This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Notebook Acting Funny [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:14:53 AM, on 8/19/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16502)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\lmi_rescue.exe
C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe
C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\lmi_rescue.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\SRE Lab\Desktop\HJT\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\RunOnce: [*LogMeInRescue_2078858596] "C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\lmi_rescue.exe" -runonce reboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: CinemaNow Service - CinemaNow, Inc. - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
O23 - Service: CyberLink Product - 2010/09/16 01:59:19 (CLKMSVC10_C6F09094) - CyberLink - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 13019 bytes
Hi EricWoods,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

[external image: Posted Image] Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

[external image: Posted Image] aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================
[external image: Posted Image] OTL

Download OTL to your desktop.
  • Make sure all other windows are closed and to let it run uninterrupted.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    • You may need two posts to fit them both in.
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
Ran everything successfully except aswmbr. Whatever it's finding keeps rebooting the notebook during the scan. It listed several entries in red as infected before one reboot. I captured what I could before one of the reboots.

Results of screen317's Security Check version 0.99.72
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
McAfee Anti-Virus and Anti-Spyware
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 25
Adobe Flash Player 10 Flash Player out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Google Chrome 28.0.1500.72
Google Chrome 28.0.1500.95
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

OTL logfile created on: 8/20/2013 1:08:52 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\SRE Lab\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.80 Gb Total Physical Memory | 5.75 Gb Available Physical Memory | 73.68% Memory free
15.60 Gb Paging File | 13.21 Gb Available in Paging File | 84.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 573.97 Gb Total Space | 370.46 Gb Free Space | 64.54% Space Free | Partition Type: NTFS
Drive D: | 21.91 Gb Total Space | 3.19 Gb Free Space | 14.58% Space Free | Partition Type: NTFS
Drive E: | 627.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SRELAB-HP | User Name: SRE Lab | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\SRE Lab\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\lmi_rescue.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (0176811377020729mcinstcleanup) – C:\Windows\Temp\0176811377020729mcinst.exe (McAfee, Inc.)
SRV - (CLKMSVC10_C6F09094) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe (CyberLink)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe ()
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (CinemaNow Service) – C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (BrYNSvc) – C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HipShieldK) – C:\Windows\SysNative\drivers\HipShieldK.sys (McAfee, Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}
IE:64bit: - HKLM\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{75C5F1BF-1072-4836-9C50-0872C11264E0}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE:64bit: - HKLM\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}
IE - HKLM\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{75C5F1BF-1072-4836-9C50-0872C11264E0}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKLM\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss…56&tsp;=4962
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTer…56&tsp;=4962
IE - HKCU\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{75C5F1BF-1072-4836-9C50-0872C11264E0}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKCU\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/09/16 04:18:05 | 000,000,000 | —D | M]

[2013/08/02 15:12:39 | 000,000,000 | —D | M] (No name found) – C:\Users\SRE Lab\AppData\Roaming\mozilla\Extensions
[2013/08/02 15:11:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Skype Click to Call = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.10.0.13089_0\
CHR - Extension: Gmail = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKCU..\RunOnce: [*LogMeInRescue_1564852023] C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\lmi_rescue.exe (LogMeIn, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83B1974F-FA01-48E8-BCBA-ED025FD0DFA8}: DhcpNameServer = 10.4.40.11 10.4.40.17
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFD09DC9-BBB7-4ECF-B449-DE3B7FCEDD22}: DhcpNameServer = 8.8.8.8
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/20 00:14:28 | 000,000,043 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{df1846ac-78ea-11e1-bb44-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{df1846ac-78ea-11e1-bb44-806e6f6e6963}\Shell\AutoRun\command - "" = E:\start.exe – [2010/04/01 03:40:27 | 002,052,921 | R— | M] (Macromedia, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.dvacm - c:\Program Files (x86)\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/20 13:01:26 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\SRE Lab\Desktop\OTL.exe
[2013/08/20 10:54:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/08/19 00:12:04 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\SRE Lab\Desktop\HiJackThis.exe
[2013/08/18 22:41:43 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet
[2013/08/15 19:47:44 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/15 19:47:44 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/15 19:47:43 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/15 19:47:43 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/15 19:47:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/15 19:47:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/15 19:47:43 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/15 19:47:43 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/15 19:47:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/15 19:47:40 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/15 19:47:40 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/15 19:47:40 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/15 19:47:40 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/15 19:47:40 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/15 19:47:39 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/14 17:15:08 | 001,472,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/08/14 17:15:08 | 000,224,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/08/14 17:15:07 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/08/14 17:14:30 | 001,888,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/14 17:14:30 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/14 17:14:29 | 001,217,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/08/14 17:14:24 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/08/14 17:14:23 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/08/14 17:14:22 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/14 17:14:22 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/08/14 17:14:21 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/08/14 17:14:20 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/08/14 17:14:15 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/08/14 17:14:14 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/08/14 17:14:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/08/14 17:14:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/08/10 00:44:55 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Movdap
[2013/08/10 00:44:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Movdap
[2013/08/09 12:33:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
[2013/08/09 12:29:29 | 000,000,000 | —D | C] – C:\Brother
[2013/08/09 12:29:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Browny02
[2013/08/09 12:29:17 | 000,025,299 | —- | C] (Brother Industries, Ltd) – C:\Windows\SysWow64\BRLM03A.DLL
[2013/08/09 12:29:04 | 000,217,088 | —- | C] (brother) – C:\Windows\SysWow64\NSSearch.dll
[2013/08/09 12:29:04 | 000,005,120 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2L.dll
[2013/08/09 12:29:04 | 000,002,560 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2S.dll
[2013/08/09 12:29:03 | 000,073,728 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2.dll
[2013/08/09 12:29:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Brother
[2013/08/07 21:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/08/07 21:49:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/08/07 21:48:54 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Panasonic
[2013/08/07 18:26:58 | 000,501,912 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK2.dll
[2013/08/07 18:26:58 | 000,120,992 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EpPicPrt.dll
[2013/08/07 18:26:58 | 000,108,704 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICEntry.dll
[2013/08/07 18:26:58 | 000,080,024 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK.dll
[2013/08/07 18:26:57 | 000,071,840 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EPPicMgr.dll
[2013/08/07 18:26:56 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\InstallShield
[2013/08/07 18:25:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Panasonic
[2013/08/07 18:25:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2013/08/04 19:08:30 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Ulead Systems
[2013/08/02 15:33:24 | 000,000,000 | —D | C] – C:\Windows\en
[2013/08/02 15:33:12 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013/08/02 15:31:52 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2013/08/02 15:30:20 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/08/02 15:30:20 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/08/02 15:30:20 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/08/02 15:30:20 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/08/02 15:30:19 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/08/02 15:30:19 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/08/02 15:30:17 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/08/02 15:30:17 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/08/02 15:18:00 | 001,239,536 | —- | C] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web(1).exe
[2013/08/02 15:12:39 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Mozilla
[2013/08/02 15:11:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/08/02 15:11:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\searchplugins
[2013/08/02 15:11:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Extensions
[2013/08/02 15:11:47 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
[2013/08/02 15:11:44 | 000,000,000 | —D | C] – C:\ProgramData\BrowserDefender
[2013/08/02 15:11:30 | 001,239,536 | —- | C] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web.exe
[2013/08/02 15:11:22 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Babylon
[2013/08/02 15:11:22 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/08/02 15:09:37 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2013/08/02 15:09:37 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2013/08/02 15:09:35 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2013/08/02 15:09:35 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2013/08/02 15:08:07 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Windows Live
[2013/08/02 15:07:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyPC Backup
[2013/08/02 15:07:11 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/08/02 15:06:51 | 000,000,000 | —D | C] – C:\ProgramData\Tarma Installer
[2013/08/02 13:12:28 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Apple Computer
[2013/08/02 13:12:28 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Apple Computer
[2013/08/02 13:12:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/08/02 13:11:23 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013/08/02 13:11:23 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2013/08/02 13:10:42 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/08/02 13:09:57 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Apple
[2013/08/02 13:09:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/08/02 13:09:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/08/02 13:08:58 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/08/02 13:08:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/08/02 13:08:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/08/02 13:08:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/08/01 01:48:54 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Adobe_Systems_Incorporate
[2013/08/01 01:48:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2013/08/01 01:48:40 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Documents\My Digital Editions
[2013/08/01 01:28:51 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Documents\JTharmonies_data
[2013/08/01 01:27:02 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Audacity
[2013/08/01 01:26:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/08/01 01:26:12 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Programs
[2013/07/29 17:59:03 | 000,000,000 | —D | C] – C:\ProgramData\Brother
[2013/07/24 20:22:52 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Microsoft Games
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/20 13:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\SRE Lab\Desktop\OTL.exe
[2013/08/20 12:49:30 | 000,891,115 | —- | M] () – C:\Users\SRE Lab\Desktop\SecurityCheck.exe
[2013/08/20 12:24:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/20 12:24:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/20 12:17:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/20 11:43:19 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/20 11:43:19 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/20 11:42:10 | 000,730,320 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/20 11:42:10 | 000,627,082 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/20 11:42:10 | 000,107,366 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/20 10:54:29 | 000,001,828 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2013/08/19 16:50:02 | 1988,513,791 | -HS- | M] () – C:\hiberfil.sys
[2013/08/19 00:12:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\SRE Lab\Desktop\HiJackThis.exe
[2013/08/16 00:29:41 | 000,448,664 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/08/09 13:11:04 | 001,127,543 | —- | M] () – C:\Users\SRE Lab\Documents\TERMS OF USE - READ ME.pdf
[2013/08/09 13:11:04 | 000,325,187 | —- | M] () – C:\Users\SRE Lab\Documents\KB Fonts Button.png
[2013/08/09 13:11:04 | 000,021,088 | —- | M] () – C:\Users\SRE Lab\Documents\KBPlanetEarth.ttf
[2013/08/09 12:33:28 | 000,002,136 | —- | M] () – C:\Users\Public\Desktop\Brother Creative Center.lnk
[2013/08/07 21:50:10 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/08/05 01:16:43 | 000,000,333 | —- | M] () – C:\Windows\BRCALIB.INI
[2013/08/04 19:06:51 | 000,034,026 | —- | M] () – C:\Users\SRE Lab\Documents\Beautybeast.wlmp
[2013/08/02 15:18:00 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web(1).exe
[2013/08/02 15:11:30 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web.exe
[2013/08/02 13:20:17 | 005,451,055 | —- | M] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991).mp3
[2013/08/02 13:12:26 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/02 13:03:31 | 000,000,068 | —- | M] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991) - YouTube.url
[2013/08/01 01:48:43 | 000,002,236 | —- | M] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,212 | —- | M] () – C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:28:51 | 000,003,522 | —- | M] () – C:\Users\SRE Lab\Documents\JTharmonies.aup
[2013/08/01 01:26:37 | 000,001,003 | —- | M] () – C:\Users\SRE Lab\Desktop\Audacity.lnk
[2013/08/01 00:02:27 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/29 17:59:03 | 000,000,410 | —- | M] () – C:\Windows\BRWMARK.INI
[2013/07/28 02:06:15 | 000,003,029 | —- | M] () – C:\Users\SRE Lab\Desktop\Microsoft Outlook 2010.lnk
[2013/07/25 04:25:54 | 001,888,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/25 03:57:27 | 001,620,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/24 22:37:25 | 002,312,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/24 22:29:41 | 001,494,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/07/24 22:29:21 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/07/24 22:28:46 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/07/24 22:28:31 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/07/24 22:28:27 | 000,816,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/24 22:28:18 | 000,729,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/24 22:27:29 | 000,096,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/07/24 22:26:53 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/24 21:25:30 | 001,427,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/07/24 21:24:39 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/07/24 21:23:59 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/07/24 21:23:51 | 000,717,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/24 21:22:47 | 000,073,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/07/24 21:22:04 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/24 01:14:31 | 000,001,097 | —- | M] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/20 12:50:09 | 000,891,115 | —- | C] () – C:\Users\SRE Lab\Desktop\SecurityCheck.exe
[2013/08/09 12:33:28 | 000,002,136 | —- | C] () – C:\Users\Public\Desktop\Brother Creative Center.lnk
[2013/08/09 12:29:12 | 000,000,050 | —- | C] () – C:\Windows\SysNative\BRADM10A.DAT
[2013/08/07 21:50:10 | 000,001,845 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/08/07 18:26:58 | 000,111,932 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2013/08/07 18:26:58 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2013/08/07 18:26:58 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2013/08/07 18:26:58 | 000,026,154 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2013/08/07 18:26:58 | 000,024,903 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2013/08/07 18:26:58 | 000,021,390 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2013/08/07 18:26:58 | 000,020,148 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2013/08/07 18:26:58 | 000,011,811 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2013/08/07 18:26:58 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2013/08/07 18:26:58 | 000,001,146 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2013/08/07 18:26:58 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2013/08/07 18:26:58 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2013/08/07 18:26:58 | 000,001,136 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2013/08/07 18:26:58 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2013/08/07 18:26:58 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2013/08/07 18:26:58 | 000,001,120 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2013/08/07 18:26:58 | 000,001,107 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2013/08/07 18:26:58 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2013/08/07 18:26:58 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2013/08/07 18:26:57 | 000,013,732 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_EN.cfg
[2013/08/07 18:26:57 | 000,006,442 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_IT.cfg
[2013/08/07 18:26:57 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_PT.cfg
[2013/08/07 18:26:57 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_BP.cfg
[2013/08/07 18:26:57 | 000,006,335 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_GE.cfg
[2013/08/07 18:26:57 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_FR.cfg
[2013/08/07 18:26:57 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_CF.cfg
[2013/08/07 18:26:57 | 000,006,122 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_DU.cfg
[2013/08/07 18:26:57 | 000,006,103 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_ES.cfg
[2013/08/07 18:26:57 | 000,005,817 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_KO.cfg
[2013/08/07 18:26:57 | 000,005,436 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_SC.cfg
[2013/08/07 18:26:57 | 000,002,889 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_RU.cfg
[2013/08/07 18:26:57 | 000,002,426 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_TC.cfg
[2013/08/02 16:04:06 | 000,034,026 | —- | C] () – C:\Users\SRE Lab\Documents\Beautybeast.wlmp
[2013/08/02 15:33:10 | 000,001,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2013/08/02 15:33:02 | 000,001,374 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2013/08/02 15:32:46 | 000,001,458 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013/08/02 15:32:26 | 000,002,486 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013/08/02 13:20:01 | 005,451,055 | —- | C] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991).mp3
[2013/08/02 13:12:26 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/02 13:09:56 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/08/02 13:03:31 | 000,000,068 | —- | C] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991) - YouTube.url
[2013/08/01 01:48:43 | 000,002,236 | —- | C] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,224 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,212 | —- | C] () – C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:28:51 | 000,003,522 | —- | C] () – C:\Users\SRE Lab\Documents\JTharmonies.aup
[2013/08/01 01:26:37 | 000,001,015 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/08/01 01:26:37 | 000,001,003 | —- | C] () – C:\Users\SRE Lab\Desktop\Audacity.lnk
[2013/07/29 18:05:13 | 000,000,333 | —- | C] () – C:\Windows\BRCALIB.INI
[2013/07/29 17:59:03 | 000,000,410 | —- | C] () – C:\Windows\BRWMARK.INI
[2013/07/28 02:06:15 | 000,003,029 | —- | C] () – C:\Users\SRE Lab\Desktop\Microsoft Outlook 2010.lnk
[2013/07/25 12:19:06 | 000,021,088 | —- | C] () – C:\Users\SRE Lab\Documents\KBPlanetEarth.ttf
[2013/07/24 01:14:31 | 000,001,097 | —- | C] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2012/12/03 08:42:50 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2012/12/03 08:42:50 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\BRLMW03A.INI

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/08/01 01:28:51 | 000,000,000 | —D | M] – C:\Users\SRE Lab\AppData\Roaming\Audacity
[2013/08/02 15:11:22 | 000,000,000 | —D | M] – C:\Users\SRE Lab\AppData\Roaming\Babylon
[2012/03/28 11:35:37 | 000,000,000 | —D | M] – C:\Users\SRE Lab\AppData\Roaming\DigitalPersona
[2013/08/18 16:10:05 | 000,000,000 | —D | M] – C:\Users\SRE Lab\AppData\Roaming\Movdap
[2013/08/19 16:43:03 | 000,000,000 | —D | M] – C:\Users\SRE Lab\AppData\Roaming\Spotify
[2013/08/04 19:08:30 | 000,000,000 | —D | M] – C:\Users\SRE Lab\AppData\Roaming\Ulead Systems
[2013/07/20 16:56:32 | 000,000,000 | —D | M] – C:\Users\SRE Lab\AppData\Roaming\WildTangent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/07/20 01:37:07 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/07/20 01:33:51 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/07/20 01:37:07 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/07/20 01:33:51 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/07/20 01:37:07 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/07/20 01:33:51 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/07/20 01:37:07 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/07/20 01:33:51 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.ZIP >
[2009/06/03 23:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2013/03/03 23:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_1a42c5438bf82907\iexplore.exe
[2013/07/24 21:48:45 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=139C8953AC56A9E559C7DEF07BC45ED7 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20613_none_183fb41ecdde0028\iexplore.exe
[2009/07/13 20:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2013/07/24 23:00:18 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=536B5973A34DDAA6E16AC8248B726BD0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20613_none_0deb09cc997d3e2d\iexplore.exe
[2013/07/24 21:42:37 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=57EC630DBD5F0713E77CB3540AB80A8E – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/07/24 21:42:37 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=57EC630DBD5F0713E77CB3540AB80A8E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16502_none_17bfe6f5b4b92b16\iexplore.exe
[2013/03/02 00:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_19d1c74872c7a039\iexplore.exe
[2010/11/20 08:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013/03/02 00:50:08 | 000,696,480 | —- | M] (Microsoft Corporation) MD5=AFB0FE34A9B7F1B7A70276B9C1A78114 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_0f7d1cf63e66de3e\iexplore.exe
[2013/07/16 16:25:20 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=AFF2C99AD2C599108B6BD9E77C24B463 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_0d0dec99809dccc9\iexplore.exe
[2013/03/04 00:42:51 | 000,696,464 | —- | M] (Microsoft Corporation) MD5=B1B17B56E0F9AE84A1F75E757217154E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_0fee1af15797670c\iexplore.exe
[2010/11/20 07:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/07/16 16:25:22 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_176296ebb4fe8ec4\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2013/07/24 22:58:46 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=FA5B33E7BB143BCE846C303B528E8D62 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/24 22:58:46 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=FA5B33E7BB143BCE846C303B528E8D62 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16502_none_0d6b3ca38058691b\iexplore.exe

< MD5 for: IEXPLORE.EXE.8332.HTML >
[2013/08/11 12:47:48 | 000,001,077 | —- | M] () MD5=0A170ED6EBCB531315E62B64806C108E – C:\Users\SRE Lab\AppData\Local\Temp\Low\__skype_toolbar_v5_logs\html\iexplore.exe.8332.html

< MD5 for: IEXPLORE.EXE.8524.HTML >
[2013/08/11 12:53:00 | 000,001,077 | —- | M] () MD5=0A170ED6EBCB531315E62B64806C108E – C:\Users\SRE Lab\AppData\Local\Temp\Low\__skype_toolbar_v5_logs\html\iexplore.exe.8524.html

< MD5 for: IEXPLORE.EXE.MUI >
[2013/07/16 16:25:20 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/16 16:25:20 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2013/07/16 16:25:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/16 16:25:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 21:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010/07/20 01:37:07 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010/07/20 01:37:07 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 21:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2013/08/19 16:50:02 | 1988,513,791 | -HS- | M] () – C:\hiberfil.sys
[2013/08/19 16:50:10 | 4083,007,487 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2013/02/06 00:56:16 | 000,322,048 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is CA5D-3C54
Directory of C:\
07/14/2009 12:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM All Users [C:\ProgramData]
07/14/2009 12:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:08 AM My Music [C:\Users\Default\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\SRE Lab
03/28/2012 11:35 AM Application Data [C:\Users\SRE Lab\AppData\Roaming]
03/28/2012 11:35 AM Cookies [C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Cookies]
03/28/2012 11:35 AM Local Settings [C:\Users\SRE Lab\AppData\Local]
03/28/2012 11:35 AM My Documents [C:\Users\SRE Lab\Documents]
03/28/2012 11:35 AM NetHood [C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
03/28/2012 11:35 AM PrintHood [C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
03/28/2012 11:35 AM Recent [C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Recent]
03/28/2012 11:35 AM SendTo [C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\SendTo]
03/28/2012 11:35 AM Start Menu [C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu]
03/28/2012 11:35 AM Templates [C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\SRE Lab\AppData\Local
03/28/2012 11:35 AM Application Data [C:\Users\SRE Lab\AppData\Local]
03/28/2012 11:35 AM History [C:\Users\SRE Lab\AppData\Local\Microsoft\Windows\History]
03/28/2012 11:35 AM Temporary Internet Files [C:\Users\SRE Lab\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\SRE Lab\Documents
03/28/2012 11:35 AM My Music [C:\Users\SRE Lab\Music]
03/28/2012 11:35 AM My Pictures [C:\Users\SRE Lab\Pictures]
03/28/2012 11:35 AM My Videos [C:\Users\SRE Lab\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
09/16/2010 04:18 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
09/16/2010 04:18 AM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
09/16/2010 04:18 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
09/16/2010 04:18 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2010 04:18 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
09/16/2010 04:18 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile
09/16/2010 04:18 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
09/16/2010 04:18 AM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
09/16/2010 04:18 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local
09/16/2010 04:18 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
09/16/2010 04:18 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
09/16/2010 04:18 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
62 Dir(s) 397,491,486,720 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/07/17 09:41:58 | 000,000,221 | -HS- | M] () – C:\Users\SRE Lab\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/08/19 00:12:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\SRE Lab\Desktop\HiJackThis.exe
[2013/08/20 13:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\SRE Lab\Desktop\OTL.exe
[2013/08/20 12:49:30 | 000,891,115 | —- | M] () – C:\Users\SRE Lab\Desktop\SecurityCheck.exe
[2013/08/02 15:18:00 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web(1).exe
[2013/08/02 15:11:30 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Base Services ==========
SRV:64bit: - [2009/07/13 20:40:01 | 000,072,192 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\aelupsvc.dll – (AeLookupSvc)
SRV:64bit: - [2013/02/27 00:47:10 | 000,070,144 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appinfo.dll – (Appinfo)
SRV:64bit: - [2009/07/13 20:38:55 | 000,079,360 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\alg.exe – (ALG)
SRV:64bit: - [2010/11/20 08:27:23 | 000,849,920 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\qmgr.dll – (BITS)
SRV:64bit: - [2010/11/20 08:25:45 | 000,705,024 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\BFE.DLL – (BFE)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\lsass.exe – (KeyIso)
SRV:64bit: - [2009/07/13 20:40:50 | 000,402,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\es.dll – (EventSystem)
SRV - [2009/07/13 20:15:19 | 000,271,360 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\es.dll – (EventSystem)
SRV:64bit: - [2012/07/04 17:13:27 | 000,136,704 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\browser.dll – (Browser)
SRV:64bit: - [2013/07/09 00:46:20 | 000,184,320 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\cryptsvc.dll – (CryptSvc)
SRV - [2013/07/08 23:46:31 | 000,140,288 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\cryptsvc.dll – (CryptSvc)
SRV:64bit: - [2010/11/20 08:27:24 | 000,512,000 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\rpcss.dll – (DcomLaunch)
SRV:64bit: - [2010/11/20 08:26:04 | 000,317,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV - [2010/11/20 07:18:30 | 000,254,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2011/03/03 01:24:16 | 000,183,296 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dnsrslvr.dll – (Dnscache)
SRV:64bit: - [2009/07/13 20:40:35 | 000,111,104 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\eapsvc.dll – (EapHost)
SRV:64bit: - [2009/07/13 20:41:00 | 000,038,912 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\hidserv.dll – (hidserv)
SRV - [2009/07/13 20:15:24 | 000,049,152 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\hidserv.dll – (hidserv)
SRV:64bit: - [2009/07/13 20:41:10 | 000,359,424 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\SysNative\ipnathlp.dll – (SharedAccess)
SRV:64bit: - [2010/11/20 08:26:39 | 000,501,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\IPSECSVC.DLL – (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:64bit: - [2009/07/13 20:41:54 | 000,524,288 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\swprv.dll – (swprv)
SRV:64bit: - [2009/07/13 20:41:26 | 000,067,584 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysNative\mmcss.dll – (MMCSS)
SRV:64bit: - [2009/07/13 20:41:52 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netman.dll – (Netman)
SRV:64bit: - [2009/07/13 20:41:52 | 000,459,776 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netprofm.dll – (netprofm)
SRV - [2009/07/13 20:16:03 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\netprofm.dll – (netprofm)
SRV:64bit: - [2012/10/03 12:44:21 | 000,303,104 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\nlasvc.dll – (NlaSvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,025,600 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\nsisvc.dll – (nsi)
SRV:64bit: - [2011/05/24 06:42:55 | 000,404,480 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpnpmgr.dll – (PlugPlay)
SRV:64bit: - [2012/02/11 01:36:02 | 000,559,104 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\spoolsv.exe – (Spooler)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\lsass.exe – (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:64bit: - [2009/07/13 20:41:53 | 000,099,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\rasauto.dll – (RasAuto)
SRV:64bit: - [2010/11/20 08:27:24 | 000,344,064 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\rasmans.dll – (RasMan)
SRV:64bit: - [2010/11/20 08:27:24 | 000,512,000 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\rpcss.dll – (RpcSs)
SRV:64bit: - [2010/11/20 08:27:25 | 000,030,720 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\seclogon.dll – (seclogon)
SRV:64bit: - [2011/11/17 01:33:55 | 000,031,232 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\lsass.exe – (SamSs)
SRV:64bit: - [2009/07/13 20:41:58 | 000,097,280 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wscsvc.dll – (wscsvc)
SRV:64bit: - [2010/11/20 08:27:26 | 000,236,032 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\srvsvc.dll – (LanmanServer)
SRV:64bit: - [2010/11/20 08:27:25 | 000,370,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\shsvcs.dll – (ShellHWDetection)
SRV - [2010/11/20 07:21:19 | 000,328,192 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\shsvcs.dll – (ShellHWDetection)
No service found with a name of slsvc
SRV:64bit: - [2010/11/20 08:27:25 | 001,110,016 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\schedsvc.dll – (Schedule)
SRV:64bit: - [2010/11/20 08:27:26 | 000,316,928 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\tapisrv.dll – (TapiSrv)
SRV - [2010/11/20 07:21:28 | 000,242,176 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\tapisrv.dll – (TapiSrv)
SRV:64bit: - [2009/07/13 20:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2012/05/01 00:40:20 | 000,209,920 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\profsvc.dll – (ProfSvc)
SRV:64bit: - [2010/11/20 08:25:27 | 001,600,512 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\VSSVC.exe – (VSS)
SRV:64bit: - [2010/11/20 08:25:42 | 000,679,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\audiosrv.dll – (AudioSrv)
SRV:64bit: - [2010/11/20 08:25:42 | 000,679,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\audiosrv.dll – (AudioEndpointBuilder)
SRV:64bit: - [2010/11/20 08:27:25 | 000,170,496 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sdrsvc.dll – (SDRSVC)
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2010/11/20 08:27:28 | 001,646,080 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wevtsvc.dll – (eventlog)
SRV:64bit: - [2010/11/20 08:26:59 | 000,828,416 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\MPSSVC.dll – (MpsSvc)
SRV:64bit: - [2010/11/20 08:27:28 | 000,580,096 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wiaservc.dll – (stisvc)
SRV:64bit: - [2010/11/20 08:24:58 | 000,128,000 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\msiexec.exe – (msiserver)
SRV - [2010/11/20 07:17:22 | 000,073,216 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWow64\msiexec.exe – (msiserver)
SRV:64bit: - [2009/07/13 20:41:56 | 000,242,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wbem\WMIsvc.dll – (Winmgmt)
SRV:64bit: - [2012/06/02 17:19:43 | 002,428,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wuaueng.dll – (wuauserv)
SRV:64bit: - [2010/11/20 08:26:07 | 000,252,416 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\dot3svc.dll – (dot3svc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,886,784 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wlansvc.dll – (Wlansvc)
SRV:64bit: - [2010/11/20 08:27:28 | 000,118,784 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wkssvc.dll – (LanmanWorkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: TOSHIBA MK6465GSX
Partitions: 4
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 199.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 574.00GB
Starting Offset: 209715200
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 22.00GB
Starting Offset: 616505016320
Hidden sectors: 0


DeviceID: Disk #0, Partition #3
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 103.00MB
Starting Offset: 640025624576
Hidden sectors: 0


========== Files - Unicode (All) ==========
[2013/08/12 12:48:45 | 000,000,068 | —- | M] ()(C:\Users\SRE Lab\Desktop\? Filter dance summer intensive - YouTube.url) – C:\Users\SRE Lab\Desktop\▶ Filter dance summer intensive - YouTube.url
[2013/08/12 12:48:45 | 000,000,068 | —- | C] ()(C:\Users\SRE Lab\Desktop\? Filter dance summer intensive - YouTube.url) – C:\Users\SRE Lab\Desktop\▶ Filter dance summer intensive - YouTube.url

< End of report >

OTL Extras logfile created on: 8/20/2013 1:08:52 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\SRE Lab\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.80 Gb Total Physical Memory | 5.75 Gb Available Physical Memory | 73.68% Memory free
15.60 Gb Paging File | 13.21 Gb Available in Paging File | 84.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 573.97 Gb Total Space | 370.46 Gb Free Space | 64.54% Space Free | Partition Type: NTFS
Drive D: | 21.91 Gb Total Space | 3.19 Gb Free Space | 14.58% Space Free | Partition Type: NTFS
Drive E: | 627.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SRELAB-HP | User Name: SRE Lab | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{4168F917-BE49-4E00-A278-74EBFA193AA8}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{8D5E278C-213D-4CE3-8911-90B8800B929C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{979C2EA4-46E3-46CE-B1EB-6DF8F05B7DCD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{CE673816-3393-4E25-B87A-1B3DDD974AE5}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{E9E4751D-0124-4FC5-82AE-DD3D66386412}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04F3BBA4-5DDA-48E0-9F47-086467164F88}" = protocol=6 | dir=in | app=c:\users\sre lab\appdata\roaming\spotify\spotify.exe |
"{06067CB7-F81F-4612-A66A-DC7A681C9ED8}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{08BED549-B4F7-49F9-B577-35129845CC23}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{0A5A734E-0E07-4734-88E9-3AFBEC275021}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{10DADACC-FCBF-490C-B296-AD9E66EC721D}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{156C006E-B97C-49D0-94F8-1FBCD6D7307A}" = protocol=17 | dir=in | app=c:\program files (x86)\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{1F00C63F-93DE-41AD-9C39-5AA6BCAFC473}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{2115D4E4-AD61-404B-A0C7-D8239C612A9D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2DDF4D22-28AE-4725-B00C-49F49ABCFA03}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{3359ABE1-D3AB-4692-BE9E-383D11E92215}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\photo\hpmediasmartphoto.exe |
"{34F2ACBB-324A-4726-A7EB-709B11C058E2}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{3DE3C434-69C0-4EDA-A8EB-FF290B70DCCD}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{49EDC7DB-4A30-4A2F-8A43-68B649769CDD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4B657FAB-3886-4D71-B736-40F299CD8173}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\cinemanow\cinemanow.exe |
"{4BFF18A1-0254-4268-8C22-37029B776360}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{51E421D5-3E97-4D4E-A900-910941E8647E}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{5328FC72-25DA-4769-8E5B-DF9C6DC9BDE1}" = protocol=6 | dir=in | app=c:\program files (x86)\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{56D93D51-EE38-494D-B92B-58B07FC6A0E3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{691F19B6-4A18-42E9-81CA-B2EA836D35E5}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{7DF74D46-7097-4D42-8572-B21E0C939135}" = protocol=6 | dir=in | app=c:\users\sre lab\appdata\roaming\spotify\spotify.exe |
"{7F7DE8BF-B2B0-4B96-814E-65720BBC5BC8}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{948809D4-5E3D-4F9A-81EE-DF6C51B0D5D4}" = protocol=17 | dir=in | app=c:\users\sre lab\appdata\roaming\spotify\spotify.exe |
"{B4A3D79C-9A8A-4F1C-9CBC-A7263D50584E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{C39736AB-74A4-4087-9647-9680CF4CBC11}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\video\hpmediasmartvideo.exe |
"{C91F606E-4766-47E8-B3E4-A926CB2B2083}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{CBBD288B-F033-4015-8B4A-F082F1032AF5}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{D1D198EB-855F-4C0C-A15E-E209575C43FE}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\cinemanow\cinemanow.exe |
"{DE3AE2B4-012C-423D-9ED3-8DDBECA92D72}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{E55AF624-9929-4C70-9EF1-82C224443BF8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{E7ACA930-B9A9-4D51-BD57-AE59E44A7C89}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\music\hptouchsmartmusic.exe |
"{EE2ED78E-D6E7-4C6C-B9E7-57E74D8E5780}" = protocol=17 | dir=in | app=c:\users\sre lab\appdata\roaming\spotify\spotify.exe |
"{EEBB8EDC-84BD-4B96-A1A8-481730009B20}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{F6FB9858-0230-46C0-B104-DBA1AFACD782}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{FCB35597-E50F-4752-A89F-2A55C78CE0D1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F6B7CB0-66D8-4B31-BF1F-D2318E58080E}" = HP SimplePass Identity Protection
"{23401053-03B3-845A-A946-32BEB58AB5AC}" = ccc-utility64
"{26A24AE4-039D-4CA4-87B4-2F86416020FF}" = Java™ 6 Update 20 (64-bit)
"{299625B9-6C69-462C-9CEA-8E06D878B1C5}" = HP 3D DriveGuard
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{34DA4817-68E1-CC8B-A9A5-392095FA28C9}" = ATI Catalyst Install Manager
"{426FAE9F-7373-496E-A215-9DB7EF4398CF}" = Validity Sensors DDK
"{4B4E2FA2-3B1E-4147-99DB-5033981D8C2F}" = HP MediaSmart Movies and TV
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5EEC477F-8E9B-4420-8829-16E7426227DB}" = Windows Live MIME IFilter
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{731A1D36-BF17-4C76-B7E7-CC055AF8C54E}" = HP MediaSmart SmartMenu
"{76FF0F03-B707-4332-B5D1-A56C8303514E}" = iTunes
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUSR_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B5FC1E1B-E70D-45F1-8E40-A3C30698B323}" = HP Wireless Assistant
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6246243-CF06-4E40-8A37-C3B537695C36}" = Share64
"{F83779DF-E1F5-43A2-A7BE-732F856FADB7}" = Microsoft SQL Server Compact 3.5 SP1 x64 English
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = Corel PaintShop Photo Pro X3
"_{F072CA07-A781-45E4-9975-C033A73019CF}" = Corel VideoStudio Pro X3
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{03D562B5-C4E2-4846-A920-33178788BE00}" = Windows Live Communications Platform
"{07E49BC1-24FF-4D7A-AC74-727BE95801AF}" = LightScribe System Software
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0A653E82-9056-A08A-8262-62F59FF285C7}" = CCC Help Korean
"{0D542538-335E-08BA-21C5-62E9A7B2BE60}" = Catalyst Control Center InstallProxy
"{0F929651-F516-4956-90F2-FFBD2CD5D30E}" = Photo Gallery
"{0FF9CC94-EF23-401E-BDBD-37403D1A2B38}" = Windows Live SOXE Definitions
"{11A63D4E-6512-6D57-8690-3D656A483AB0}" = CCC Help French
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = Roxio CinemaNow 2.0
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{147D8BB7-FEE8-5D53-390D-7FB94FC26BC8}" = CCC Help Italian
"{16734097-34B9-C5E3-7863-7A9CAAEB391F}" = ccc-core-static
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2AC01935-3774-4981-98C8-14E93C14372C}" = Windows Live UX Platform Language Pack
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{35772A32-7A3D-A8FC-840C-B84B536E62FD}" = CCC Help Swedish
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{42C095E5-4CE2-A376-9893-93431C6A236E}" = CCC Help Dutch
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45898170-E68C-4F02-AA35-C2186BF347A3}" = Movie Maker
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B156358-CE9C-4E9F-8CAD-79AE86A68C60}" = HP Power Manager
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6
"{543F949F-2B95-448F-9F2E-56F0C5FF8E2C}" = Catalyst Control Center - Branding
"{5A0EE0F0-E909-4F3B-B437-AAD9252427CB}" = Windows Live Installer
"{5BA6D86E-AA0D-05FF-09B5-ED3CD5277A42}" = CCC Help German
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{5E094C92-6288-4F43-AA9A-D452D0218F3F}" = Windows Live Essentials
"{6389F199-1D6C-4974-9557-693F9DD48736}" = Windows Live Writer Resources
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{6B65BA9C-2E00-3BCB-8EA5-94A7841B39C1}" = CCC Help Thai
"{6B6923B9-8719-425B-916C-CD2908F31AAF}" = Windows Live SOXE
"{6C122441-1861-4CD7-B1C5-A163A6984E12}" = CinemaNow Media Manager
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{70743ADB-DD63-DA15-1E6C-32D88C54E04D}" = CCC Help English
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72D90DB3-A16A-4545-B555-868471101833}" = HP Setup
"{778E3C06-48EB-79CA-775E-BEA3086896AD}" = CCC Help Japanese
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A083F0E-189D-9100-8883-3B7E75B53E3F}" = CCC Help Chinese Traditional
"{7C6F0282-3DCD-4A80-95AC-BB298E821C44}" = Windows Live Writer
"{7D4318AC-9560-46F0-910F-0B38D6CDC009}" = HP Documentation
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89870E0D-9602-41F8-9E83-14F6849346A4}" = Windows Live Mail
"{89C7E0A7-4D9D-4DCC-8834-A9A2B92D7EBB}" = Photo Gallery
"{8AE4C1DF-D685-56CB-4B4E-181A12FFAF55}" = CCC Help Turkish
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MediaSmart CinemaNow 2.0
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{925BC35B-CA11-577E-95C7-67C5BD4776BA}" = Catalyst Control Center Graphics Previews Common
"{93138715-2252-4107-C3C6-D7F8ACAD4956}" = CCC Help Finnish
"{95A73EEC-18CA-0C70-2E88-C6F901C69583}" = CCC Help Russian
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C6D5C94-386A-4DE7-B99F-523D3F167B9A}" = Windows Live Messenger
"{9C7243A7-5C0E-3190-A042-01D88F7BB791}" = CCC Help Portuguese
"{9ECF7817-DB11-4FBA-9DF1-296A578D513A}" = Adobe Shockwave Player 11.5
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA6F75E4-1807-4AAF-8CCC-4B9A48476BA5}" = Catalyst Control Center Localization All
"{AAA94EAA-40A4-458C-9D86-D1DA765B51D5}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.3 MUI
"{ACF5C43A-3E69-ED63-FCF9-831B3B9D1516}" = CCC Help Polish
"{AF144D2F-E890-B537-DC7C-DE01A8AC5405}" = CCC Help Norwegian
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B286BAC3-CBE6-4854-BF68-EB72A34CEA56}" = Windows Live Messenger
"{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}" = Movie Maker
"{B4201487-FA15-8BCC-6833-E355A43CCCDB}" = Catalyst Control Center Graphics Previews Vista
"{B5DE2511-C5D3-0AAC-0470-606067398EBB}" = CCC Help Chinese Standard
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{BDDA1E1E-204E-4368-B0C2-737F16B76307}" = HP MediaSmart/TouchSmart Netflix
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6B0EE9E-2128-4448-B7AE-5E2B46E0F0E7}" = Windows Live Photo Common
"{C77A8D2F-DE6E-E548-FA06-C56251441D95}" = CCC Help Spanish
"{C8871195-1265-0859-CC55-ADE112EEF7D3}" = Times Reader
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D1612A3D-0DCC-4055-BB6A-0036F31158A0}" = Setup
"{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = ICA
"{D1F80EFD-A032-4E8E-A367-70C44AD4DCE0}" = ISCOM
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D604900F-A275-416C-AF9D-CDEDF58B72DB}" = Windows Live Mail
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{DA4BF4BE-3CDC-43B5-BBDA-DDDA73103111}" = Corel PaintShop Photo Pro X3
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DCD941B6-F2E7-4FAF-B102-F7D4DE5FF99A}" = IPM_PSP_Pro
"{DCF1928A-FC01-48E7-A7E6-4651D42EF6A1}" = PSPPRO_DCRAW
"{DD7C5FC1-DCA5-487A-AF23-658B1C00243F}" = Photo Common
"{DF8B9311-ADE7-4EDE-B121-326CAA3D225D}" = PSPPContent
"{E05DB9F9-C8E7-45F2-BE9E-76D4C447CE9B}" = HP Software Framework
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2A97415-BD97-4867-B906-05E39E9EE51F}" = HL-2270DW
"{E342D296-DB9D-4FC7-ACB0-39926C0BFA16}" = HP Quick Launch
"{E3445598-4424-4EE2-B71C-C23325F7FB71}" = Windows Live PIMT Platform
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E93EAD24-E483-52AA-2E6F-C792E51E3F92}" = CCC Help Czech
"{ECB2E743-BFBD-7C77-6C62-F54ACD0ECE6D}" = CCC Help Hungarian
"{EFBCA571-617D-484A-9ECA-E301BB6D0750}" = Windows Live Writer
"{F069C491-69E6-4D9B-9A0C-B7894A1FA97C}" = Setup
"{F072CA07-A781-45E4-9975-C033A73019CF}" = ICA
"{F0A06BEC-E4BA-DB4F-C3DF-37A3C77780EF}" = CCC Help Danish
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E58739-2B4C-498F-9B0D-FF0F2FD52B61}" = Windows Live UX Platform
"{F206FEC3-F5DD-43FD-A8CF-9C46B8A6A92C}" = VSPro
"{F4E9851F-765E-40B7-9859-237C2724E62C}" = DeviceIO
"{F6A76E9C-C299-4CFA-AD2A-57FE9DD68B70}" = Contents
"{F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}" = Junk Mail filter update
"{F8423392-2296-4748-9B66-344432459632}" = PureHD
"{F909BD3C-8684-4ACF-B7C3-33F4F9F901B7}" = Share
"{F90DE865-1A3D-D6D6-0638-F1D2EFCB5C29}" = PX Profile Update
"{F95C8C1F-25BB-44EC-A7E6-5C17ABC6BC71}" = VIO
"{FB0B6DDD-DF3E-4CD6-927C-724AB854E322}" = VSClassic
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FD67D9F3-FED6-4A2E-9D6C-8C8C44DEF8FF}" = IPM_VS_Pro
"{FD7DDB2A-445B-78D3-EAFB-6F7BE425285E}" = CCC Help Greek
"{FE661711-E392-4B3F-A4A7-02C747C09134}" = ISCOM
"Adobe AIR" = Adobe AIR
"Adobe Digital Editions 2.0" = Adobe Digital Editions 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Audacity_is1" = Audacity 2.0.3
"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader
"Google Chrome" = Google Chrome
"HP DVB-T TV Tuner" = HP DVB-T TV Tuner 8.0.64.43
"HP Photo Creations" = HP Photo Creations
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"MSC" = McAfee SecurityCenter
"My HP Game Console" = HP Game Console
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"WT087328" = Blackhawk Striker 2
"WT087335" = Build-a-lot 2
"WT087342" = Dora's Carnival Adventure
"WT087360" = Escape Rosecliff Island
"WT087361" = FATE
"WT087362" = Final Drive Nitro
"WT087372" = Heroes of Hellas 2 - Olympia
"WT087373" = Jewel Quest 3
"WT087379" = Jewel Quest Solitaire 2
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087414" = Virtual Families
"WT087415" = Wheel of Fortune 2
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087501" = Plants vs. Zombies
"WT087513" = Virtual Villagers - The Secret City
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HuluDesktop" = Hulu Desktop
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/9/2013 10:14:59 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/9/2013 10:14:59 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3277706

Error - 8/9/2013 10:14:59 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3277706

Error - 8/9/2013 10:15:00 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/9/2013 10:15:00 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3278720

Error - 8/9/2013 10:15:00 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3278720

Error - 8/9/2013 10:15:01 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 8/9/2013 10:15:01 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3279828

Error - 8/9/2013 10:15:01 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3279828

Error - 8/9/2013 10:15:02 PM | Computer Name = SRELab-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

[ HP Wireless Assistant Events ]
Error - 3/28/2012 12:37:27 PM | Computer Name = SRELab-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 3/28/2012 12:37:32 PM | Computer Name = SRELab-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 3/28/2012 12:37:37 PM | Computer Name = SRELab-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 3/28/2012 12:37:42 PM | Computer Name = SRELab-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 3/28/2012 12:37:47 PM | Computer Name = SRELab-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 3/28/2012 12:38:47 PM | Computer Name = SRELab-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 3/28/2012 12:39:48 PM | Computer Name = SRELab-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

[ System Events ]
Error - 8/16/2013 11:02:51 PM | Computer Name = SRELab-HP | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:59:59 PM on ?8/?16/?2013 was unexpected.

Error - 8/17/2013 12:31:50 AM | Computer Name = SRELab-HP | Source = volsnap | ID = 393230
Description = The shadow copies of volume C: were aborted because of an IO failure
on volume C:.

Error - 8/17/2013 2:00:11 PM | Computer Name = SRELab-HP | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Error Reporting Service service to connect.

Error - 8/17/2013 2:00:41 PM | Computer Name = SRELab-HP | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Error Reporting Service service to connect.

Error - 8/17/2013 2:04:35 PM | Computer Name = SRELab-HP | Source = Service Control Manager | ID = 7034
Description = The McAfee Scanner service terminated unexpectedly. It has done this
1 time(s).

Error - 8/17/2013 2:08:20 PM | Computer Name = SRELab-HP | Source = Service Control Manager | ID = 7031
Description = The McAfee McShield service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 5000 milliseconds:
Restart the service.

Error - 8/17/2013 2:09:07 PM | Computer Name = SRELab-HP | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the McAfee
McShield service to connect.

Error - 8/17/2013 2:09:07 PM | Computer Name = SRELab-HP | Source = Service Control Manager | ID = 7000
Description = The McAfee McShield service failed to start due to the following error:
%%1053

Error - 8/17/2013 2:27:47 PM | Computer Name = SRELab-HP | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:25:52 PM on ?8/?17/?2013 was unexpected.

Error - 8/17/2013 9:17:35 PM | Computer Name = SRELab-HP | Source = Service Control Manager | ID = 7031
Description = The McAfee McShield service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 5000 milliseconds:
Restart the service.


< End of report >

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-20 14:16:06
—————————–
14:16:06.033 OS Version: Windows x64 6.1.7601 Service Pack 1
14:16:06.033 Number of processors: 4 586 0x2505
14:16:06.034 ComputerName: SRELAB-HP UserName: SRE Lab
14:16:07.976 Initialize success
14:22:07.879 AVAST engine defs: 13082001
14:23:36.864 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
14:23:36.868 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 610480MB BusType: 3
14:23:37.008 Disk 0 MBR read successfully
14:23:37.013 Disk 0 MBR scan
14:23:37.022 Disk 0 unknown MBR code
14:23:37.039 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
14:23:37.053 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 587745 MB offset 409600
14:23:37.093 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 22431 MB offset 1204111360
14:23:37.114 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 1250050048
14:23:37.268 Disk 0 scanning C:\Windows\system32\drivers
14:23:48.056 Service scanning
14:24:32.130 Modules scanning
14:24:32.149 Disk 0 trace - called modules:
14:24:32.160
14:24:33.754 AVAST engine scan C:\Windows
14:24:36.577 AVAST engine scan C:\Windows\system32
14:29:39.982 AVAST engine scan C:\Windows\system32\drivers
14:29:59.996 AVAST engine scan C:\Users\SRE Lab
14:35:42.862 Disk 0 MBR has been saved successfully to "C:\Users\SRE Lab\Desktop\MBR.dat"
14:35:42.870 The log file has been saved successfully to "C:\Users\SRE Lab\Desktop\aswMBR.txt"

Attachments:

Hi EricWoods,

[external image: Posted Image] Run OTL.exe
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE:64bit: - HKLM\..\SearchScopes\{75C5F1BF-1072-4836-9C50-0872C11264E0}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE - HKLM\..\SearchScopes\{75C5F1BF-1072-4836-9C50-0872C11264E0}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss…56&tsp=4962
    IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTer…56&tsp=4962
    IE - HKCU\..\SearchScopes\{75C5F1BF-1072-4836-9C50-0872C11264E0}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    [2013/08/02 15:11:47 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
    [2013/08/02 15:11:44 | 000,000,000 | —D | C] – C:\ProgramData\BrowserDefender
    [2013/08/02 15:11:22 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Babylon
    [2013/08/02 15:11:22 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
    
    :Commands
    [purity]
    [createrestorepoint]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

[external image: Posted Image] AdwCleaner

Download AdwCleaner to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

[external image: Posted Image] Malwarebytes Anti-Rootkit
  • Download Malwarebytes Anti-Rootkit
  • Once the file has been downloaded, right click on the downloaded file and select the Extract all menu option.
  • Follow the instructions to extract the ZIP file to a folder called mbar-versionnumber on your desktop.
  • Once the ZIP file has been extracted, open the folder and when that folder opens, double-click on the mbar folder.
  • Double-click on the mbar.exe file to launch Malwarebytes Anti-Rootkit.
  • After you double-click on the mbar.exe file, you may receive a User Account Control (UAC) message if you are sure you wish to allow the program to run. Please allow to start Malwarebytes Anti-Rootkit correctly.
  • Malwarebytes Anti-Rootkit will now install necessary drivers that are required for the program to operate correctly.
  • If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.
[external image: Posted Image]
  • Please click by the introduction screen on the Next button to continue.
[external image: Posted Image]
  • Next you will see the Update Database screen.
  • Click on the Update button so Malwarebytes Anti-Rootkit can download the latest definition updates.
[external image: Posted Image]
  • When the update has finished, click on the Next button.
[external image: Posted Image]
  • Next you can select some basic scanning options. Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
  • Malwarebytes Anti-Rootkit will now start scanning your computer for rootkits. This scan can take some time, so please be patient.
[external image: Posted Image]
  • When the scan with Malwarebytes Anti-Rootkit is finished, the program will display a screen with the results from the scan.
  • Make sure everything is selected and that the option to create a restore point is checked.
  • Next click on the Cleanup button. Malwarebytes Anti-Rootkit will then prompt you to reboot your computer.
  • Click on Yes button to restart your computer.
  • There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log.
  • The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run.
    • For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt.
  • The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program.
=========================

[external image: Posted Image] Re-run OTL (it should be located on your desktop).
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • OTL fix log (if produced)
  • AdwCleaner.txt
  • system-log.txt
  • Fresh OTL.txt
  • What symptoms are you experiencing?
Seems to be running better now.

# AdwCleaner v3.000 - Report created 21/08/2013 at 18:48:03
# Updated 20/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : SRE Lab - SRELAB-HP
# Running from : C:\Users\SRE Lab\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Users\SRE Lab\AppData\LocalLow\delta
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Users\SRELAB~1\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
File Deleted : C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
File Deleted : C:\Windows\System32\Tasks\BrowserDefendert

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKCU\Software\857db8db76fe945
Key Deleted : HKLM\SOFTWARE\857db8db76fe945
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\AppDataLow\Software\LyricsContainer
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Delta
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16502


-\\ Google Chrome v29.0.1547.57

[ File : C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [5269 octets] - [21/08/2013 18:43:31]
AdwCleaner[S0].txt - [4990 octets] - [21/08/2013 18:48:03]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5050 octets] ##########

—————————————
Malwarebytes Anti-Rootkit BETA 1.06.1.1005

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.527000 GHz
Memory total: 8377974784, free: 6218014720

=======================================


—————————————
Malwarebytes Anti-Rootkit BETA 1.06.1.1005

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.527000 GHz
Memory total: 8377974784, free: 6412394496

Downloaded database version: v2013.08.21.07
Initializing…
———— Kernel report ————
08/21/2013 19:10:50
———— Loaded modules ———–
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\compbatt.sys
\SystemRoot\system32\DRIVERS\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\system32\drivers\mfehidk.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\mfewfpk.sys
\SystemRoot\system32\DRIVERS\wd.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\system32\DRIVERS\hpdskflt.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\system32\DRIVERS\igdpmd64.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\bcmwl664.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\drivers\mouclass.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\Impcd.sys
\SystemRoot\system32\DRIVERS\Accelerometer.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\clwvd.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\DRIVERS\circlass.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\AtiHdmi.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\DRIVERS\stwrt64.sys
\SystemRoot\system32\drivers\mfeavfk.sys
\SystemRoot\system32\drivers\mfefirek.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\WinUSB.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\??\C:\Windows\system32\Drivers\rikvm_C6F09094.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\drivers\mfeapfk.sys
\SystemRoot\system32\drivers\cfwids.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\mbamswissarmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\psapi.dll
\Windows\System32\advapi32.dll
\Windows\System32\shell32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\Wldap32.dll
\Windows\System32\usp10.dll
\Windows\System32\sechost.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\user32.dll
\Windows\System32\setupapi.dll
\Windows\System32\iertutil.dll
\Windows\System32\lpk.dll
\Windows\System32\msvcrt.dll
\Windows\System32\msctf.dll
\Windows\System32\ole32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\kernel32.dll
\Windows\System32\gdi32.dll
\Windows\System32\oleaut32.dll
\Windows\System32\imm32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\normaliz.dll
\Windows\System32\clbcatq.dll
\Windows\System32\nsi.dll
\Windows\System32\ws2_32.dll
\Windows\System32\wininet.dll
\Windows\System32\urlmon.dll
\Windows\System32\difxapi.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\devobj.dll
\Windows\System32\crypt32.dll
\Windows\System32\wintrust.dll
\Windows\System32\KernelBase.dll
\Windows\System32\comctl32.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa800a19a060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa80080cb050
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Device number: 0, partition: 2
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800a19a060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xfffffa800839b330, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800a19a060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80082548b0, DeviceName: Unknown, DriverName: \Driver\hpdskflt\
DevicePointer: 0xfffffa80080cb050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
Device number: 0, partition: 2
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\Windows\system32\drivers…
<<<2>>>
Device number: 0, partition: 2
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 2FBFE761

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 407552
Partition file system is NTFS
Partition is bootable

Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 409600 Numsec = 1203701760

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 1204111360 Numsec = 45938688

Partition 3 type is Other (0xc)
Partition is NOT ACTIVE.
Partition starts at LBA: 1250050048 Numsec = 211632

Disk Size: 640135028736 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1250243728-1250263728)…
Done!
Infected: c:\Users\SRE Lab\AppData\Local\Temp\SetupToparcadehits.exe –> [Adware.GameVance]
Scan finished
Creating System Restore point…
Cleaning up…
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================


Removal queue found; removal started
Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_i.mbam…
Removing c:\programdata\malwarebytes' anti-malware (portable)\bootstrap_0_0_2048_i.mbam…
Removing c:\programdata\malwarebytes' anti-malware (portable)\mbr_0_r.mbam…
Removal finished

OTL logfile created on: 8/21/2013 10:50:40 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\SRE Lab\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.80 Gb Total Physical Memory | 5.73 Gb Available Physical Memory | 73.45% Memory free
15.60 Gb Paging File | 13.16 Gb Available in Paging File | 84.35% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 573.97 Gb Total Space | 370.74 Gb Free Space | 64.59% Space Free | Partition Type: NTFS
Drive D: | 21.91 Gb Total Space | 3.19 Gb Free Space | 14.58% Space Free | Partition Type: NTFS
Drive E: | 627.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SRELAB-HP | User Name: SRE Lab | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0003.tmp\lmi_rescue.exe (LogMeIn, Inc.)
PRC - C:\Users\SRE Lab\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\SRE Lab\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (CLKMSVC10_C6F09094) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe (CyberLink)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe ()
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (CinemaNow Service) – C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (BrYNSvc) – C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mbamchameleon) – C:\Windows\SysNative\drivers\mbamchameleon.sys ()
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HipShieldK) – C:\Windows\SysNative\drivers\HipShieldK.sys (McAfee, Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}
IE:64bit: - HKLM\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/09/16 04:18:05 | 000,000,000 | —D | M]

[2013/08/02 15:12:39 | 000,000,000 | —D | M] (No name found) – C:\Users\SRE Lab\AppData\Roaming\mozilla\Extensions
[2013/08/02 15:11:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_1\
CHR - Extension: Google Drive = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\
CHR - Extension: YouTube = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1\
CHR - Extension: Google Search = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: Skype Click to Call = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.10.0.13089_1\
CHR - Extension: Google Wallet Service = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.9_1\
CHR - Extension: Gmail = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\SRE Lab\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\RunOnce: [*LogMeInRescue_3780372088] C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0003.tmp\lmi_rescue.exe (LogMeIn, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83B1974F-FA01-48E8-BCBA-ED025FD0DFA8}: DhcpNameServer = 10.4.40.11 10.4.40.17
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFD09DC9-BBB7-4ECF-B449-DE3B7FCEDD22}: DhcpNameServer = 8.8.8.8
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/20 00:14:28 | 000,000,043 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{df1846ac-78ea-11e1-bb44-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{df1846ac-78ea-11e1-bb44-806e6f6e6963}\Shell\AutoRun\command - "" = E:\start.exe – [2010/04/01 03:40:27 | 002,052,921 | R— | M] (Macromedia, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/21 22:24:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/08/21 19:10:50 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/08/21 19:08:51 | 012,081,912 | —- | C] (Malwarebytes Corp.) – C:\Users\SRE Lab\Desktop\mbar-1.06.1.1005.exe
[2013/08/21 19:05:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/08/21 19:04:57 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Desktop\mbar
[2013/08/21 18:42:07 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/08/21 18:34:32 | 000,000,000 | —D | C] – C:\_OTL
[2013/08/20 14:45:14 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/08/20 13:02:50 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\SRE Lab\Desktop\aswMBR.exe
[2013/08/20 13:01:26 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\SRE Lab\Desktop\OTL.exe
[2013/08/19 00:12:04 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\SRE Lab\Desktop\HiJackThis.exe
[2013/08/18 22:41:43 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet
[2013/08/15 19:47:44 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/15 19:47:44 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/15 19:47:43 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/15 19:47:43 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/15 19:47:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/15 19:47:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/15 19:47:43 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/15 19:47:43 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/15 19:47:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/15 19:47:40 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/15 19:47:40 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/15 19:47:40 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/15 19:47:40 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/15 19:47:40 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/15 19:47:39 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/14 17:15:08 | 001,472,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/08/14 17:15:08 | 000,224,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/08/14 17:15:07 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/08/14 17:14:30 | 001,888,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/14 17:14:30 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/14 17:14:29 | 001,217,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/08/14 17:14:24 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/08/14 17:14:23 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/08/14 17:14:22 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/14 17:14:22 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/08/14 17:14:21 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/08/14 17:14:20 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/08/14 17:14:15 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/08/14 17:14:14 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/08/14 17:14:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/08/14 17:14:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/08/10 00:44:55 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Movdap
[2013/08/10 00:44:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Movdap
[2013/08/09 12:33:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
[2013/08/09 12:29:29 | 000,000,000 | —D | C] – C:\Brother
[2013/08/09 12:29:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Browny02
[2013/08/09 12:29:17 | 000,025,299 | —- | C] (Brother Industries, Ltd) – C:\Windows\SysWow64\BRLM03A.DLL
[2013/08/09 12:29:04 | 000,217,088 | —- | C] (brother) – C:\Windows\SysWow64\NSSearch.dll
[2013/08/09 12:29:04 | 000,005,120 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2L.dll
[2013/08/09 12:29:04 | 000,002,560 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2S.dll
[2013/08/09 12:29:03 | 000,073,728 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2.dll
[2013/08/09 12:29:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Brother
[2013/08/07 21:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/08/07 21:49:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/08/07 21:48:54 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Panasonic
[2013/08/07 18:26:58 | 000,501,912 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK2.dll
[2013/08/07 18:26:58 | 000,120,992 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EpPicPrt.dll
[2013/08/07 18:26:58 | 000,108,704 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICEntry.dll
[2013/08/07 18:26:58 | 000,080,024 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK.dll
[2013/08/07 18:26:57 | 000,071,840 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EPPicMgr.dll
[2013/08/07 18:26:56 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\InstallShield
[2013/08/07 18:25:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Panasonic
[2013/08/07 18:25:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2013/08/04 19:08:30 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Ulead Systems
[2013/08/02 15:33:24 | 000,000,000 | —D | C] – C:\Windows\en
[2013/08/02 15:33:12 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013/08/02 15:31:52 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2013/08/02 15:30:20 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/08/02 15:30:20 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/08/02 15:30:20 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/08/02 15:30:20 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/08/02 15:30:19 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/08/02 15:30:19 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/08/02 15:30:17 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/08/02 15:30:17 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/08/02 15:18:00 | 001,239,536 | —- | C] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web(1).exe
[2013/08/02 15:12:39 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Mozilla
[2013/08/02 15:11:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/08/02 15:11:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\searchplugins
[2013/08/02 15:11:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Extensions
[2013/08/02 15:11:30 | 001,239,536 | —- | C] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web.exe
[2013/08/02 15:09:37 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2013/08/02 15:09:37 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2013/08/02 15:09:35 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2013/08/02 15:09:35 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2013/08/02 15:08:07 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Windows Live
[2013/08/02 15:07:11 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/08/02 13:12:28 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Apple Computer
[2013/08/02 13:12:28 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Apple Computer
[2013/08/02 13:12:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/08/02 13:11:23 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013/08/02 13:11:23 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2013/08/02 13:10:42 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/08/02 13:09:57 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Apple
[2013/08/02 13:09:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/08/02 13:09:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/08/02 13:08:58 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/08/02 13:08:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/08/02 13:08:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/08/02 13:08:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/08/01 01:48:54 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Adobe_Systems_Incorporate
[2013/08/01 01:48:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2013/08/01 01:48:40 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Documents\My Digital Editions
[2013/08/01 01:28:51 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Documents\JTharmonies_data
[2013/08/01 01:27:02 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Audacity
[2013/08/01 01:26:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/08/01 01:26:12 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Programs
[2013/07/29 17:59:03 | 000,000,000 | —D | C] – C:\ProgramData\Brother
[2013/07/24 20:22:52 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Microsoft Games
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/21 22:24:13 | 000,001,828 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2013/08/21 22:24:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/21 22:20:15 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/21 21:24:49 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/21 21:24:49 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/21 21:21:32 | 000,730,320 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/21 21:21:32 | 000,627,082 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/21 21:21:32 | 000,107,366 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/21 21:17:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/21 21:17:09 | 1988,513,791 | -HS- | M] () – C:\hiberfil.sys
[2013/08/21 19:09:55 | 000,036,680 | —- | M] () – C:\Windows\SysNative\drivers\mbamchameleon.sys
[2013/08/21 19:09:14 | 012,081,912 | —- | M] (Malwarebytes Corp.) – C:\Users\SRE Lab\Desktop\mbar-1.06.1.1005.exe
[2013/08/21 18:41:32 | 000,975,858 | —- | M] () – C:\Users\SRE Lab\Desktop\AdwCleaner.exe
[2013/08/20 23:43:42 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/20 15:01:17 | 571,216,105 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/08/20 14:35:42 | 000,000,512 | —- | M] () – C:\Users\SRE Lab\Desktop\MBR.dat
[2013/08/20 14:14:51 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\SRE Lab\Desktop\aswMBR.exe
[2013/08/20 13:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\SRE Lab\Desktop\OTL.exe
[2013/08/20 12:49:30 | 000,891,115 | —- | M] () – C:\Users\SRE Lab\Desktop\SecurityCheck.exe
[2013/08/19 00:12:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\SRE Lab\Desktop\HiJackThis.exe
[2013/08/16 00:29:41 | 000,448,664 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/08/09 13:11:04 | 001,127,543 | —- | M] () – C:\Users\SRE Lab\Documents\TERMS OF USE - READ ME.pdf
[2013/08/09 13:11:04 | 000,325,187 | —- | M] () – C:\Users\SRE Lab\Documents\KB Fonts Button.png
[2013/08/09 13:11:04 | 000,021,088 | —- | M] () – C:\Users\SRE Lab\Documents\KBPlanetEarth.ttf
[2013/08/09 12:33:28 | 000,002,136 | —- | M] () – C:\Users\Public\Desktop\Brother Creative Center.lnk
[2013/08/07 21:50:10 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/08/05 01:16:43 | 000,000,333 | —- | M] () – C:\Windows\BRCALIB.INI
[2013/08/04 19:06:51 | 000,034,026 | —- | M] () – C:\Users\SRE Lab\Documents\Beautybeast.wlmp
[2013/08/02 15:18:00 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web(1).exe
[2013/08/02 15:11:30 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web.exe
[2013/08/02 13:20:17 | 005,451,055 | —- | M] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991).mp3
[2013/08/02 13:12:26 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/02 13:03:31 | 000,000,068 | —- | M] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991) - YouTube.url
[2013/08/01 01:48:43 | 000,002,236 | —- | M] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,212 | —- | M] () – C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:28:51 | 000,003,522 | —- | M] () – C:\Users\SRE Lab\Documents\JTharmonies.aup
[2013/08/01 01:26:37 | 000,001,003 | —- | M] () – C:\Users\SRE Lab\Desktop\Audacity.lnk
[2013/07/29 17:59:03 | 000,000,410 | —- | M] () – C:\Windows\BRWMARK.INI
[2013/07/28 02:06:15 | 000,003,029 | —- | M] () – C:\Users\SRE Lab\Desktop\Microsoft Outlook 2010.lnk
[2013/07/25 04:25:54 | 001,888,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/25 03:57:27 | 001,620,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/24 22:37:25 | 002,312,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/24 22:29:41 | 001,494,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/07/24 22:29:21 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/07/24 22:28:46 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/07/24 22:28:31 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/07/24 22:28:27 | 000,816,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/24 22:28:18 | 000,729,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/24 22:27:29 | 000,096,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/07/24 22:26:53 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/24 21:25:30 | 001,427,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/07/24 21:24:39 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/07/24 21:23:59 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/07/24 21:23:51 | 000,717,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/24 21:22:47 | 000,073,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/07/24 21:22:04 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/24 01:14:31 | 000,001,097 | —- | M] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/21 19:09:55 | 000,036,680 | —- | C] () – C:\Windows\SysNative\drivers\mbamchameleon.sys
[2013/08/21 18:41:16 | 000,975,858 | —- | C] () – C:\Users\SRE Lab\Desktop\AdwCleaner.exe
[2013/08/20 14:45:07 | 571,216,105 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/08/20 14:35:42 | 000,000,512 | —- | C] () – C:\Users\SRE Lab\Desktop\MBR.dat
[2013/08/20 12:50:09 | 000,891,115 | —- | C] () – C:\Users\SRE Lab\Desktop\SecurityCheck.exe
[2013/08/09 12:33:28 | 000,002,136 | —- | C] () – C:\Users\Public\Desktop\Brother Creative Center.lnk
[2013/08/09 12:29:12 | 000,000,050 | —- | C] () – C:\Windows\SysNative\BRADM10A.DAT
[2013/08/07 21:50:10 | 000,001,845 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/08/07 18:26:58 | 000,111,932 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2013/08/07 18:26:58 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2013/08/07 18:26:58 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2013/08/07 18:26:58 | 000,026,154 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2013/08/07 18:26:58 | 000,024,903 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2013/08/07 18:26:58 | 000,021,390 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2013/08/07 18:26:58 | 000,020,148 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2013/08/07 18:26:58 | 000,011,811 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2013/08/07 18:26:58 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2013/08/07 18:26:58 | 000,001,146 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2013/08/07 18:26:58 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2013/08/07 18:26:58 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2013/08/07 18:26:58 | 000,001,136 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2013/08/07 18:26:58 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2013/08/07 18:26:58 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2013/08/07 18:26:58 | 000,001,120 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2013/08/07 18:26:58 | 000,001,107 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2013/08/07 18:26:58 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2013/08/07 18:26:58 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2013/08/07 18:26:57 | 000,013,732 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_EN.cfg
[2013/08/07 18:26:57 | 000,006,442 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_IT.cfg
[2013/08/07 18:26:57 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_PT.cfg
[2013/08/07 18:26:57 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_BP.cfg
[2013/08/07 18:26:57 | 000,006,335 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_GE.cfg
[2013/08/07 18:26:57 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_FR.cfg
[2013/08/07 18:26:57 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_CF.cfg
[2013/08/07 18:26:57 | 000,006,122 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_DU.cfg
[2013/08/07 18:26:57 | 000,006,103 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_ES.cfg
[2013/08/07 18:26:57 | 000,005,817 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_KO.cfg
[2013/08/07 18:26:57 | 000,005,436 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_SC.cfg
[2013/08/07 18:26:57 | 000,002,889 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_RU.cfg
[2013/08/07 18:26:57 | 000,002,426 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_TC.cfg
[2013/08/02 16:04:06 | 000,034,026 | —- | C] () – C:\Users\SRE Lab\Documents\Beautybeast.wlmp
[2013/08/02 15:33:10 | 000,001,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2013/08/02 15:33:02 | 000,001,374 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2013/08/02 15:32:46 | 000,001,458 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013/08/02 15:32:26 | 000,002,486 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013/08/02 13:20:01 | 005,451,055 | —- | C] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991).mp3
[2013/08/02 13:12:26 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/02 13:09:56 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/08/02 13:03:31 | 000,000,068 | —- | C] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991) - YouTube.url
[2013/08/01 01:48:43 | 000,002,236 | —- | C] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,224 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,212 | —- | C] () – C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:28:51 | 000,003,522 | —- | C] () – C:\Users\SRE Lab\Documents\JTharmonies.aup
[2013/08/01 01:26:37 | 000,001,015 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/08/01 01:26:37 | 000,001,003 | —- | C] () – C:\Users\SRE Lab\Desktop\Audacity.lnk
[2013/07/29 18:05:13 | 000,000,333 | —- | C] () – C:\Windows\BRCALIB.INI
[2013/07/29 17:59:03 | 000,000,410 | —- | C] () – C:\Windows\BRWMARK.INI
[2013/07/28 02:06:15 | 000,003,029 | —- | C] () – C:\Users\SRE Lab\Desktop\Microsoft Outlook 2010.lnk
[2013/07/25 12:19:06 | 000,021,088 | —- | C] () – C:\Users\SRE Lab\Documents\KBPlanetEarth.ttf
[2013/07/24 01:14:31 | 000,001,097 | —- | C] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2012/12/03 08:42:50 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2012/12/03 08:42:50 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\BRLMW03A.INI

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Files - Unicode (All) ==========
[2013/08/12 12:48:45 | 000,000,068 | —- | M] ()(C:\Users\SRE Lab\Desktop\? Filter dance summer intensive - YouTube.url) – C:\Users\SRE Lab\Desktop\▶ Filter dance summer intensive - YouTube.url
[2013/08/12 12:48:45 | 000,000,068 | —- | C] ()(C:\Users\SRE Lab\Desktop\? Filter dance summer intensive - YouTube.url) – C:\Users\SRE Lab\Desktop\▶ Filter dance summer intensive - YouTube.url

< End of report >
Hi EricWoods,

[external image: Posted Image] Malwarebytes' Anti-Malware

Locate Malwarebytes' Anti-Malware (it should be on your desktop).
If not, download it here
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Once the program has loaded, select the Update tab to get the latest updates before performing the scan.
  • Select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
=========================


[external image: Posted Image] ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:

  • MBAM log
  • ESET's log.txt
  • How's the computer running, any symptoms?
Notebook running better but still getting "Windows has detected that your computer’s performance is slow." message from taskbar (during scanning). Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.08.22.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 SRE Lab :: SRELAB-HP [administrator] 8/22/2013 12:09:15 PM mbam-log-2013-08-22 (12-09-15).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 217421 Time elapsed: 3 minute(s), 52 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 3 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{DA3D98A6-868D-4E1B-BB78-0887230DA405} (PUP.OPtional.LyricsAd) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA3D98A6-868D-4E1B-BB78-0887230DA405} (PUP.OPtional.LyricsAd) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF190686-9E72-403C-B99D-682ABDB63C5B} (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 9 C:\Users\SRE Lab\AppData\Roaming\Movdap\WebCakeDesktop.exe (PUP.WebCake.A) -> Quarantined and deleted successfully. C:\Users\SRE Lab\AppData\Local\Temp\LyricsContainertmp.exe (PUP.Optional.LyricsAd) -> Quarantined and deleted successfully. C:\$Recycle.Bin\S-1-5-21-2375417462-58682541-106656562-1000\$R80YZWI.exe (PUP.Optional.IBryte) -> Quarantined and deleted successfully. C:\Users\SRE Lab\AppData\Local\Temp\nsk9130.tmp\installer.exe (PUP.Optional.InstallerApps.A) -> Quarantined and deleted successfully. C:\Users\SRE Lab\AppData\Local\Temp\nsk9130.tmp\wajam_2207-6c14163c.exe (PUP.Optional.Wajam) -> Quarantined and deleted successfully. C:\Users\SRE Lab\Downloads\7zip-setup.exe (PUP.DownloadAdmin) -> Quarantined and deleted successfully. C:\Users\SRE Lab\Downloads\Windows Live Movie Maker (1).exe (PUP.Optional.Solimba) -> Quarantined and deleted successfully. C:\Users\SRE Lab\Downloads\windows live movie maker setup.exe (PUP.Soft32Downloader) -> Quarantined and deleted successfully. C:\Users\SRE Lab\Downloads\Windows Live Movie Maker.exe (PUP.Optional.Solimba) -> Quarantined and deleted successfully. (end) C:\Program Files (x86)\Movdap\WebCakeIEClient.dll probably a variant of Win32/Adware.Yontoo.A application C:\Users\SRE Lab\AppData\Local\Temp\6E781783-BAB0-7891-8834-37DD342B5F02\Setup.exe a variant of Win32/Toolbar.Babylon.H application
Hi EricWoods,

but still getting "Windows has detected that your computer’s performance is slow." message from taskbar (during scanning).

From what I understand about this feature of Windows is that it is a warning when you system resources are being taxed. There is no way to disable the warnings but here is a suggestion that might help.
  • Go to Start > type "advance system settings" in search box and select "view advance system settings".
  • On Advance tab, click Settings under Performance.
  • In visual effect, select adjust for best performance and on the list,
    Tick
  • enable desktop composition
  • show thumbnails instead of icons
  • smooth edges of screen fonts
  • use visual styles on windows and buttons.
See if the warnings subside.

=========================

[external image: Posted Image] Run OTL.exe
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Program Files (x86)\Movdap\WebCakeIEClient.dll
    C:\Users\SRE Lab\AppData\Local\Temp\6E781783-BAB0-7891-8834-37DD342B5F02\Setup.exe
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

In your next post please provide the following:
  • Fresh OTL.txt
  • Any remaining issues?
OTL logfile created on: 8/23/2013 11:50:46 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\SRE Lab\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.80 Gb Total Physical Memory | 5.31 Gb Available Physical Memory | 68.07% Memory free
15.60 Gb Paging File | 12.88 Gb Available in Paging File | 82.55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 573.97 Gb Total Space | 374.02 Gb Free Space | 65.16% Space Free | Partition Type: NTFS
Drive D: | 21.91 Gb Total Space | 3.19 Gb Free Space | 14.58% Space Free | Partition Type: NTFS
Drive E: | 627.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SRELAB-HP | User Name: SRE Lab | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0003.tmp\lmi_rescue.exe (LogMeIn, Inc.)
PRC - C:\Users\SRE Lab\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Users\SRE Lab\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\ffmpegsumo.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (CLKMSVC10_C6F09094) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe (CyberLink)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe ()
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (CinemaNow Service) – C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (BrYNSvc) – C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HipShieldK) – C:\Windows\SysNative\drivers\HipShieldK.sys (McAfee, Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}
IE:64bit: - HKLM\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}
IE - HKCU\..\SearchScopes\{727E7E3A-8776-4AA3-A8AA-9F3BB13834CC}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{7AEF202B-80EF-45E0-A6F7-48EB97CA3957}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\..\SearchScopes\{CD2A1234-3A8D-4B8D-8F12-93C46896C555}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/09/16 04:18:05 | 000,000,000 | —D | M]

[2013/08/02 15:12:39 | 000,000,000 | —D | M] (No name found) – C:\Users\SRE Lab\AppData\Roaming\mozilla\Extensions
[2013/08/02 15:11:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.57\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_1\
CHR - Extension: Google Drive = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\
CHR - Extension: YouTube = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1\
CHR - Extension: Google Search = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: Skype Click to Call = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.10.0.13089_1\
CHR - Extension: Google Wallet Service = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.9_1\
CHR - Extension: Gmail = C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\SRE Lab\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\RunOnce: [*LogMeInRescue_1779670186] C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet\LMIR0003.tmp\lmi_rescue.exe (LogMeIn, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83B1974F-FA01-48E8-BCBA-ED025FD0DFA8}: DhcpNameServer = 10.4.40.11 10.4.40.17
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFD09DC9-BBB7-4ECF-B449-DE3B7FCEDD22}: DhcpNameServer = 8.8.8.8
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/20 00:14:28 | 000,000,043 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{df1846ac-78ea-11e1-bb44-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{df1846ac-78ea-11e1-bb44-806e6f6e6963}\Shell\AutoRun\command - "" = E:\start.exe – [2010/04/01 03:40:27 | 002,052,921 | R— | M] (Macromedia, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/23 23:48:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/08/22 12:23:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/08/22 12:04:50 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Malwarebytes
[2013/08/22 12:04:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/08/22 12:04:10 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/08/22 12:04:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/08/22 12:00:50 | 010,285,040 | —- | C] (Malwarebytes Corporation ) – C:\Users\SRE Lab\Desktop\mbam-setup-1.75.0.1300.exe
[2013/08/22 09:07:35 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Documents\Outlook Files
[2013/08/21 19:08:51 | 012,081,912 | —- | C] (Malwarebytes Corp.) – C:\Users\SRE Lab\Desktop\mbar-1.06.1.1005.exe
[2013/08/21 19:05:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/08/21 19:04:57 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Desktop\mbar
[2013/08/21 18:42:07 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/08/21 18:34:32 | 000,000,000 | —D | C] – C:\_OTL
[2013/08/20 14:45:14 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/08/20 13:02:50 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\SRE Lab\Desktop\aswMBR.exe
[2013/08/20 13:01:26 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\SRE Lab\Desktop\OTL.exe
[2013/08/19 00:12:04 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\SRE Lab\Desktop\HiJackThis.exe
[2013/08/18 22:41:43 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\LogMeIn Rescue Applet
[2013/08/15 19:47:44 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/15 19:47:44 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/15 19:47:43 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/15 19:47:43 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/15 19:47:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/15 19:47:43 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/15 19:47:43 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/15 19:47:43 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/15 19:47:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/15 19:47:40 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/15 19:47:40 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/15 19:47:40 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/15 19:47:40 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/15 19:47:40 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/15 19:47:39 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/14 17:15:08 | 001,472,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/08/14 17:15:08 | 000,224,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/08/14 17:15:07 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/08/14 17:14:30 | 001,888,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/14 17:14:30 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/14 17:14:29 | 001,217,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/08/14 17:14:24 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/08/14 17:14:23 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/08/14 17:14:22 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/14 17:14:22 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/08/14 17:14:21 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/08/14 17:14:20 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/08/14 17:14:15 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/08/14 17:14:14 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/08/14 17:14:14 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/08/14 17:14:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/08/10 00:44:55 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Movdap
[2013/08/10 00:44:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Movdap
[2013/08/09 12:33:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
[2013/08/09 12:29:29 | 000,000,000 | —D | C] – C:\Brother
[2013/08/09 12:29:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Browny02
[2013/08/09 12:29:17 | 000,025,299 | —- | C] (Brother Industries, Ltd) – C:\Windows\SysWow64\BRLM03A.DLL
[2013/08/09 12:29:04 | 000,217,088 | —- | C] (brother) – C:\Windows\SysWow64\NSSearch.dll
[2013/08/09 12:29:04 | 000,005,120 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2L.dll
[2013/08/09 12:29:04 | 000,002,560 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2S.dll
[2013/08/09 12:29:03 | 000,073,728 | —- | C] (Brother Industries Ltd.) – C:\Windows\SysWow64\BrDctF2.dll
[2013/08/09 12:29:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Brother
[2013/08/07 21:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/08/07 21:49:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/08/07 21:48:54 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Panasonic
[2013/08/07 18:26:58 | 000,501,912 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK2.dll
[2013/08/07 18:26:58 | 000,120,992 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EpPicPrt.dll
[2013/08/07 18:26:58 | 000,108,704 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICEntry.dll
[2013/08/07 18:26:58 | 000,080,024 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\PICSDK.dll
[2013/08/07 18:26:57 | 000,071,840 | —- | C] (SEIKO EPSON CORPORATION) – C:\Windows\SysWow64\EPPicMgr.dll
[2013/08/07 18:26:56 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\InstallShield
[2013/08/07 18:25:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Panasonic
[2013/08/07 18:25:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2013/08/04 19:08:30 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Ulead Systems
[2013/08/02 15:33:24 | 000,000,000 | —D | C] – C:\Windows\en
[2013/08/02 15:33:12 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2013/08/02 15:31:52 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2013/08/02 15:30:20 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_7.dll
[2013/08/02 15:30:20 | 000,518,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_7.dll
[2013/08/02 15:30:20 | 000,077,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_5.dll
[2013/08/02 15:30:20 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_5.dll
[2013/08/02 15:30:19 | 002,526,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_43.dll
[2013/08/02 15:30:19 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_43.dll
[2013/08/02 15:30:17 | 000,276,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_43.dll
[2013/08/02 15:30:17 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_43.dll
[2013/08/02 15:18:00 | 001,239,536 | —- | C] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web(1).exe
[2013/08/02 15:12:39 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Mozilla
[2013/08/02 15:11:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/08/02 15:11:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\searchplugins
[2013/08/02 15:11:48 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Extensions
[2013/08/02 15:11:30 | 001,239,536 | —- | C] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web.exe
[2013/08/02 15:09:37 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2013/08/02 15:09:37 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2013/08/02 15:09:35 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2013/08/02 15:09:35 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2013/08/02 15:08:07 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Windows Live
[2013/08/02 15:07:11 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/08/02 13:12:28 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Apple Computer
[2013/08/02 13:12:28 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Apple Computer
[2013/08/02 13:12:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/08/02 13:11:23 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013/08/02 13:11:23 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2013/08/02 13:10:42 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2013/08/02 13:10:41 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/08/02 13:09:57 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Apple
[2013/08/02 13:09:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/08/02 13:09:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/08/02 13:08:58 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/08/02 13:08:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/08/02 13:08:41 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/08/02 13:08:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/08/01 01:48:54 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Adobe_Systems_Incorporate
[2013/08/01 01:48:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2013/08/01 01:48:40 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Documents\My Digital Editions
[2013/08/01 01:28:51 | 000,000,000 | —D | C] – C:\Users\SRE Lab\Documents\JTharmonies_data
[2013/08/01 01:27:02 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Roaming\Audacity
[2013/08/01 01:26:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/08/01 01:26:12 | 000,000,000 | —D | C] – C:\Users\SRE Lab\AppData\Local\Programs
[2013/07/29 17:59:03 | 000,000,000 | —D | C] – C:\ProgramData\Brother

========== Files - Modified Within 30 Days ==========

[2013/08/23 23:49:46 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/23 23:49:46 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/23 23:48:31 | 000,001,828 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2013/08/23 23:46:59 | 000,730,320 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/23 23:46:59 | 000,627,082 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/23 23:46:59 | 000,107,366 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/23 23:42:17 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/23 23:42:12 | 1988,513,791 | -HS- | M] () – C:\hiberfil.sys
[2013/08/23 23:24:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/22 14:55:31 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/22 12:04:17 | 000,001,105 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/22 12:01:45 | 010,285,040 | —- | M] (Malwarebytes Corporation ) – C:\Users\SRE Lab\Desktop\mbam-setup-1.75.0.1300.exe
[2013/08/21 19:09:14 | 012,081,912 | —- | M] (Malwarebytes Corp.) – C:\Users\SRE Lab\Desktop\mbar-1.06.1.1005.exe
[2013/08/21 18:41:32 | 000,975,858 | —- | M] () – C:\Users\SRE Lab\Desktop\AdwCleaner.exe
[2013/08/20 23:43:42 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/20 15:01:17 | 571,216,105 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/08/20 14:35:42 | 000,000,512 | —- | M] () – C:\Users\SRE Lab\Desktop\MBR.dat
[2013/08/20 14:14:51 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\SRE Lab\Desktop\aswMBR.exe
[2013/08/20 13:01:33 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\SRE Lab\Desktop\OTL.exe
[2013/08/20 12:49:30 | 000,891,115 | —- | M] () – C:\Users\SRE Lab\Desktop\SecurityCheck.exe
[2013/08/19 00:12:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\SRE Lab\Desktop\HiJackThis.exe
[2013/08/16 00:29:41 | 000,448,664 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/08/09 13:11:04 | 001,127,543 | —- | M] () – C:\Users\SRE Lab\Documents\TERMS OF USE - READ ME.pdf
[2013/08/09 13:11:04 | 000,325,187 | —- | M] () – C:\Users\SRE Lab\Documents\KB Fonts Button.png
[2013/08/09 13:11:04 | 000,021,088 | —- | M] () – C:\Users\SRE Lab\Documents\KBPlanetEarth.ttf
[2013/08/09 12:33:28 | 000,002,136 | —- | M] () – C:\Users\Public\Desktop\Brother Creative Center.lnk
[2013/08/07 21:50:10 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/08/05 01:16:43 | 000,000,333 | —- | M] () – C:\Windows\BRCALIB.INI
[2013/08/04 19:06:51 | 000,034,026 | —- | M] () – C:\Users\SRE Lab\Documents\Beautybeast.wlmp
[2013/08/02 15:18:00 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web(1).exe
[2013/08/02 15:11:30 | 001,239,536 | —- | M] (Microsoft Corporation) – C:\Users\SRE Lab\Desktop\wlsetup-web.exe
[2013/08/02 13:20:17 | 005,451,055 | —- | M] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991).mp3
[2013/08/02 13:12:26 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/02 13:03:31 | 000,000,068 | —- | M] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991) - YouTube.url
[2013/08/01 01:48:43 | 000,002,236 | —- | M] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,212 | —- | M] () – C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:28:51 | 000,003,522 | —- | M] () – C:\Users\SRE Lab\Documents\JTharmonies.aup
[2013/08/01 01:26:37 | 000,001,003 | —- | M] () – C:\Users\SRE Lab\Desktop\Audacity.lnk
[2013/07/29 17:59:03 | 000,000,410 | —- | M] () – C:\Windows\BRWMARK.INI
[2013/07/28 02:06:15 | 000,003,029 | —- | M] () – C:\Users\SRE Lab\Desktop\Microsoft Outlook 2010.lnk
[2013/07/25 04:25:54 | 001,888,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/25 03:57:27 | 001,620,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL

========== Files Created - No Company Name ==========

[2013/08/22 12:04:17 | 000,001,105 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/21 18:41:16 | 000,975,858 | —- | C] () – C:\Users\SRE Lab\Desktop\AdwCleaner.exe
[2013/08/20 14:45:07 | 571,216,105 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/08/20 14:35:42 | 000,000,512 | —- | C] () – C:\Users\SRE Lab\Desktop\MBR.dat
[2013/08/20 12:50:09 | 000,891,115 | —- | C] () – C:\Users\SRE Lab\Desktop\SecurityCheck.exe
[2013/08/09 12:33:28 | 000,002,136 | —- | C] () – C:\Users\Public\Desktop\Brother Creative Center.lnk
[2013/08/09 12:29:12 | 000,000,050 | —- | C] () – C:\Windows\SysNative\BRADM10A.DAT
[2013/08/07 21:50:10 | 000,001,845 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2013/08/07 18:26:58 | 000,111,932 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2013/08/07 18:26:58 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2013/08/07 18:26:58 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2013/08/07 18:26:58 | 000,026,154 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2013/08/07 18:26:58 | 000,024,903 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2013/08/07 18:26:58 | 000,021,390 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2013/08/07 18:26:58 | 000,020,148 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2013/08/07 18:26:58 | 000,011,811 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2013/08/07 18:26:58 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2013/08/07 18:26:58 | 000,001,146 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_DU.dat
[2013/08/07 18:26:58 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2013/08/07 18:26:58 | 000,001,139 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2013/08/07 18:26:58 | 000,001,136 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2013/08/07 18:26:58 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2013/08/07 18:26:58 | 000,001,129 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2013/08/07 18:26:58 | 000,001,120 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_IT.dat
[2013/08/07 18:26:58 | 000,001,107 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_GE.dat
[2013/08/07 18:26:58 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2013/08/07 18:26:58 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2013/08/07 18:26:57 | 000,013,732 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_EN.cfg
[2013/08/07 18:26:57 | 000,006,442 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_IT.cfg
[2013/08/07 18:26:57 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_PT.cfg
[2013/08/07 18:26:57 | 000,006,347 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_BP.cfg
[2013/08/07 18:26:57 | 000,006,335 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_GE.cfg
[2013/08/07 18:26:57 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_FR.cfg
[2013/08/07 18:26:57 | 000,006,195 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_CF.cfg
[2013/08/07 18:26:57 | 000,006,122 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_DU.cfg
[2013/08/07 18:26:57 | 000,006,103 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_ES.cfg
[2013/08/07 18:26:57 | 000,005,817 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_KO.cfg
[2013/08/07 18:26:57 | 000,005,436 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_SC.cfg
[2013/08/07 18:26:57 | 000,002,889 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_RU.cfg
[2013/08/07 18:26:57 | 000,002,426 | —- | C] () – C:\Windows\SysWow64\EPPICLocal_TC.cfg
[2013/08/02 16:04:06 | 000,034,026 | —- | C] () – C:\Users\SRE Lab\Documents\Beautybeast.wlmp
[2013/08/02 15:33:10 | 000,001,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2013/08/02 15:33:02 | 000,001,374 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2013/08/02 15:32:46 | 000,001,458 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2013/08/02 15:32:26 | 000,002,486 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2013/08/02 13:20:01 | 005,451,055 | —- | C] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991).mp3
[2013/08/02 13:12:26 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/02 13:09:56 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/08/02 13:03:31 | 000,000,068 | —- | C] () – C:\Users\SRE Lab\Desktop\Belle (Little Town) - Beauty and the Beast (1991) - YouTube.url
[2013/08/01 01:48:43 | 000,002,236 | —- | C] () – C:\Users\SRE Lab\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,224 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:48:43 | 000,002,212 | —- | C] () – C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
[2013/08/01 01:28:51 | 000,003,522 | —- | C] () – C:\Users\SRE Lab\Documents\JTharmonies.aup
[2013/08/01 01:26:37 | 000,001,015 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/08/01 01:26:37 | 000,001,003 | —- | C] () – C:\Users\SRE Lab\Desktop\Audacity.lnk
[2013/07/29 18:05:13 | 000,000,333 | —- | C] () – C:\Windows\BRCALIB.INI
[2013/07/29 17:59:03 | 000,000,410 | —- | C] () – C:\Windows\BRWMARK.INI
[2013/07/28 02:06:15 | 000,003,029 | —- | C] () – C:\Users\SRE Lab\Desktop\Microsoft Outlook 2010.lnk
[2013/07/25 12:19:06 | 000,021,088 | —- | C] () – C:\Users\SRE Lab\Documents\KBPlanetEarth.ttf
[2012/12/03 08:42:50 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2012/12/03 08:42:50 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\BRLMW03A.INI

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Files - Unicode (All) ==========
[2013/08/12 12:48:45 | 000,000,068 | —- | M] ()(C:\Users\SRE Lab\Desktop\? Filter dance summer intensive - YouTube.url) – C:\Users\SRE Lab\Desktop\▶ Filter dance summer intensive - YouTube.url
[2013/08/12 12:48:45 | 000,000,068 | —- | C] ()(C:\Users\SRE Lab\Desktop\? Filter dance summer intensive - YouTube.url) – C:\Users\SRE Lab\Desktop\▶ Filter dance summer intensive - YouTube.url

< End of report >
Has regular slowdowns, times when it freezes momentarily. Don't see any other signs of problems. Could this be due to performance changes made earlier, or is something else going on?
Hi EricWoods,

Could this be due to performance changes made earlier, or is something else going on?

I'm confident we have removed all the malware that was present. But if still seem to be having some issues let's see if we can resolve those issues.

Below are a few items we usually address when we are wrapping things up, but let's try them now and see if they have any affect on the issues you are experiencing.

=========================

[external image: Posted Image] Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • Adobe Flash Player 10
  • Adobe Reader 9
=========================

[external image: Posted Image] Reboot

=========================

[external image: Posted Image] Adobe Flash Player:

Go to http://get.adobe.com/flashplayer/?no_ab=1
  • Remove the check mark from the box "Install Google Drive"
  • Click the Download button, and follow the onscreen directions to complete the installation.
Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.

=========================

[external image: Posted Image] Adobe Reader:

Go to http://get.adobe.com/reader/otherversions/
  • Use the drop down menu's to select your operating system
  • Select your language > Select The current version of Adobe Reader for your language
  • Remove the check mark from the box "Free! McAfee Security Scan Plus"
  • Click the Download button, and follow the onscreen directions to complete the installation.
Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.

=========================

[external image: Posted Image] Disable Java in Web Browsers

There is a vulnerability with regards to Java and web browsers. Therefore, we recommend to disable java in web browsers.
More information can be found here: http://www.techsupportforum.com/forums/f50…ers-683721.html

  • Click on the Start button and then click on the Control Panel option.
  • In the Control Panel Search enter Java Control Panel.
  • Click on the Java icon to open the Java Control Panel.
[external image: Posted Image]

Disable Java through the Java Control Panel

  • In the Java Control Panel, click on the Security tab.
  • Deselect the check box for Enable Java content in the browser. This will disable the Java plug-in in the browser.
  • Click Apply. When the Windows User Account Control (UAC) dialog appears, allow permissions to make the changes.
  • Click OK in the Java Plug-in confirmation window.
  • Restart the browser for changes to take effect.
[external image: Posted Image]

=========================

In your next post please provide the following:
  • Any change in performance?
DIdn't reinstall Flash Player, as am using Chrome for browser. Didn't see box in Security tab of Java Control Panel to disable browser content so uninstalled 6 Update 20 and 7 Update 25.
Hi EricWoods,

By removing all Java you may notice a change in the way some features of your web browsers perform.

=========================

[external image: Posted Image] System File Checker (SFC)
  • Click on the Start button and in the Search programs and files box type the following:

    • command
  • Don't press Enter, just let the search results populate above.
  • In the search results, locate the Programs section.
  • Locate the Command Prompt shortcut and right-click on it.
  • Select Run as administrator.
  • Click Yes on the User Account Control window that appears.
  • Important: If you are see a User Account Control window but also a message that says To continue, type an administrator password, and then click Yes, then your user account must be a standard account, not an administrator account. Before you can click Yes and open an elevated command prompt, you'll need to type the password of another user on your Windows 7 computer that has administrator level privileges.
  • Note: You will not see this window at all if your User Account Control settings are turned all the way down. See How To Disable User Account Control in Windows 7 for more information.
  • An elevated Command Prompt window will appear.

    • Type: sfc /scannow (There's a space between sfc and /scannow.) , then hit Enter
  • After the scan runs type exit to close the command prompt window
=========================

In your next post please provide the following:
  • Did the scan complete successfully?
  • How is the computer running?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI