-w- c:\windows\SysWow64\cryptdlg.dll 2013-05-08 23:06 . 2011-08-11 15:09 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-08 06:39 . 2013-06-12 19:13 1910632 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-02 13:55 . 2013-05-02 13:55 163504 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}"= "c:\program files (x86)\Search_Spin\prxtbSear.dll" [2013-03-05 231168] . [HKEY_CLASSES_ROOT\clsid\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}] 2013-07-01 16:56 169304 —-a-w- c:\program files\Updater By SweetPacks\Extension32.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}] 2013-07-18 15:41 433272 —-a-w- c:\users\Mark Hudson\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA}] 2013-07-18 15:40 153432 —-a-w- c:\users\Mark Hudson\AppData\Local\TopArcadeHits\Toparcadehits.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{A7C0A55C-300E-4193-8FB5-5DB8E6533D35}] 2012-11-06 03:42 690776 ——w- c:\program files (x86)\FreePriceAlerts\vbobho.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] 2013-05-30 23:50 1309456 —-a-r- c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}] 2013-03-05 12:37 231168 —-a-w- c:\program files (x86)\Search_Spin\prxtbSear.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}"= "c:\program files (x86)\Search_Spin\prxtbSear.dll" [2013-03-05 231168] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2013-05-30 1309456] . [HKEY_CLASSES_ROOT\clsid\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}] . [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OfficeSyncProcess"="c:\program files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672] "SearchProtect"="c:\users\Mark Hudson\AppData\Roaming\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2013-05-23 1561968] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-09-28 340336] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-09-17 407920] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-09-17 201584] "Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-03-14 1081424] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-11 336384] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "SearchProtectAll"="c:\program files (x86)\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640] "BingDesktop"="c:\program files (x86)\Microsoft\BingDesktop\BingDesktop.exe" [2013-06-20 2249352] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2013-05-23 311152] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216] . c:\users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-1-8 228448] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files (x86)\Acer\Acer VCM\AcerVCM.exe [2011-3-30 704104] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 lowpp;Lowrance MMC Parallel Port Driver;c:\windows\system32\Drivers\lowpp.sys;c:\windows\SYSNATIVE\Drivers\lowpp.sys [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppdbulkio.sys;c:\windows\SYSNATIVE\drivers\hppdbulkio.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAVx64\1404000.028\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\NAVx64\1404000.028\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAVx64\1404000.028\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NAVx64\1404000.028\SYMEFA64.SYS [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [x] S1 ccSet_NAV;Norton AntiVirus Settings Manager;c:\windows\system32\drivers\NAVx64\1404000.028\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NAVx64\1404000.028\ccSetx64.sys [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130727.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130727.001\IDSvia64.sys [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAVx64\1404000.028\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NAVx64\1404000.028\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NAVx64\1404000.028\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NAVx64\1404000.028\SYMNETS.SYS [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 BingDesktopUpdate;Bing Desktop Update service;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe;c:\program files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [x] S2 CltMngSvc;Search Protect by Conduit Updater;c:\program files (x86)\SearchProtect\bin\CltMngSvc.exe;c:\program files (x86)\SearchProtect\bin\CltMngSvc.exe [x] S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x] S2 HP DS Service;HP DS Service;c:\program files (x86)\HP\HPBDSService\HPBDSService.exe;c:\program files (x86)\HP\HPBDSService\HPBDSService.exe [x] S2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [x] S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 NAV;Norton AntiVirus;c:\program files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe;c:\program files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe [x] S2 Neat Startup Service;Neat Startup Service;c:\program files (x86)\Neat\exec\NeatStartupService.exe;c:\program files (x86)\Neat\exec\NeatStartupService.exe [x] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 NSL;Norton Safe Web Lite;c:\program files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe;c:\program files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe [x] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [x] S2 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [x] S2 UltiDev Web Server Pro;UltiDev Web Server Pro;c:\program files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe;c:\program files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe [x] S2 Updater By SweetPacks;Updater By SweetPacks;c:\program files\Updater By SweetPacks\ExtensionUpdaterService.exe;c:\program files\Updater By SweetPacks\ExtensionUpdaterService.exe [x] S2 UWS HiPriv Services;UWS HiPriv Services;c:\program files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe;c:\program files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe [x] S2 UWS LoPriv Services;UWS LoPriv Services;c:\program files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe;c:\program files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe [x] S2 WajamUpdater;WajamUpdater;c:\program files (x86)\Wajam\Updater\WajamUpdater.exe;c:\program files (x86)\Wajam\Updater\WajamUpdater.exe [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] S3 tapklink;Klink Virtual Network Adapter;c:\windows\system32\DRIVERS\tapklink.sys;c:\windows\SYSNATIVE\DRIVERS\tapklink.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2013-07-30 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 20:01] . 2013-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-29 17:44] . 2013-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-29 17:44] . 2013-07-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job - c:\users\Mark Hudson\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-10 03:27] . 2013-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job - c:\users\Mark Hudson\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-10 03:27] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-01-28 862088] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.arcpointlabs.com/south-san-antonio mStart Page = hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10045&barid={52F3DEE3-EFBE-11E2-BB67-0015830B13C0} mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = hxxp://www.google.com IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.2.1 192.168.0.1 DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} - hxxp://192.168.2.119/web/WebClient.cab DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.gunbroker.com/WebResource.axd?d=Qydpf0KIwF1Fr6RRPI2vp09Qx7960W1PefrwdgTL1YWRWyUo6in6PN6VS7m59gst6zjhnPK4xtevtk kiPAeNbVdLz1lm1BKvO-eVx_B2d1Lb7EFrywmMr-EfCQUqniwFPL_qr5-6LT50B9lSJqZDgme2Vksu6ajL4Qvm6a-2VX8ROm8K0&t=634230999680000000 FF - ProfilePath - c:\users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\ FF - prefs.js: browser.search.defaulturl - FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10045&barid={52F3DEE3-EFBE-11E2-BB67-0015830B13C0} FF - prefs.js: keyword.URL - hxxp://start.sweetpacks.com/?src=2&st=12&crg=3.5000006.10045&barid={52F3DEE3-EFBE-11E2-BB67-0015830B13C0}&q= FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie=ISO-8859-1&q=&sa=Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie=ISO-8859-1&q=&sa=Search FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108317 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - acc5324700000000000000ff2f22a54d FF - user.js: extensions.BabylonToolbar_i.hardId - acc5324700000000000000ff2f22a54d FF - user.js: extensions.BabylonToolbar_i.instlDay - 15389 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:39 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.instlRef - sst . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-KiesAirMessage - c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe Wow6432Node-HKLM-Run- - (no file) Wow6432Node-HKU-Default-Run-SearchProtect - \SearchProtect\bin\cltmng.exe HKLM_Wow6432Node-ActiveSetup-Neat ADF Scanner 2008 - reg copy HKLM\Software\Wow6432Node\The Neat Company\Neat ADF Scanner 2008 HKCU\Software\The Neat Company\Neat ADF Scanner 2008 HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) WebBrowser-{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-RealPlayer 16.0 - c:\program files (x86)\real\realplayer\Update\r1puninst.exe AddRemove-{82AD8F8E-B613-42C2-A85A-F8C23F28E1E2}_is1 - c:\program files (x86)\Wallpaper Changer\unins000.exe AddRemove-{C1C3E833-420E-4D78-9BA7-86AEBB272384} - c:\users\Mark Hudson\AppData\Local\TopArcadeHits\uninstaller.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NAV] "ImagePath"="\"c:\program files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files (x86)\Norton AntiVirus\Engine\20.4.0.40\diMaster.dll\" /prefetch:1" – . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NSL] "ImagePath"="\"c:\program files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe\" /s \"NSL\" /m \"c:\program files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Launch Manager\LMworker.exe c:\program files (x86)\Launch Manager\LMutilps32.exe c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe . ************************************************************************** . Completion time: 2013-07-29 23:40:05 - machine was rebooted ComboFix-quarantined-files.txt 2013-07-30 04:40 . Pre-Run: 215,492,984,832 bytes free Post-Run: 217,668,153,344 bytes free . - - End Of File - - 74831B59F6C1AEFF1CE6784A33067F97 A36C5E4F47E84449FF07ED3517B43A31
-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
===================================================

Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message
===================================================

On your next reply please post :
AdwCleaner log
JRT log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Conspire, I thought all was going well until I attempted to update this thread. As I hit the link you provided in your email an attempt to redirect me by Oyodomo.com was underway. It did not succeed, almost acted as if it had stalled. I had to retry several times but finally made it to the thread to reply. I have not noticed the Oyodomo.com redirect prior to this event since we started working on this project. No sure if it means anything, but wanted to share what I observed. Below are the requested logs. Thanks again, Mark # AdwCleaner v2.306 - Logfile created 07/30/2013 at 09:46:34 # Updated 19/07/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Mark Hudson - MARKHUDSON-PC # Boot Mode : Normal # Running from : C:\Users\Mark Hudson\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : CltMngSvc Stopped & Deleted : Updater By SweetPacks Stopped & Deleted : WajamUpdater ***** [Files / Folders] ***** File Deleted : C:\user.js File Deleted : C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage File Deleted : C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal File Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi File Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\[removed] File Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Askcom.xml File Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\SweetIm.xml File Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Web Search.xml Folder Deleted : C:\Program Files (x86)\BabylonToolbar Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\DefaultTab Folder Deleted : C:\Program Files (x86)\Free Offers from Freeze.com Folder Deleted : C:\Program Files (x86)\Search_Spin Folder Deleted : C:\Program Files (x86)\SearchProtect Folder Deleted : C:\Program Files (x86)\SweetIM Folder Deleted : C:\Program Files (x86)\Wajam Folder Deleted : C:\Program Files\DomaIQ Uninstaller Folder Deleted : C:\Program Files\Updater By SweetPacks Folder Deleted : C:\ProgramData\Ask Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\Users\Mark Hudson\AppData\Local\APN Folder Deleted : C:\Users\Mark Hudson\AppData\Local\Babylon Folder Deleted : C:\Users\Mark Hudson\AppData\Local\Conduit Folder Deleted : C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc Folder Deleted : C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\klibnahbojhkanfgaglnlalfkgpcppfi Folder Deleted : C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\klibnahbojhkanfgaglnlalfkgpcppfi Folder Deleted : C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj Folder Deleted : C:\Users\Mark Hudson\AppData\Local\OpenCandy Folder Deleted : C:\Users\Mark Hudson\AppData\Local\SwvUpdater Folder Deleted : C:\Users\Mark Hudson\AppData\Local\Wajam Folder Deleted : C:\Users\Mark Hudson\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Mark Hudson\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\Mark Hudson\AppData\LocalLow\Search_Spin Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\Babylon Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\DefaultTab Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\CT3241284 Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\CT3289847 Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{739df940-c5ee-4bab-9d7e-270894ae687a} Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c} Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\Smartbar Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\OpenCandy Folder Deleted : C:\Users\Mark Hudson\AppData\Roaming\SearchProtect Folder Deleted : C:\Windows\SysWOW64\ARFC Folder Deleted : C:\Windows\SysWOW64\jmdp Folder Deleted : C:\Windows\SysWOW64\WNLT ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Deleted : HKCU\Software\AppDataLow\Software\DefaultTab Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\Search_Spin Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\BabylonToolbar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\Default Tab Key Deleted : HKCU\Software\DefaultTab Key Deleted : HKCU\Software\Google\Chrome\Extensions\klibnahbojhkanfgaglnlalfkgpcppfi Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0A0C99B-FB33-428B-963D-820A325212DD} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C} Key Deleted : HKCU\Software\SearchProtect Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\Wajam Key Deleted : HKCU\Software\WNLT Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\Software\BabylonToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL Key Deleted : HKLM\SOFTWARE\Classes\b Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1 Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3241284 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289847 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1 Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Default Tab Key Deleted : HKLM\Software\DefaultTab Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E0A0C99B-FB33-428B-963D-820A325212DD} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\Software\Search_Spin Key Deleted : HKLM\Software\SearchProtect Key Deleted : HKLM\Software\Wajam Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E0A0C99B-FB33-428B-963D-820A325212DD} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\klibnahbojhkanfgaglnlalfkgpcppfi Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B86AB18A-F181-4245-8358-8C9E3B8DAD93} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2D0FCF4-7585-4DC1-955E-9281BD4DF4A4} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DomaIQ Uninstaller Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Search_Spin Toolbar Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WNLT Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C}] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchprotect] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C}] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{FE02A3EF-6CD5-4DC6-8CF4-F3BCAC60BC7C}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16635 Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10045&barid={52F3DEE3-EFBE-11E2-BB67-0015830B13C0} –> hxxp://www.google.com -\\ Mozilla Firefox v9.0.1 (en-US) File : C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\prefs.js C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\user.js … Deleted ! Deleted : user_pref("CT3241284.1000234.TWC_TMP_city", "PLANO"); Deleted : user_pref("CT3241284.1000234.TWC_TMP_country", "US"); Deleted : user_pref("CT3241284.1000234.TWC_country", "UNITED STATES"); Deleted : user_pref("CT3241284.1000234.TWC_locId", "USTX1060"); Deleted : user_pref("CT3241284.1000234.TWC_location", "Plano, TX"); Deleted : user_pref("CT3241284.1000234.TWC_region", "US"); Deleted : user_pref("CT3241284.1000234.TWC_temp_dis", "f"); Deleted : user_pref("CT3241284.1000234.TWC_wind_dis", "mph"); Deleted : user_pref("CT3241284.1000234.weatherData", "{\"icon\":\"29.png\",\"temperature\":\"72°F\",\"temperat[…] Deleted : user_pref("CT3241284.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3241284.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[…] Deleted : user_pref("CT3241284.FF19Solved", "true"); Deleted : user_pref("CT3241284.Facebook_Mode.enc", "Mg=="); Deleted : user_pref("CT3241284.Facebook_User_Locale.enc", "ZW4="); Deleted : user_pref("CT3241284.FirstTime", "true"); Deleted : user_pref("CT3241284.FirstTimeFF3", "true"); Deleted : user_pref("CT3241284.PG_ENABLE", "dHJ1ZQ=="); Deleted : user_pref("CT3241284.SF_JUST_INSTALLED.enc", "RkFMU0U="); Deleted : user_pref("CT3241284.SF_STATUS.enc", "RU5BQkxFRA=="); Deleted : user_pref("CT3241284.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT324[…] Deleted : user_pref("CT3241284.UserID", "UN13223289111417098"); Deleted : user_pref("CT3241284.addressBarTakeOverEnabledInHidden", "true"); Deleted : user_pref("CT3241284.autoDisableScopes", -1); Deleted : user_pref("CT3241284.browser.search.defaultthis.engineName", "true"); Deleted : user_pref("CT3241284.defaultSearch", "true"); Deleted : user_pref("CT3241284.embeddedsData", "[{\"appId\":\"129883967008082178\",\"apiPermissions\":{\"cross[…] Deleted : user_pref("CT3241284.enableAlerts", "true"); Deleted : user_pref("CT3241284.enableFix404ByUser", "FALSE"); Deleted : user_pref("CT3241284.enableSearchFromAddressBar", "true"); Deleted : user_pref("CT3241284.firstTimeDialogOpened", "true"); Deleted : user_pref("CT3241284.fixPageNotFoundError", "true"); Deleted : user_pref("CT3241284.fixPageNotFoundErrorByUser", "true"); Deleted : user_pref("CT3241284.fixPageNotFoundErrorInHidden", "true"); Deleted : user_pref("CT3241284.fixUrls", true); Deleted : user_pref("CT3241284.hxxp___pinterest_aot_im.isEnabled.enc", "WQ=="); Deleted : user_pref("CT3241284.installDate", "10/4/2013 21:04:34"); Deleted : user_pref("CT3241284.installId", "conduitinstaller.exe"); Deleted : user_pref("CT3241284.installType", "conduitnsisintegration"); Deleted : user_pref("CT3241284.installUsage", "2013-05-05T20:53:56.9884823+03:00"); Deleted : user_pref("CT3241284.installUsageEarly", "2013-05-05T20:53:46.4426119+03:00"); Deleted : user_pref("CT3241284.installerVersion", "1.3.7.3"); Deleted : user_pref("CT3241284.isCheckedStartAsHidden", true); Deleted : user_pref("CT3241284.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3241284.isFirstTimeToolbarLoading", "false"); Deleted : user_pref("CT3241284.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Deleted : user_pref("CT3241284.keyword", "true"); Deleted : user_pref("CT3241284.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit[…] Deleted : user_pref("CT3241284.lastVersion", "10.15.0.62"); Deleted : user_pref("CT3241284.mam_gk_appStateReportTime.enc", "MTM3Mzk1NDU3ODU0Mg=="); Deleted : user_pref("CT3241284.mam_gk_appState_CouponBuddy.enc", "b24="); Deleted : user_pref("CT3241284.mam_gk_appState_Easytobook.enc", "b24="); Deleted : user_pref("CT3241284.mam_gk_appState_Easytobook_targeted.enc", "b24="); Deleted : user_pref("CT3241284.mam_gk_appState_PriceGong.enc", "b24="); Deleted : user_pref("CT3241284.mam_gk_appState_WindowShopper.enc", "b24="); Deleted : user_pref("CT3241284.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IkNvdXBvbkJ1ZGR5IiwidXJsIjoiaHR0cDov[…] Deleted : user_pref("CT3241284.mam_gk_appsDefaultEnabled.enc", "bnVsbA=="); Deleted : user_pref("CT3241284.mam_gk_calledSetupService.enc", "MQ=="); Deleted : user_pref("CT3241284.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IkFjdHVhbENsaWNrIiw[…] Deleted : user_pref("CT3241284.mam_gk_currentVersion.enc", "MS45LjAuNA=="); Deleted : user_pref("CT3241284.mam_gk_eventsCache.enc", "eyJkZmY1MGMxMS01YWI0LTRiNjEtOGMxMC1iYThmZmFmOTJjYTUiO[…] Deleted : user_pref("CT3241284.mam_gk_existingUsersRecoveryDone.enc", "MQ=="); Deleted : user_pref("CT3241284.mam_gk_first_time.enc", "MQ=="); Deleted : user_pref("CT3241284.mam_gk_gadgetOpen.enc", "MA=="); Deleted : user_pref("CT3241284.mam_gk_installer_preapproved.enc", "ZmFsc2U="); Deleted : user_pref("CT3241284.mam_gk_lastLoginTime.enc", "MTM3Mzk1NDU3NTYwOQ=="); Deleted : user_pref("CT3241284.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50[…] Deleted : user_pref("CT3241284.mam_gk_mamEnabled.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3241284.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3241284.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVyd[…] Deleted : user_pref("CT3241284.mam_gk_settings1.9.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVyd[…] Deleted : user_pref("CT3241284.mam_gk_showCloseButton.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3241284.mam_gk_showWelcomeGadget.enc", "ZmFsc2U="); Deleted : user_pref("CT3241284.mam_gk_userId.enc", "Zjk1YmMwMjctNTlhYS00ODI5LTlmYzgtMjQ1MTI2M2U2OWVm"); Deleted : user_pref("CT3241284.migrateAppsAndComponents", true); Deleted : user_pref("CT3241284.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fsearch.conduit.c[…] Deleted : user_pref("CT3241284.openThankYouPage", "false"); Deleted : user_pref("CT3241284.openUninstallPage", "true"); Deleted : user_pref("CT3241284.price-gong.isManagedApp", "true"); Deleted : user_pref("CT3241284.revertSettingsEnabled", "false"); Deleted : user_pref("CT3241284.search.searchAppId", "129883967008082178"); Deleted : user_pref("CT3241284.search.searchCount", "0"); Deleted : user_pref("CT3241284.searchFromAddressBarEnabledByUser", "true"); Deleted : user_pref("CT3241284.searchInNewTabEnabledByUser", "true"); Deleted : user_pref("CT3241284.searchInNewTabEnabledInHidden", "true"); Deleted : user_pref("CT3241284.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3241284.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[…] Deleted : user_pref("CT3241284.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[…] Deleted : user_pref("CT3241284.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[…] Deleted : user_pref("CT3241284.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3241284.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3241284.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[…] Deleted : user_pref("CT3241284.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1367776436326"); Deleted : user_pref("CT3241284.serviceLayer_services_appsMetadata_lastUpdate", "1367776436217"); Deleted : user_pref("CT3241284.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1367776437754"); Deleted : user_pref("CT3241284.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1367776430[…] Deleted : user_pref("CT3241284.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1367776439282")[…] Deleted : user_pref("CT3241284.serviceLayer_services_location_lastUpdate", "1367776431676"); Deleted : user_pref("CT3241284.serviceLayer_services_login_10.15.0.62_lastUpdate", "1367776436865"); Deleted : user_pref("CT3241284.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1367776437893"); Deleted : user_pref("CT3241284.serviceLayer_services_searchAPI_lastUpdate", "1367776431701"); Deleted : user_pref("CT3241284.serviceLayer_services_serviceMap_lastUpdate", "1367776423331"); Deleted : user_pref("CT3241284.serviceLayer_services_toolbarContextMenu_lastUpdate", "1367776437565"); Deleted : user_pref("CT3241284.serviceLayer_services_toolbarSettings_lastUpdate", "1367776431253"); Deleted : user_pref("CT3241284.serviceLayer_services_translation_lastUpdate", "1367776438136"); Deleted : user_pref("CT3241284.settingsINI", true); Deleted : user_pref("CT3241284.shouldFirstTimeDialog", "false"); Deleted : user_pref("CT3241284.showToolbarPermission", "false"); Deleted : user_pref("CT3241284.smartbar.CTID", "CT3241284"); Deleted : user_pref("CT3241284.smartbar.Uninstall", "0"); Deleted : user_pref("CT3241284.smartbar.homepage", true); Deleted : user_pref("CT3241284.smartbar.toolbarName", "Search Spin "); Deleted : user_pref("CT3241284.startPage", "true"); Deleted : user_pref("CT3241284.toolbarBornServerTime", "5-5-2013"); Deleted : user_pref("CT3241284.toolbarCurrentServerTime", "5-5-2013"); Deleted : user_pref("CT3241284.toolbarLoginClientTime", "Sun May 05 2013 12:53:56 GMT-0500 (Central Daylight T[…] Deleted : user_pref("CT3241284_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[…] Deleted : user_pref("CT3289847.1000082.isPlayDisplay", "true"); Deleted : user_pref("CT3289847.1000082.state", "{\"state\":\"stopped\",\"text\":\"1.FM (Cou…\",\"description[…] Deleted : user_pref("CT3289847.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3289847.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[…] Deleted : user_pref("CT3289847.FF19Solved", "true"); Deleted : user_pref("CT3289847.Facebook_Mode.enc", "Mg=="); Deleted : user_pref("CT3289847.Facebook_User_Locale.enc", "ZW4="); Deleted : user_pref("CT3289847.FirstTime", "true"); Deleted : user_pref("CT3289847.FirstTimeFF3", "true"); Deleted : user_pref("CT3289847.PG_ENABLE", "dHJ1ZQ=="); Deleted : user_pref("CT3289847.SF_JUST_INSTALLED.enc", "RkFMU0U="); Deleted : user_pref("CT3289847.SF_STATUS.enc", "RU5BQkxFRA=="); Deleted : user_pref("CT3289847.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT328[…] Deleted : user_pref("CT3289847.UserID", "UN19338413015765794"); Deleted : user_pref("CT3289847.addressBarTakeOverEnabledInHidden", "true"); Deleted : user_pref("CT3289847.browser.search.defaultthis.engineName", "true"); Deleted : user_pref("CT3289847.defaultSearch", "true"); Deleted : user_pref("CT3289847.embeddedsData", "[{\"appId\":\"130068661007799818\",\"apiPermissions\":{\"cross[…] Deleted : user_pref("CT3289847.enableAlerts", "true"); Deleted : user_pref("CT3289847.enableFix404ByUser", "TRUE"); Deleted : user_pref("CT3289847.enableSearchFromAddressBar", "true"); Deleted : user_pref("CT3289847.firstTimeDialogOpened", "true"); Deleted : user_pref("CT3289847.fixPageNotFoundError", "true"); Deleted : user_pref("CT3289847.fixPageNotFoundErrorByUser", "true"); Deleted : user_pref("CT3289847.fixPageNotFoundErrorInHidden", "true"); Deleted : user_pref("CT3289847.fixUrls", true); Deleted : user_pref("CT3289847.hxxp___api28_starwebnet_com.pid2.enc", "NTYwNTJiMzgtMTEyNy1jODI1LTBiYzctODAxZTF[…] Deleted : user_pref("CT3289847.hxxp___api31_starwebnet_com.pid2.enc", "OGU5YmU4ZTktMjA1YS04ODA2LTEwNjItZTNjODk[…] Deleted : user_pref("CT3289847.hxxp___facebook_conduitapps_com.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPTAsaHNjcm9[…] Deleted : user_pref("CT3289847.hxxp___toolbar_jollywallet_com_tlb_2.Affiliate_defaultGui.enc", "eyJndWkiOltdLC[…] Deleted : user_pref("CT3289847.hxxp___toolbar_jollywallet_com_tlb_2.Affiliate_settings.enc", "eyJpbml0VXJsIjoi[…] Deleted : user_pref("CT3289847.hxxp___toolbar_jollywallet_com_tlb_2.jw_token.enc", "MmRjOTZmYTUtMTI3ZC01NDljLW[…] Deleted : user_pref("CT3289847.hxxp___toolbar_jollywallet_com_tlb_2.key_list_id.enc", "MjAxMjA4MDItMDAw"); Deleted : user_pref("CT3289847.installDate", "29/4/2013 9:56:58"); Deleted : user_pref("CT3289847.installId", "9818"); Deleted : user_pref("CT3289847.installSessionId", "-1"); Deleted : user_pref("CT3289847.installSp", "TRUE"); Deleted : user_pref("CT3289847.installType", "conduitnsisintegration"); Deleted : user_pref("CT3289847.installerVersion", "1.4.1.3"); Deleted : user_pref("CT3289847.isCheckedStartAsHidden", true); Deleted : user_pref("CT3289847.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3289847.isFirstTimeToolbarLoading", "false"); Deleted : user_pref("CT3289847.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Deleted : user_pref("CT3289847.keyword", "true"); Deleted : user_pref("CT3289847.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit[…] Deleted : user_pref("CT3289847.lastVersion", "10.14.380.14"); Deleted : user_pref("CT3289847.mam_gk_appStateReportTime.enc", "MTM3Mzk1NDU3NTcyOQ=="); Deleted : user_pref("CT3289847.mam_gk_appState_CouponBuddy.enc", "b24="); Deleted : user_pref("CT3289847.mam_gk_appState_Easytobook.enc", "b24="); Deleted : user_pref("CT3289847.mam_gk_appState_Easytobook_targeted.enc", "b24="); Deleted : user_pref("CT3289847.mam_gk_appState_PriceGong.enc", "b24="); Deleted : user_pref("CT3289847.mam_gk_appState_WindowShopper.enc", "b24="); Deleted : user_pref("CT3289847.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IkNvdXBvbkJ1ZGR5IiwidXJsIjoiaHR0cDov[…] Deleted : user_pref("CT3289847.mam_gk_appsDefaultEnabled.enc", "bnVsbA=="); Deleted : user_pref("CT3289847.mam_gk_calledSetupService.enc", "MQ=="); Deleted : user_pref("CT3289847.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IkFjdHVhbENsaWNrIiw[…] Deleted : user_pref("CT3289847.mam_gk_currentVersion.enc", "MS45LjAuNA=="); Deleted : user_pref("CT3289847.mam_gk_eventsCache.enc", "eyI1MzgzMmRkOC1kMmY4LTRmZmMtYTAyNC03M2IzMGIzMzNhNGYiO[…] Deleted : user_pref("CT3289847.mam_gk_existingUsersRecoveryDone.enc", "MQ=="); Deleted : user_pref("CT3289847.mam_gk_first_time.enc", "MQ=="); Deleted : user_pref("CT3289847.mam_gk_gadgetOpen.enc", "MA=="); Deleted : user_pref("CT3289847.mam_gk_lastLoginTime.enc", "MTM3Mzk1NDU3NDk2Mg=="); Deleted : user_pref("CT3289847.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50[…] Deleted : user_pref("CT3289847.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3289847.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVyd[…] Deleted : user_pref("CT3289847.mam_gk_settings1.9.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVyd[…] Deleted : user_pref("CT3289847.mam_gk_showCloseButton.enc", "dHJ1ZQ=="); Deleted : user_pref("CT3289847.mam_gk_showWelcomeGadget.enc", "ZmFsc2U="); Deleted : user_pref("CT3289847.mam_gk_userId.enc", "MTE3NDZlYTctZjEwNy00OWM1LWFjYTItZjEwOWYzNTJmMDY1"); Deleted : user_pref("CT3289847.migrateAppsAndComponents", true); Deleted : user_pref("CT3289847.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%[…] Deleted : user_pref("CT3289847.openThankYouPage", "false"); Deleted : user_pref("CT3289847.openUninstallPage", "true"); Deleted : user_pref("CT3289847.price-gong.isManagedApp", "true"); Deleted : user_pref("CT3289847.revertSettingsEnabled", "true"); Deleted : user_pref("CT3289847.search.searchAppId", "130068661007799818"); Deleted : user_pref("CT3289847.search.searchCount", "0"); Deleted : user_pref("CT3289847.searchFromAddressBarEnabledByUser", "true"); Deleted : user_pref("CT3289847.searchInNewTabEnabledByUser", "true"); Deleted : user_pref("CT3289847.searchInNewTabEnabledInHidden", "true"); Deleted : user_pref("CT3289847.searchRevert", "true"); Deleted : user_pref("CT3289847.searchUserMode", "2"); Deleted : user_pref("CT3289847.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); Deleted : user_pref("CT3289847.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[…] Deleted : user_pref("CT3289847.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[…] Deleted : user_pref("CT3289847.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[…] Deleted : user_pref("CT3289847.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3289847.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[…] Deleted : user_pref("CT3289847.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[…] Deleted : user_pref("CT3289847.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1367776424912"); Deleted : user_pref("CT3289847.serviceLayer_services_appsMetadata_lastUpdate", "1367776424593"); Deleted : user_pref("CT3289847.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1367776424190"); Deleted : user_pref("CT3289847.serviceLayer_services_location_lastUpdate", "1367776414425"); Deleted : user_pref("CT3289847.serviceLayer_services_login_10.14.380.14_lastUpdate", "1367776426990"); Deleted : user_pref("CT3289847.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1367776424459"); Deleted : user_pref("CT3289847.serviceLayer_services_searchAPI_lastUpdate", "1367776414560"); Deleted : user_pref("CT3289847.serviceLayer_services_serviceMap_lastUpdate", "1367776412562"); Deleted : user_pref("CT3289847.serviceLayer_services_setupAPI_lastUpdate", "1367776425211"); Deleted : user_pref("CT3289847.serviceLayer_services_toolbarContextMenu_lastUpdate", "1367776423893"); Deleted : user_pref("CT3289847.serviceLayer_services_toolbarSettings_lastUpdate", "1367776413425"); Deleted : user_pref("CT3289847.serviceLayer_services_translation_lastUpdate", "1367776424629"); Deleted : user_pref("CT3289847.settingsINI", true); Deleted : user_pref("CT3289847.shouldFirstTimeDialog", "false"); Deleted : user_pref("CT3289847.smartbar.CTID", "CT3289847"); Deleted : user_pref("CT3289847.smartbar.Uninstall", "0"); Deleted : user_pref("CT3289847.smartbar.homepage", "true"); Deleted : user_pref("CT3289847.smartbar.toolbarName", "WhiteSmoke New "); Deleted : user_pref("CT3289847.startPage", "true"); Deleted : user_pref("CT3289847.toolbarBornServerTime", "5-5-2013"); Deleted : user_pref("CT3289847.toolbarCurrentServerTime", "5-5-2013"); Deleted : user_pref("CT3289847.versionFromInstaller", "10.14.380.14"); Deleted : user_pref("CT3289847_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[…] Deleted : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3241284&octid=CT324128[…] Deleted : user_pref("Smartbar.ConduitSearchEngineList", "Search Spin Customized Web Search"); Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241284[…] Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.startnow.com/s/?src=addrbar&provid[…] Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3241284"); Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Deleted : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke New Customized Web Search"); Deleted : user_pref("browser.search.order.1", "Ask.com"); Deleted : user_pref("browser.startup.homepage", "hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10045[…] Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108317"); Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "acc5324700000000000000ff2f22a54d"); Deleted : user_pref("extensions.BabylonToolbar_i.id", "acc5324700000000000000ff2f22a54d"); Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15389"); Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1715:39:41"); Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Deleted : user_pref("keyword.URL", "hxxp://start.sweetpacks.com/?src=2&st=12&crg=3.5000006.10045&barid={52F3DE[…] Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3241284&octid=CT3241284[…] Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[…] Deleted : user_pref("smartbar.machineId", "IKCARQBIXO2YFJ4YRNINNAOV7ILEY4JLEWO/FFYTZWSX0ZSI+AMKEZFKC8LSXGJMSYZ[…] Deleted : user_pref("smartbar.originalHomepage", "hxxp://search.startnow.com/s/?src=startpage&provider=&provid[…] Deleted : user_pref("smartbar.originalSearchAddressUrl", "hxxp://search.startnow.com/s/?src=addrbar&provider=&[…] Deleted : user_pref("smartbar.originalSearchEngine", "StartNow "); Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT32[…] Deleted : user_pref("sweetim.toolbar.urls.homepage", "hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.[…] Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "Ask.com"); Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "Search Spin Customized Web Sear[…] Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaulturl", "hxxp://search.conduit.com/ResultsEx[…] Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[…] -\\ Google Chrome v28.0.1500.72 File : C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [46634 octets] - [30/07/2013 09:44:02] AdwCleaner[S1].txt - [47096 octets] - [30/07/2013 09:46:34] ########## EOF - C:\AdwCleaner[S1].txt - [47157 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.2.8 (07.29.2013:2) OS: Windows 7 Home Premium x64 Ran by [removed] on Tue 07/30/2013 at 9:57:17.49 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\askpartnercobrandingtool_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\askpartnercobrandingtool_rasmancs Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{524497EB-7C75-4E81-88FB-A2EC225B518F} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8F1D75D1-7330-47BD-B5C8-C3BE1BAC82C8} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{ABD93EAF-D775-BC54-E63B-2804F22FD156} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C249B982-FC65-4460-98A6-ED6C092FD5FB} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} ~~~ Files ~~~ Folders Failed to delete: [Folder] "C:\ProgramData\strongvault online backup" Successfully deleted: [Folder] "C:\Users\Mark Hudson\AppData\Roaming\strongvault" Successfully deleted: [Folder] "C:\Users\Mark Hudson\AppData\Roaming\systweak" Successfully deleted: [Folder] "C:\Users\Mark Hudson\appdata\local\toparcadehits" Successfully deleted: [Folder] "C:\Users\Mark Hudson\AppData\Roaming\microsoft\windows\start menu\programs\toparcadehits" Successfully deleted: [Folder] "C:\ai_recyclebin" Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{00A16F29-521D-4A2B-8060-484D2AF52326} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{013E97A6-3C35-4E7A-95F0-B6E9471B95AC} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{01B5392B-3763-4B56-A983-9B0FCC14FAC0} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{02C205A4-D165-41C5-8B67-5EC0909D2404} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{02FF185F-7B77-481C-8FD6-0AC00A7FA02E} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{0656F93D-0483-4C5B-9B1B-14B9FD9C5CA4} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{08CAE2E5-41FC-4139-BAF3-8D1CF66924D8} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{109535A3-C969-4AD6-B38E-85D001830402} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{1111FC43-430B-4B49-B376-271189F28074} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{12852122-51FD-4DD9-AD27-9033E3B84494} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{13D952C3-C050-4288-8C72-73B525BC0CE5} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{161784D3-19B3-45C4-9C1C-89CDC9E61248} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{18539311-5BE4-4FA7-8ACB-C6A62E8008DE} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{18AF405E-8465-4C62-842A-1621D4B853B2} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{1A2F7A4A-7B79-4668-A0E2-43CD3B171A9B} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{1BDBF9C7-0A1C-4C78-B319-80156245AF74} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{1CF4E00B-BEE2-478B-9E69-43B96F812B8B} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{1D6EBE11-8B4D-4E12-B3DB-C0667B2EE7F6} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{1FB39D54-1128-4259-90B6-4A8D179886C7} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{1FE56794-2A80-45D7-8D3E-5B3BC6D08FBC} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{21142E53-6105-4262-A83D-ED0BEE5DBD90} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{21D7908F-F0FF-4408-8C5E-02ADD043F110} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{27C5A81D-5B9D-423E-8757-56EDDBE7D0CD} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{2DC17573-5765-4094-9A60-0E83F5F0BB21} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{2F6F5B86-34D3-4701-BCB5-135196B2218C} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{2F71CEB8-E278-491B-AA05-4320A8BA1ABB} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{307343B5-A884-4324-A49B-A35F3236531A} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{31B1C99E-090E-45CC-AF97-0721B65F4EAF} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{33B63C3B-3FE5-439F-B74D-48D824CBBE48} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{341DC3F3-2602-4905-9D4C-06FC4D68C677} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{38EDC5CE-B8F0-4790-9AC7-02A7B662EBA7} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{39004918-A336-4126-BA26-F0455A662F04} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{3E6D7CF7-6EB5-4154-A8C4-D25C2B703EBD} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{3F40692C-2687-484F-921E-DEDF0445B754} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{40253D4F-6F7A-4F35-B9CB-7D3BD6612D50} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{46E68357-BE66-496A-8612-84D3F46BB807} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{478683EE-51B3-479B-A2B8-88F36FD8BF17} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{47AF45C5-F1CA-4139-A6A8-A59C57300E8B} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{4E8ADEF2-B1FE-4A34-A23B-2AF3C122353A} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{4F6B97C2-8557-4A21-BF93-47E250ADD578} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{4FF4FCF5-7E46-4C1B-AC51-537DE459D84D} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{51BA0B4A-BFC4-49AB-BAED-0F9A33900A70} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{53DE6748-D544-46A5-8CE7-01C31098CCA0} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{55D281EA-941B-4F5C-9496-CC12CD839FEF} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{569C8053-557D-4DC7-989D-65066501D4DF} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{5910901E-CD12-4642-9EDD-B7F25D0572F0} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{5A44CE4D-B121-4CD6-8BF3-C0B754E0F864} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{5AA83F21-81AE-4EF1-AFE8-5F7DEDA53E52} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{61D80C93-5C1F-430E-B165-4F39DDDCBA75} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{639D74DA-D814-476F-A305-80E431BB4FC2} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{63AD69E0-A23E-418E-B5C5-7FE622E07B87} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{66A89363-48F0-4C7C-A7B5-5329399563A3} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{681FBB28-C952-4C0C-A998-B186F30DE297} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{6B66DD65-50FD-48AA-ACBD-50F4A4969DE9} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{6BD03E92-FB75-47CE-8B52-F927FDE4180A} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{6C290431-D36B-4CB6-86CA-F8C5A125728B} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{6C86F5EB-6A85-46FD-A164-0A3598BFC351} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{6D27F034-9C93-4E16-BE7A-0DAF5F6CF458} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{7154C4C6-71C1-4732-9E82-2342B78B6D93} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{721C9245-A6F7-4DD2-87E2-CE811283D06F} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{727DB47E-7DE0-440F-BF40-76E359283C9C} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{75801056-526F-445A-AC30-211BF3E06C52} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{7A68AF89-6CCC-4E7A-8023-31A4D8B7C2DF} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{7D1D40BA-00F5-4C40-B53C-85DB338B4143} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{7E85110F-800D-4D50-B332-39276E8AC5E3} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{7EBAF96E-A826-4D7E-BEE5-C7B90BD80619} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{7EDDADF9-7173-473B-B3CE-E98C540F7661} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{7F44B17D-ECF5-4FF1-87AE-5C96926EF89E} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{83ED5EC3-5254-4665-BE20-C8E2CA529F18} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{8531CBE3-C9A5-4B57-96BB-CD29A6059300} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{88AF779D-7D50-4883-A2FB-9F6C99632C30} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{9144AC38-823A-4D53-BD54-EBE726641F01} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{928A6886-47AA-41DF-AA6D-227878B542DF} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{93A677C3-8A87-40FF-A711-FA958E739A0D} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{97FF3329-F937-44D6-A2C2-68B1E00C8EEE} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{9A212740-5BBA-4D43-8249-FE6AE6BA9098} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{9AA21CAB-3FE6-4D4C-B1B6-29C4F2230BA5} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{A3D15543-6F80-4EC0-B7E8-A14346A6D550} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{A7B3CF7A-A48C-43A7-9E18-856F476B39C9} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{A9CE8CAD-AEAD-4442-9F66-FD9356FF5454} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{AAEA5379-442F-45FA-B99C-E7AC4C117ABC} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{B147B03F-7717-480C-B298-DA8DBEB09539} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{B1E01C20-8CBA-4597-8E8E-748156BCBEC6} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{B4457EED-B764-451F-B8FD-C652978773A4} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{B473A310-35C5-4C95-888B-FB13E9F6A0FB} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{B50AC879-DC3C-4234-9787-0DFDFB707C86} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{BEAE4E63-BD53-4E85-B85C-A6F3A3A4DBD0} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{C10CE310-A459-49B5-BDA9-715D8DEC628E} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{C3879209-CC71-4EA1-8E2C-2A4633F7F842} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{C79C4B39-86B8-4CF3-8D23-AB19E71CB40C} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{C7FA188E-39BE-4319-A2E5-27ECA9BC2F8C} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{CA7E7311-924B-4A0C-82F8-2B32AE9795F6} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{CE25BCAD-5104-4361-994F-1C615EA4575A} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{CF3DA321-737D-477F-AEF5-C28C8E86CC32} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{D0ACD11B-57A2-45A4-BC53-38246EE3E984} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{D14A607A-BA27-468D-8864-1D568188F361} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{D14C7AA8-139A-42F8-A9A5-445B7FA74F72} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{D36DABD4-2478-471E-BB9D-E3E4C6B2CDB0} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{DB027B63-0645-4821-A44F-30D2942DE1E0} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{E0574D30-B91D-4A38-988A-587C69A1C9F1} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{E1329CDF-0089-4C1A-8203-569D344EFC15} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{E238A86B-88E4-4EA9-9BAF-6BFFD37F8FEB} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{E3489E92-E26F-4C20-8C85-0A308E8E1ED6} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{E8C5D4D5-8963-486E-8126-6E41098B75A8} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{F22FA8E8-4609-41A9-A1F5-13CCCA69004A} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{F5669657-ECFA-45FE-BF10-231B5E34F318} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{F7BF9AEF-772A-47E7-B906-889B2FC9AF1E} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{F98E7A20-248A-4180-853A-279FD488FB8E} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{F9986D7D-1121-4A35-805B-BA3812E2DE12} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{FE2D43D1-5E10-44E5-ACB1-0E0695A5661F} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{FF5CC048-785E-47E1-A237-61B62BC3648A} Successfully deleted: [Empty Folder] C:\Users\Mark Hudson\appdata\local\{FFD852D2-1626-4230-9759-9E718DF53225} ~~~ Chrome Successfully deleted: [Folder] C:\Users\Mark Hudson\appdata\local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Tue 07/30/2013 at 10:26:38.33 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Oyodomo.com redirect is my issue. My original post was in hopes of removing it, however it popped up again while attempting my last post reply to you. I thought we got rid of it, but it appears to sill be present. Mark
OK,

OTL just finished.


OTL logfile created on: 7/30/2013 5:10:59 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 51.35% Memory free
3.46 Gb Paging File | 1.75 Gb Available in Paging File | 50.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 202.73 Gb Free Space | 71.14% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mark Hudson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\83cfe0422e7e54f3f00107c15a63f1b4\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6da2afd0e57708d41892d9d3e32ba5a3\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f3770f9a13d7516e4c03f23dbd319cba\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\4572de8445038600e4552429b18fbe32\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7546a01feb9d477570b883eec56cc673\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\112f6448b7434699af4bcc05f25ce12b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\64b92e2a22bb8c1e86486bd22828acc5\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c1c41a9e1a25999e74defafecb2aa0bc\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\89445d5b924ad94744d00f1b6cd2285d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (CxAudMsg) – C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BingDesktopUpdate) – C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Neat Startup Service) – C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (UWS HiPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe (UltiDev LLC)
SRV - (UltiDev Web Server Pro) – C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe (UltiDev LLC)
SRV - (UWS LoPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe (UltiDev LLC)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NSL) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
SRV - (HP DS Service) – C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) – C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (tapklink) – C:\Windows\SysNative\drivers\tapklink.sys (Faveset LLC)
DRV:64bit: - (HPFXBULKLEDM) – C:\Windows\SysNative\drivers\hppdbulkio.sys (Hewlett Packard)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130730.003\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130730.003\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130727.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (lowpp) – C:\Windows\SysWOW64\drivers\lowpp.sys (Lowrance Electronics, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}
IE - HKCU\..\SearchScopes\{9001ECE5-27F9-7260-292B-CF945347FC97}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}:10.15.0.62
FF - prefs.js..extensions.enabledAddons: {739df940-c5ee-4bab-9d7e-270894ae687a}:10.14.380.14
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/08/19 14:23:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\IPSFFPlgn\ [2013/04/23 00:02:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/13 10:22:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/13 10:22:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/07/18 10:40:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions
[2011/06/23 10:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/07/30 09:47:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions
[2013/07/18 10:40:37 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/07/30 09:47:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}
[2013/07/24 10:13:09 | 000,001,793 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Bing.xml
[2013/05/05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml
[2013/03/27 23:15:47 | 000,002,356 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\startnow.xml
[2012/10/19 10:38:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\MARK HUDSON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QJ5BZ23M.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
[2011/12/21 02:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/20 23:30:41 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: TopArcadeHits = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0\
CHR - Extension: RealDownloader = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\

O1 HOSTS File: ([2013/07/29 23:24:08 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll (FreePriceAlerts.com)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: hostpilot.com ([ARCpoint] https in Local intranet)
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} http://192.168.2.119/web/WebClient.cab (WebClient Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.gunbroker.com/WebResource.axd?d…230999680000000 (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F22A54D-AEDC-4C91-AD17-7CB0657B12F0}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BFF0016-01B7-4FE7-8946-570FA6A6F5DC}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF9E37F2-B89B-4AA7-BFEE-EEB3BF7AD7F4}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.L263 - lcodc26x2.dll File not found
Drivers32: vidc.LEAD - LCODCCMP2.DLL File not found
Drivers32: vidc.LSCR - C:\Program Files (x86)\Common Files\RZPPTCodec\Codec\LCodcScr2.dll ()
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/30 09:57:10 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/07/30 09:41:07 | 000,562,042 | —- | C] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/29 23:24:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/07/29 22:41:44 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/07/29 22:41:44 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/07/29 22:41:44 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/07/29 22:37:43 | 000,000,000 | —D | C] – C:\Qoobox
[2013/07/29 22:35:26 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/07/29 22:33:22 | 005,095,176 | R— | C] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:21 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/29 21:07:52 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 21:01:26 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\Documents\Virus Removal
[2013/07/29 18:28:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/28 11:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/24 11:21:34 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Malwarebytes
[2013/07/24 11:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/24 11:21:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/24 11:21:01 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/24 11:21:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/24 11:20:21 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Programs
[2013/07/23 16:52:42 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\NPE
[2013/07/18 15:09:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealZeal Soft
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\RZPPTCodec
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\RealZeal Soft
[2013/07/18 10:48:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIViewer
[2013/07/18 10:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIViewer
[2013/07/18 10:26:26 | 000,033,792 | —- | C] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[2013/07/11 14:35:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 14:35:31 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 14:35:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 14:35:29 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 14:35:28 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 14:35:28 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 14:35:28 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 14:35:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 14:35:28 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 14:35:24 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 14:35:23 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 14:35:23 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 14:35:21 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 11:00:42 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/11 11:00:42 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/11 11:00:40 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/11 11:00:39 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:59:26 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/30 16:48:02 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/30 16:35:01 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2013/07/30 16:34:02 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/30 16:34:02 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/30 14:12:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/30 12:47:02 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/30 12:47:02 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/30 12:36:41 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2013/07/30 10:35:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2013/07/30 09:41:28 | 000,562,042 | —- | M] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/30 09:39:20 | 000,666,633 | —- | M] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 23:24:08 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/07/29 22:33:42 | 005,095,176 | R— | M] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/29 21:08:13 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 18:57:11 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:42 | 000,002,216 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | M] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/28 11:50:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/27 10:07:40 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:06:01 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/23 10:27:35 | 000,797,524 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/23 10:27:35 | 000,674,654 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/23 10:27:35 | 000,125,872 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/23 10:27:00 | 000,020,992 | —- | M] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/22 12:20:29 | 000,000,358 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2013/07/22 12:20:29 | 000,000,139 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2013/07/22 12:10:02 | 000,000,018 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2013/07/18 15:09:18 | 000,002,805 | —- | M] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:05 | 026,710,528 | —- | M] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | M] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/16 22:01:33 | 000,001,732 | —- | M] () – C:\Users\Mark Hudson\Desktop\DvrClient.cfg
[2013/07/16 09:50:52 | 000,006,087 | —- | M] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/07/15 15:01:01 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/07/15 15:01:01 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/07/15 10:49:49 | 000,002,403 | —- | M] () – C:\Users\Mark Hudson\Desktop\Google Chrome.lnk
[2013/07/11 15:37:03 | 000,417,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/30 09:39:15 | 000,666,633 | —- | C] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 22:41:44 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/07/29 22:41:44 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/07/29 22:41:44 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/07/29 22:41:44 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/07/29 22:41:44 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/28 20:36:41 | 000,002,216 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | C] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/27 10:07:38 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:05:57 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/18 15:30:50 | 000,020,992 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/18 15:09:15 | 000,002,805 | —- | C] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:30 | 026,710,528 | —- | C] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | C] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/18 10:26:26 | 001,645,360 | —- | C] () – C:\Windows\SysNative\dmwu.exe
[2013/07/16 09:50:52 | 000,006,087 | —- | C] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/22 20:43:48 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/05/22 20:43:48 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/05/22 20:43:48 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/05/22 20:43:48 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/04/19 10:44:01 | 000,000,358 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2012/10/02 09:00:38 | 000,000,000 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\bibstats
[2012/09/07 08:12:25 | 000,001,940 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2012/07/23 13:22:39 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2012/07/23 13:22:38 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2012/07/23 13:20:41 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2012/07/23 13:20:39 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2012/07/23 13:20:39 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2012/06/10 21:12:47 | 000,004,096 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\keyfile3.drm
[2012/03/27 22:35:43 | 000,000,139 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2012/03/27 22:34:52 | 000,000,018 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2012/02/19 17:31:33 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/02/09 18:20:06 | 000,102,912 | —- | C] () – C:\Windows\agent_x64.exe
[2011/11/17 15:12:42 | 000,000,247 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\kclientgui.ini
[2011/10/10 12:41:33 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/10/10 12:41:33 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/07/29 11:01:50 | 000,007,598 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\Resmon.ResmonCfg

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/14 20:09:30 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Canon
[2013/07/30 16:47:10 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Clip Art Collection
[2011/07/07 11:59:23 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/27 10:20:46 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\IrfanView
[2013/07/25 18:48:53 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\MyPhoneExplorer
[2012/02/09 18:34:40 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Neat
[2012/02/09 18:34:19 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Nuance
[2011/07/07 12:14:06 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PDF Writer
[2013/06/21 22:35:09 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PPTRemote
[2013/06/26 21:04:03 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Samsung
[2012/05/12 16:13:42 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\SmartDraw
[2012/03/08 16:15:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\TaxCut
[2011/06/23 10:48:11 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Thunderbird
[2012/10/06 09:42:48 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Tific
[2012/03/21 09:50:21 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\WeatherBug
[2012/11/15 16:13:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\webex
[2012/03/27 10:14:31 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Winff

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 02:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 22:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 22:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 02:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 02:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 02:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 02:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2013/07/30 17:05:23 | 000,232,816 | —- | M] () MD5=0E6B27795D84EEFE9721F0B056976470 – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: EXPLORER.ZIP >
[2009/06/03 21:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.BAT >
[2013/07/10 12:33:13 | 000,029,141 | —- | M] () MD5=1ACDFEB8A7A728A429476F11E7A24617 – C:\Users\Mark Hudson\AppData\Local\Temp\jrt\iexplore.bat

< MD5 for: IEXPLORE.EXE >
[2012/06/02 06:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 20:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/05/17 18:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/29 00:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012/08/24 02:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2013/02/22 02:04:50 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_0d238c71808d94e7\iexplore.exe
[2012/05/17 17:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/10/08 03:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/06/11 23:41:27 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=2A5F565327BFD679EC5F790DC15BBF25 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2012/08/24 06:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013/04/05 00:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/06/11 19:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/06/11 19:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\erdnt\cache86\iexplore.exe
[2013/06/11 19:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/02/21 23:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_177836c3b4ee56e2\iexplore.exe
[2012/06/02 04:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2013/05/16 20:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2013/02/21 23:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_17f703a2ce14129d\iexplore.exe
[2012/10/08 07:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/05/17 21:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012/08/24 05:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 21:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 07:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012/08/24 02:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/04/30 08:17:39 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/02/02 03:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 22:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013/05/16 22:02:08 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2011/10/17 10:35:25 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/06/28 20:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013/06/11 21:28:00 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Program Files\Internet Explorer\iexplore.exe
[2013/06/11 21:28:00 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2013/04/05 01:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/02/22 02:17:45 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=B21A57AA4CB928059A0C0C58A9E77A02 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_0da2595099b350a2\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/06/02 03:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 22:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/06/12 02:51:43 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=CA88A25280B1D85ED0BC26B042ABBCCF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2013/04/05 02:53:33 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2012/10/08 03:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 02:23:03 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2013/04/30 08:17:47 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2012/06/28 18:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/01/08 19:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/10/17 10:35:15 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/10/08 06:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/05/17 20:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.412.DMP >
[2013/07/28 11:35:28 | 003,849,852 | —- | M] () MD5=7C1462F4CCEAEBD2B8BCD7E7EE2A9743 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.412.dmp
[2013/07/28 11:35:28 | 003,849,852 | —- | M] () MD5=7C1462F4CCEAEBD2B8BCD7E7EE2A9743 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.412.dmp

< MD5 for: IEXPLORE.EXE.MUI >
[2011/10/17 10:35:16 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/10/17 10:35:26 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/04/30 08:17:50 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/04/30 08:17:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/04/30 08:17:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/04/30 08:17:50 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/07/30 17:07:16 | 000,268,934 | —- | M] () MD5=C16F016CDAF7BC24056C013214B35304 – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2013/05/10 02:57:30 | 000,558,879 | —- | M] () MD5=3679F8D3253DC110D1D8F2AE115EE00C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.DAT >
[2013/07/29 02:23:09 | 000,002,235 | —- | M] () MD5=3F56F15AB110188F78E3DCE876FC707E – C:\Users\Mark Hudson\AppData\Local\Temp\jrt\services.dat

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 02:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 02:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.JS >
[2013/06/20 11:12:52 | 000,001,083 | —- | M] () MD5=18272708A717583EBB2AE9712FDA65CD – C:\Program Files (x86)\Microsoft\BingDesktop\Apps\runtime\mocks\services.js
[2010/08/16 14:07:26 | 000,018,674 | —- | M] () MD5=7209830374F12E59D7802B687A5F0542 – C:\Program Files (x86)\Barnes & Noble\BNDesktopReader\HTML\js\services.js

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 02:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 02:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 02:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 02:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 02:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 02:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 02:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 02:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 02:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/07/30 09:44:51 | 000,046,634 | —- | M] () – C:\AdwCleaner[R1].txt
[2013/07/30 09:48:11 | 000,047,175 | —- | M] () – C:\AdwCleaner[S1].txt
[2011/03/30 05:13:11 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2013/07/29 23:40:08 | 000,034,893 | —- | M] () – C:\ComboFix.txt
[2013/07/30 12:36:41 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2011/09/19 10:15:31 | 000,000,040 | —- | M] () – C:\log.txt
[2005/09/23 01:39:38 | 000,894,976 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2013/07/30 12:36:47 | 1856,925,696 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is ACC5-3247
Directory of C:\
07/14/2009 12:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\Program Files\UltiDev
06/28/2012 10:41 PM Web Server [\??\C:\Program Files (x86)\UltiDev\Web Server]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM All Users [C:\ProgramData]
07/14/2009 12:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:08 AM My Music [C:\Users\Default\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Mark Hudson
06/21/2011 04:40 PM Application Data [C:\Users\Mark Hudson\AppData\Roaming]
06/21/2011 04:40 PM Cookies [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Cookies]
06/21/2011 04:40 PM Local Settings [C:\Users\Mark Hudson\AppData\Local]
06/21/2011 04:40 PM My Documents [C:\Users\Mark Hudson\Documents]
06/21/2011 04:40 PM NetHood [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/21/2011 04:40 PM PrintHood [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/21/2011 04:40 PM Recent [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Recent]
06/21/2011 04:40 PM SendTo [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\SendTo]
06/21/2011 04:40 PM Start Menu [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Start Menu]
06/21/2011 04:40 PM Templates [C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Mark Hudson\AppData\Local
06/21/2011 04:40 PM Application Data [C:\Users\Mark Hudson\AppData\Local]
06/21/2011 04:40 PM History [C:\Users\Mark Hudson\AppData\Local\Microsoft\Windows\History]
06/21/2011 04:40 PM Temporary Internet Files [C:\Users\Mark Hudson\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Mark Hudson\Documents
06/21/2011 04:40 PM My Music [C:\Users\Mark Hudson\Music]
06/21/2011 04:40 PM My Pictures [C:\Users\Mark Hudson\Pictures]
06/21/2011 04:40 PM My Videos [C:\Users\Mark Hudson\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 220,952,199,168 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/09/12 15:07:55 | 000,000,221 | -HS- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/07/30 09:39:20 | 000,666,633 | —- | M] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 18:57:11 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/29 22:33:42 | 005,095,176 | R— | M] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/30 09:41:28 | 000,562,042 | —- | M] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/28 11:50:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2011/12/07 00:37:46 | 002,846,720 | —- | M] (微软中国) – C:\Users\Mark Hudson\Desktop\Southcross Cameras.exe
[2013/07/29 21:08:13 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox
    [2013/05/05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml
    O2 - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll (FreePriceAlerts.com)
    
    :Commands
    [EMPTYTEMP]
    [CLEARALLRESTOREPOINTS]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
Conspire,

I think I did this correctly.

I copy & pasted the text in the code box above to OTL and ran a scan, saving the txt log generated. I then re-booted the machine and re-ran the scan without the code box text added, and saved the txt log.

Mark

TL logfile created on: 7/31/2013 2:44:22 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.71 Gb Available Physical Memory | 41.03% Memory free
3.46 Gb Paging File | 1.79 Gb Available in Paging File | 51.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 205.67 Gb Free Space | 72.17% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mark Hudson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\83cfe0422e7e54f3f00107c15a63f1b4\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6da2afd0e57708d41892d9d3e32ba5a3\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f3770f9a13d7516e4c03f23dbd319cba\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\4572de8445038600e4552429b18fbe32\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7546a01feb9d477570b883eec56cc673\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\112f6448b7434699af4bcc05f25ce12b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\64b92e2a22bb8c1e86486bd22828acc5\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c1c41a9e1a25999e74defafecb2aa0bc\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\89445d5b924ad94744d00f1b6cd2285d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (CxAudMsg) – C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BingDesktopUpdate) – C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Neat Startup Service) – C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (UWS HiPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe (UltiDev LLC)
SRV - (UltiDev Web Server Pro) – C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe (UltiDev LLC)
SRV - (UWS LoPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe (UltiDev LLC)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NSL) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
SRV - (HP DS Service) – C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) – C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (tapklink) – C:\Windows\SysNative\drivers\tapklink.sys (Faveset LLC)
DRV:64bit: - (HPFXBULKLEDM) – C:\Windows\SysNative\drivers\hppdbulkio.sys (Hewlett Packard)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130730.032\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130730.032\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130730.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (lowpp) – C:\Windows\SysWOW64\drivers\lowpp.sys (Lowrance Electronics, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}
IE - HKCU\..\SearchScopes\{9001ECE5-27F9-7260-292B-CF945347FC97}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}:10.15.0.62
FF - prefs.js..extensions.enabledAddons: {739df940-c5ee-4bab-9d7e-270894ae687a}:10.14.380.14
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/08/19 14:23:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\IPSFFPlgn\ [2013/04/23 00:02:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/13 10:22:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/13 10:22:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/07/18 10:40:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions
[2011/06/23 10:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/07/30 09:47:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions
[2013/07/18 10:40:37 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/07/30 09:47:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}
[2013/07/24 10:13:09 | 000,001,793 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Bing.xml
[2013/05/05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml
[2013/03/27 23:15:47 | 000,002,356 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\startnow.xml
[2012/10/19 10:38:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\MARK HUDSON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QJ5BZ23M.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
[2011/12/21 02:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/20 23:30:41 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: TopArcadeHits = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0\
CHR - Extension: RealDownloader = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\

O1 HOSTS File: ([2013/07/29 23:24:08 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll (FreePriceAlerts.com)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: hostpilot.com ([ARCpoint] https in Local intranet)
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} http://192.168.2.119/web/WebClient.cab (WebClient Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.gunbroker.com/WebResource.axd?d…230999680000000 (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F22A54D-AEDC-4C91-AD17-7CB0657B12F0}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BFF0016-01B7-4FE7-8946-570FA6A6F5DC}: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF9E37F2-B89B-4AA7-BFEE-EEB3BF7AD7F4}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[CLEARALLRESTOREPOINTS]
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/30 09:57:10 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/07/30 09:41:07 | 000,562,042 | —- | C] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/29 23:24:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/07/29 22:41:44 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/07/29 22:41:44 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/07/29 22:41:44 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/07/29 22:37:43 | 000,000,000 | —D | C] – C:\Qoobox
[2013/07/29 22:35:26 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/07/29 22:33:22 | 005,095,176 | R— | C] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:21 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/29 21:07:52 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 21:01:26 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\Documents\Virus Removal
[2013/07/29 18:28:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/28 11:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/24 11:21:34 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Malwarebytes
[2013/07/24 11:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/24 11:21:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/24 11:21:01 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/24 11:21:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/24 11:20:21 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Programs
[2013/07/23 16:52:42 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\NPE
[2013/07/18 15:09:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealZeal Soft
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\RZPPTCodec
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\RealZeal Soft
[2013/07/18 10:48:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIViewer
[2013/07/18 10:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIViewer
[2013/07/18 10:26:26 | 000,033,792 | —- | C] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[2013/07/11 14:35:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 14:35:31 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 14:35:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 14:35:29 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 14:35:28 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 14:35:28 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 14:35:28 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 14:35:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 14:35:28 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 14:35:24 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 14:35:23 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 14:35:23 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 14:35:21 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 11:00:42 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/11 11:00:42 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/11 11:00:40 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/11 11:00:39 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:59:26 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/31 14:48:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/31 14:35:04 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2013/07/31 14:34:06 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/31 14:23:31 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/31 14:23:31 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/31 14:13:42 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/31 14:13:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/31 14:13:17 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2013/07/30 10:35:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2013/07/30 09:41:28 | 000,562,042 | —- | M] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/30 09:39:20 | 000,666,633 | —- | M] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 23:24:08 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/07/29 22:33:42 | 005,095,176 | R— | M] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/29 21:08:13 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 18:57:11 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:42 | 000,002,216 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | M] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/28 11:50:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/27 10:07:40 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:06:01 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/23 10:27:35 | 000,797,524 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/23 10:27:35 | 000,674,654 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/23 10:27:35 | 000,125,872 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/23 10:27:00 | 000,020,992 | —- | M] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/22 12:20:29 | 000,000,358 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2013/07/22 12:20:29 | 000,000,139 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2013/07/22 12:10:02 | 000,000,018 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2013/07/18 15:09:18 | 000,002,805 | —- | M] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:05 | 026,710,528 | —- | M] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | M] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/16 22:01:33 | 000,001,732 | —- | M] () – C:\Users\Mark Hudson\Desktop\DvrClient.cfg
[2013/07/16 09:50:52 | 000,006,087 | —- | M] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/07/15 15:01:01 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/07/15 15:01:01 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/07/15 10:49:49 | 000,002,403 | —- | M] () – C:\Users\Mark Hudson\Desktop\Google Chrome.lnk
[2013/07/11 15:37:03 | 000,417,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/30 09:39:15 | 000,666,633 | —- | C] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 22:41:44 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/07/29 22:41:44 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/07/29 22:41:44 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/07/29 22:41:44 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/07/29 22:41:44 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/28 20:36:41 | 000,002,216 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | C] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/27 10:07:38 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:05:57 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/18 15:30:50 | 000,020,992 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/18 15:09:15 | 000,002,805 | —- | C] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:30 | 026,710,528 | —- | C] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | C] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/18 10:26:26 | 001,645,360 | —- | C] () – C:\Windows\SysNative\dmwu.exe
[2013/07/16 09:50:52 | 000,006,087 | —- | C] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/22 20:43:48 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/05/22 20:43:48 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/05/22 20:43:48 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/05/22 20:43:48 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/04/19 10:44:01 | 000,000,358 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2012/10/02 09:00:38 | 000,000,000 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\bibstats
[2012/09/07 08:12:25 | 000,001,940 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2012/07/23 13:22:39 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2012/07/23 13:22:38 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2012/07/23 13:20:41 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2012/07/23 13:20:39 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2012/07/23 13:20:39 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2012/06/10 21:12:47 | 000,004,096 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\keyfile3.drm
[2012/03/27 22:35:43 | 000,000,139 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2012/03/27 22:34:52 | 000,000,018 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2012/02/19 17:31:33 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/02/09 18:20:06 | 000,102,912 | —- | C] () – C:\Windows\agent_x64.exe
[2011/11/17 15:12:42 | 000,000,247 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\kclientgui.ini
[2011/10/10 12:41:33 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/10/10 12:41:33 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/07/29 11:01:50 | 000,007,598 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\Resmon.ResmonCfg

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/14 20:09:30 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Canon
[2013/07/30 17:58:15 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Clip Art Collection
[2011/07/07 11:59:23 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/27 10:20:46 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\IrfanView
[2013/07/25 18:48:53 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\MyPhoneExplorer
[2012/02/09 18:34:40 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Neat
[2012/02/09 18:34:19 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Nuance
[2011/07/07 12:14:06 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PDF Writer
[2013/06/21 22:35:09 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PPTRemote
[2013/06/26 21:04:03 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Samsung
[2012/05/12 16:13:42 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\SmartDraw
[2012/03/08 16:15:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\TaxCut
[2011/06/23 10:48:11 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Thunderbird
[2012/10/06 09:42:48 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Tific
[2012/03/21 09:50:21 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\WeatherBug
[2012/11/15 16:13:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\webex
[2012/03/27 10:14:31 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Winff

========== Purity Check ==========



========== Custom Scans ==========

< :OTL >
[2009/07/14 00:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009/07/14 00:08:49 | 000,032,530 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/07/09 22:27:49 | 000,000,880 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2011/07/09 22:27:50 | 000,000,932 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2011/09/29 12:44:56 | 000,000,904 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2011/09/29 12:44:57 | 000,000,908 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012/03/29 08:54:18 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job

< 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX >

< FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox >

< FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox >

< [2013/05/05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml >
Invalid Switch: 05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml

< O2 - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll (FreePriceAlerts.com) >

< >

< :Commands >

< [EMPTYTEMP] >

< End of report >



REBOOT


OTL logfile created on: 7/31/2013 4:25:40 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 42.88% Memory free
3.46 Gb Paging File | 1.80 Gb Available in Paging File | 52.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 205.50 Gb Free Space | 72.11% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mark Hudson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\83cfe0422e7e54f3f00107c15a63f1b4\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6da2afd0e57708d41892d9d3e32ba5a3\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f3770f9a13d7516e4c03f23dbd319cba\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\4572de8445038600e4552429b18fbe32\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7546a01feb9d477570b883eec56cc673\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\112f6448b7434699af4bcc05f25ce12b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\64b92e2a22bb8c1e86486bd22828acc5\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c1c41a9e1a25999e74defafecb2aa0bc\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\89445d5b924ad94744d00f1b6cd2285d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (CxAudMsg) – C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BingDesktopUpdate) – C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Neat Startup Service) – C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (UWS HiPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe (UltiDev LLC)
SRV - (UltiDev Web Server Pro) – C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe (UltiDev LLC)
SRV - (UWS LoPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe (UltiDev LLC)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NSL) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
SRV - (HP DS Service) – C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) – C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (tapklink) – C:\Windows\SysNative\drivers\tapklink.sys (Faveset LLC)
DRV:64bit: - (HPFXBULKLEDM) – C:\Windows\SysNative\drivers\hppdbulkio.sys (Hewlett Packard)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130730.032\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130730.032\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130730.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (lowpp) – C:\Windows\SysWOW64\drivers\lowpp.sys (Lowrance Electronics, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}
IE - HKCU\..\SearchScopes\{9001ECE5-27F9-7260-292B-CF945347FC97}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}:10.15.0.62
FF - prefs.js..extensions.enabledAddons: {739df940-c5ee-4bab-9d7e-270894ae687a}:10.14.380.14
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/08/19 14:23:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\IPSFFPlgn\ [2013/04/23 00:02:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/13 10:22:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/13 10:22:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/07/18 10:40:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions
[2011/06/23 10:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/07/30 09:47:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions
[2013/07/18 10:40:37 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/07/30 09:47:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}
[2013/07/24 10:13:09 | 000,001,793 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Bing.xml
[2013/05/05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml
[2013/03/27 23:15:47 | 000,002,356 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\startnow.xml
[2012/10/19 10:38:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\MARK HUDSON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QJ5BZ23M.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
[2011/12/21 02:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/20 23:30:41 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: TopArcadeHits = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0\
CHR - Extension: RealDownloader = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\

O1 HOSTS File: ([2013/07/29 23:24:08 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll (FreePriceAlerts.com)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: hostpilot.com ([ARCpoint] https in Local intranet)
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} http://192.168.2.119/web/WebClient.cab (WebClient Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.gunbroker.com/WebResource.axd?d…230999680000000 (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F22A54D-AEDC-4C91-AD17-7CB0657B12F0}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BFF0016-01B7-4FE7-8946-570FA6A6F5DC}: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF9E37F2-B89B-4AA7-BFEE-EEB3BF7AD7F4}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/07/30 09:57:10 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/07/30 09:41:07 | 000,562,042 | —- | C] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/29 23:24:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/07/29 22:41:44 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/07/29 22:41:44 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/07/29 22:41:44 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/07/29 22:37:43 | 000,000,000 | —D | C] – C:\Qoobox
[2013/07/29 22:35:26 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/07/29 22:33:22 | 005,095,176 | R— | C] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:21 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/29 21:07:52 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 21:01:26 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\Documents\Virus Removal
[2013/07/29 18:28:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/28 11:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/24 11:21:34 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Malwarebytes
[2013/07/24 11:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/24 11:21:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/24 11:21:01 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/24 11:21:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/24 11:20:21 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Programs
[2013/07/23 16:52:42 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\NPE
[2013/07/18 15:09:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealZeal Soft
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\RZPPTCodec
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\RealZeal Soft
[2013/07/18 10:48:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIViewer
[2013/07/18 10:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIViewer
[2013/07/18 10:26:26 | 000,033,792 | —- | C] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[2013/07/11 14:35:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 14:35:31 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 14:35:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 14:35:29 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 14:35:28 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 14:35:28 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 14:35:28 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 14:35:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 14:35:28 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 14:35:24 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 14:35:23 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 14:35:23 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 14:35:21 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 11:00:42 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/11 11:00:42 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/11 11:00:40 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/11 11:00:39 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:59:26 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/07/31 16:35:03 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2013/07/31 16:34:06 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/31 16:34:05 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/31 16:07:13 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/31 16:07:13 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/31 15:58:54 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/31 15:58:45 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2013/07/31 14:48:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/30 10:35:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2013/07/30 09:41:28 | 000,562,042 | —- | M] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/30 09:39:20 | 000,666,633 | —- | M] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 23:24:08 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/07/29 22:33:42 | 005,095,176 | R— | M] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/29 21:08:13 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 18:57:11 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:42 | 000,002,216 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | M] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/28 11:50:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/27 10:07:40 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:06:01 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/23 10:27:35 | 000,797,524 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/23 10:27:35 | 000,674,654 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/23 10:27:35 | 000,125,872 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/23 10:27:00 | 000,020,992 | —- | M] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/22 12:20:29 | 000,000,358 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2013/07/22 12:20:29 | 000,000,139 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2013/07/22 12:10:02 | 000,000,018 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2013/07/18 15:09:18 | 000,002,805 | —- | M] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:05 | 026,710,528 | —- | M] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | M] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/16 22:01:33 | 000,001,732 | —- | M] () – C:\Users\Mark Hudson\Desktop\DvrClient.cfg
[2013/07/16 09:50:52 | 000,006,087 | —- | M] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/07/15 15:01:01 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/07/15 15:01:01 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/07/15 10:49:49 | 000,002,403 | —- | M] () – C:\Users\Mark Hudson\Desktop\Google Chrome.lnk
[2013/07/11 15:37:03 | 000,417,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/30 09:39:15 | 000,666,633 | —- | C] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 22:41:44 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/07/29 22:41:44 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/07/29 22:41:44 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/07/29 22:41:44 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/07/29 22:41:44 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/28 20:36:41 | 000,002,216 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | C] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/27 10:07:38 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:05:57 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/18 15:30:50 | 000,020,992 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/18 15:09:15 | 000,002,805 | —- | C] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:30 | 026,710,528 | —- | C] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | C] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/18 10:26:26 | 001,645,360 | —- | C] () – C:\Windows\SysNative\dmwu.exe
[2013/07/16 09:50:52 | 000,006,087 | —- | C] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/22 20:43:48 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/05/22 20:43:48 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/05/22 20:43:48 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/05/22 20:43:48 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/04/19 10:44:01 | 000,000,358 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2012/10/02 09:00:38 | 000,000,000 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\bibstats
[2012/09/07 08:12:25 | 000,001,940 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2012/07/23 13:22:39 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2012/07/23 13:22:38 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2012/07/23 13:20:41 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2012/07/23 13:20:39 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2012/07/23 13:20:39 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2012/06/10 21:12:47 | 000,004,096 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\keyfile3.drm
[2012/03/27 22:35:43 | 000,000,139 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2012/03/27 22:34:52 | 000,000,018 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2012/02/19 17:31:33 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/02/09 18:20:06 | 000,102,912 | —- | C] () – C:\Windows\agent_x64.exe
[2011/11/17 15:12:42 | 000,000,247 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\kclientgui.ini
[2011/10/10 12:41:33 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/10/10 12:41:33 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/07/29 11:01:50 | 000,007,598 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\Resmon.ResmonCfg

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/14 20:09:30 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Canon
[2013/07/30 17:58:15 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Clip Art Collection
[2011/07/07 11:59:23 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/27 10:20:46 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\IrfanView
[2013/07/25 18:48:53 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\MyPhoneExplorer
[2012/02/09 18:34:40 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Neat
[2012/02/09 18:34:19 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Nuance
[2011/07/07 12:14:06 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PDF Writer
[2013/06/21 22:35:09 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PPTRemote
[2013/06/26 21:04:03 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Samsung
[2012/05/12 16:13:42 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\SmartDraw
[2012/03/08 16:15:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\TaxCut
[2011/06/23 10:48:11 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Thunderbird
[2012/10/06 09:42:48 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Tific
[2012/03/21 09:50:21 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\WeatherBug
[2012/11/15 16:13:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\webex
[2012/03/27 10:14:31 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Winff

========== Purity Check ==========



< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI