This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected by win32:PUP [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys, need some help here,please.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 29/07/2012 16:29:29
System Uptime: 24/08/2013 22:32:06 (1 hours ago)
.
Motherboard: Dell Inc. | |
Processor: Genuine Intel® CPU T2600 @ 2.16GHz | Microprocessor | 2163/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 298 GiB total, 227.12 GiB free.
D: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: Security Processor Loader Driver
Device ID: ROOT\LEGACY_SPLDR\0000
Manufacturer:
Name: Security Processor Loader Driver
PNP Device ID: ROOT\LEGACY_SPLDR\0000
Service: spldr
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: aswRvrt
Device ID: ROOT\LEGACY_ASWRVRT\0000
Manufacturer:
Name: aswRvrt
PNP Device ID: ROOT\LEGACY_ASWRVRT\0000
Service: aswRvrt
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: avast! Network Shield Support
Device ID: ROOT\LEGACY_ASWTDI\0000
Manufacturer:
Name: avast! Network Shield Support
PNP Device ID: ROOT\LEGACY_ASWTDI\0000
Service: aswTdi
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: aswVmm
Device ID: ROOT\LEGACY_ASWVMM\0000
Manufacturer:
Name: aswVmm
PNP Device ID: ROOT\LEGACY_ASWVMM\0000
Service: aswVmm
.
==== System Restore Points ===================
.
RP76: 22/08/2013 02:39:19 - Removed Apple Mobile Device Support
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
Adobe Reader XI (11.0.03)
AIDA64 Extreme Edition v2.00
Apple Application Support
Apple Mobile Device Support
Apple Software Update
avast! Free Antivirus
Bonjour
CCleaner
Conexant HDA D110 MDC V.92 Modem
DAEMON Tools Lite
Dropbox
EPSON Copy Utility 3
EPSON Easy Photo Print
EPSON Printer Software
EPSON Scan
ffdshow v1.2.4422 [2012-04-09]
Futuremark SystemInfo
Google Chrome
Google Update Helper
HDVidCodec
iTunes
Java 7 Update 25
Java Auto Updater
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MozBackup 1.5.1
Mozilla Firefox 21.0 (x86 en-GB)
Mozilla Maintenance Service
Mozilla Thunderbird 17.0.8 (x86 en-US)
NVIDIA Drivers
Omiga Plus
Picasa 3
QuickTime
RICOH Media Driver ver.2.07.01.04
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Skype Click to Call
Skype™ 6.6
Smart Defrag 2
Solar Accounts
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817327) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VLC media player 2.0.6
WinRAR 4.20 (32-bit)
WinZipper
XPS LightFX SDK
Xvid Video Codec
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
Your Uninstaller! 7
.
==== Event Viewer Messages From Past Week ========
.
24/08/2013 23:01:16, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
24/08/2013 22:32:50, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
24/08/2013 22:32:49, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
24/08/2013 22:32:49, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
24/08/2013 22:32:40, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
24/08/2013 22:32:34, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
24/08/2013 22:32:33, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: aswRvrt aswSnx aswSP aswTdi aswVmm discache spldr Wanarpv6
24/08/2013 22:16:26, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000116 (0x88735510, 0x93e25700, 0x00000000, 0x00000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 082413-24694-01.
24/08/2013 18:19:46, Error: Service Control Manager [7022] - The Wsys Service service hung on starting.
24/08/2013 16:49:18, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000116 (0x88a88510, 0x94220700, 0x00000000, 0x00000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 082413-16317-01.
.
==== End Of File ===========================
OTL Extras logfile created on: 24/08/2013 22:48:32 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\XPS-M1710\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 81.63% Memory free
6.00 Gb Paging File | 5.48 Gb Available in Paging File | 91.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 227.14 Gb Free Space | 76.22% Space Free | Partition Type: NTFS

Computer Name: XPS-M1710-PC | User Name: XPS-M1710 | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1E5C97B4-D49D-44D0-BBF9-ABDB3C52A1B5}" = lport=445 | protocol=6 | dir=in | app=system |
"{22B21DD1-2BC7-4FE4-8130-6E5F8ECCE01E}" = lport=139 | protocol=6 | dir=in | app=system |
"{2D4F4C6D-46D4-4B22-95C2-5FE4E8F6BE91}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{30EB5D9A-A217-419C-B0D2-82F74DDE1A34}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{36E1C6B8-D1E8-4B93-AA95-3CAD90BDAAEF}" = rport=138 | protocol=17 | dir=out | app=system |
"{3C1281C2-130C-4B89-AEFE-F7E465EB0B50}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5706FDBC-125D-419D-91D6-9EDDE998F9AE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5AEAC25A-E377-4E29-9AB7-A204CEDE4A6A}" = rport=139 | protocol=6 | dir=out | app=system |
"{5C11ECA0-41DF-41B5-9F90-1123E2BC8387}" = rport=137 | protocol=17 | dir=out | app=system |
"{6098788D-61A7-4832-80A0-FC70338C28B8}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6DA28001-797A-423E-A071-3BA6AEA69022}" = lport=137 | protocol=17 | dir=in | app=system |
"{749F68EE-1EBC-4FF2-B59F-0158601D271C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{781365BD-3E7D-46CE-AEDA-E09A93D42978}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{80B6CC3A-4887-4ECD-81EB-1D99363CE54F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{81A3FA7D-3749-4D6D-B948-FF38C65A8D35}" = lport=10243 | protocol=6 | dir=in | app=system |
"{9F0C86DB-B90F-4B73-A920-9FE4838E1FBC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A02BA9FC-08C3-4E98-B83F-99B505744158}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A4AD374B-022B-47CD-8225-B98BA90B8998}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{B514EBDF-3926-44D5-AC6E-FA324A57B649}" = rport=445 | protocol=6 | dir=out | app=system |
"{C7472F36-ACD7-4FD9-AB6E-89D5C51D69A0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{DB027ADE-B0F1-4C2F-8F04-35626C59B381}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EC4A52FD-1032-43C6-82F8-0AC2EC13DE63}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{F7BBCB40-D3C5-4313-9CBD-D6F332A43388}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F8B84E99-BB69-4943-8165-95307AFA5781}" = lport=138 | protocol=17 | dir=in | app=system |
"{FAD4F117-D238-4415-A9B0-037AAC183362}" = rport=10243 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F16CBC2-B09C-4058-9A94-59647584A5D4}" = protocol=17 | dir=in | app=c:\users\xps-m1710\appdata\roaming\dropbox\bin\dropbox.exe |
"{160BF642-6F27-430E-9C75-E4B8EF94CC27}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1D80BC72-3E1E-48B2-8952-14D0E219390C}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{2BC2D295-AC51-4066-9F5D-C3292E9ED631}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3B017D62-8414-4F40-8258-1FF988678083}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3FEC75B1-913C-449F-9FB3-C68CBAB06E16}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{432E6BA9-7B1F-4738-9474-439155C8ECA0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{51BEEBF1-087A-480F-AADF-F4387C56EC7B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{51C9CBA1-BE81-48DA-91B0-A3F4E8D20F1A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5880869D-CB02-4C6A-A963-94DE0DA2BAA8}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{62A55DFD-158A-48BF-B6C1-66B904523233}" = protocol=6 | dir=in | app=c:\programdata\esafe\egdpsvc.exe |
"{64ACCCF3-DEC3-4458-8B68-8688161EB228}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{65544177-5433-4B17-AC3B-2338C3155B69}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{670CFABC-22E2-44D1-9648-A6A45DE84ECB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{773C7799-0147-43F0-96CE-D98B30C89365}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{7AD73712-0F70-40FB-9B94-82CE7BC9910A}" = protocol=6 | dir=in | app=c:\users\xps-m1710\appdata\roaming\dropbox\bin\dropbox.exe |
"{8933C34B-CB6F-4DEE-B2E4-322A331CEF34}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9695D5E4-B1AF-456E-A10F-5F1F9CFAE17E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9A1B26C9-72C0-4283-9EC6-B6E8F934131A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{ADE24506-9DC3-48EF-9FB6-F2EBB686A642}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{AE20887C-2267-49F1-A7DD-C055D91101C5}" = protocol=6 | dir=out | app=system |
"{B4E93B7C-66A3-4127-BF9A-D5DE4244FD3D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D2E52B2D-DAF1-422B-BD44-823063CA340C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D731B1B3-6272-4781-A0BB-DA4DAC19B48A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E27BF034-10AD-40CD-8659-E12E542C4A56}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FBC0F73A-8CDD-48E5-A31B-61623A76C847}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 25
"{2B818257-E6C7-4841-8C29-C5C9A982BCE5}" = RICOH Media Driver ver.2.07.01.04
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{777C06F9-8462-4289-9026-0462906E177F}" = XPS LightFX SDK
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B486871-27EB-49A5-8832-77176E63333C}" = iTunes
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}" = EPSON Easy Photo Print
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"1ClickDownload" = HDVidCodec
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v2.00
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"DAEMON Tools Lite" = DAEMON Tools Lite
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ffdshow_is1" = ffdshow v1.2.4422 [2012-04-09]
"Google Chrome" = Google Chrome
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MozBackup" = MozBackup 1.5.1
"Mozilla Firefox 21.0 (x86 en-GB)" = Mozilla Firefox 21.0 (x86 en-GB)
"Mozilla Thunderbird 17.0.8 (x86 en-US)" = Mozilla Thunderbird 17.0.8 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"Omiga Plus" = Omiga Plus
"Picasa 3" = Picasa 3
"PROPLUS" = Microsoft Office Professional Plus 2007
"Smart Defrag 2_is1" = Smart Defrag 2
"Solar Accounts" = Solar Accounts
"VLC media player" = VLC media player 2.0.6
"WinRAR archiver" = WinRAR 4.20 (32-bit)
"WinZipper" = WinZipper
"Xvid Video Codec 1.3.2" = Xvid Video Codec
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"YU2010_is1" = Your Uninstaller! 7

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 21/08/2013 03:29:36 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 21/08/2013 20:36:32 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 22/08/2013 05:26:07 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 22/08/2013 10:23:01 | Computer Name = XPS-M1710-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\omiga plus\eDhelper64.exe".
Dependent
Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 23/08/2013 04:20:05 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 24/08/2013 03:58:59 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 24/08/2013 05:02:30 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 24/08/2013 10:51:18 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 24/08/2013 12:20:00 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

Error - 24/08/2013 16:17:55 | Computer Name = XPS-M1710-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 29/07/2013 05:05:10 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7031
Description = The avast! Antivirus service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 5000 milliseconds:
Restart the service.

Error - 29/07/2013 18:45:46 | Computer Name = XPS-M1710-PC | Source = DCOM | ID = 10010
Description =

Error - 29/07/2013 20:47:02 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7022
Description = The Wsys Service service hung on starting.

Error - 29/07/2013 22:47:07 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7022
Description = The Wsys Service service hung on starting.

Error - 30/07/2013 03:09:23 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7022
Description = The Wsys Service service hung on starting.

Error - 31/07/2013 04:00:18 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7022
Description = The Wsys Service service hung on starting.

Error - 16/08/2013 17:35:45 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Omiga
plus service service to connect.

Error - 16/08/2013 17:35:45 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7000
Description = The Omiga plus service service failed to start due to the following
error: %%1053

Error - 16/08/2013 17:37:10 | Computer Name = XPS-M1710-PC | Source = Service Control Manager | ID = 7022
Description = The Wsys Service service hung on starting.

Error - 16/08/2013 17:37:34 | Computer Name = XPS-M1710-PC | Source = Microsoft-Windows-Application-Experience | ID = 205
Description = The Program Compatibility Assistant service failed to perform the
phase two initialization.
otl
OTL logfile created on: 24/08/2013 22:48:32 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\XPS-M1710\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 81.63% Memory free
6.00 Gb Paging File | 5.48 Gb Available in Paging File | 91.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 297.99 Gb Total Space | 227.14 Gb Free Space | 76.22% Space Free | Partition Type: NTFS

Computer Name: XPS-M1710-PC | User Name: XPS-M1710 | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\XPS-M1710\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.57\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.57\ffmpegsumo.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WsysSvc) – C:\ProgramData\eSafe\eGdpSvc.exe (Wsys Co., Ltd.)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (omigaplussvc) – C:\Program Files\Omiga Plus\omigaplusSvc.exe (Taiwan Shui Mu Chih Ching Technology Limited.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (winzipersvc) – C:\Program Files\WinZipper\winzipersvc.exe (Taiwan Shui Mu Chih Ching Technology Limited.)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (EPSON_PM_RPCV4_01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (cpuz130) – C:\Users\XPS-M1~1\AppData\Local\Temp\cpuz130\cpuz_x32.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (dtsoftbus01) – C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (SmartDefragDriver) – C:\Windows\System32\drivers\SmartDefragDriver.sys ()
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:\Windows\System32\drivers\tsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:\Windows\System32\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (terminpt) – C:\Windows\System32\drivers\terminpt.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (guardian2) – C:\Windows\System32\drivers\oz776.sys (O2Micro)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=a…6220864&ir=
IE - HKLM\..\SearchScopes,DefaultScope = {D1CC9BEF-4D83-426D-A492-E51A7B893C12}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{D1CC9BEF-4D83-426D-A492-E51A7B893C12: "URL" = http://start.mysearchdial.com/results.php?…6220864&ir=

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = AF A9 70 D1 5C BC CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {25A794BA-8A77-47B0-A3DC-E16F524A10DC}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerm…tc&tsp=4920
IE - HKCU\..\SearchScopes\{25A794BA-8A77-47B0-A3DC-E16F524A10DC}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..CT3293887.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultthis.engineName: "Vgrabber V1.6 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3293887&CUI=UN71053028719713211&UM=2&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledAddons: %7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%7D:7.0
FF - prefs.js..extensions.enabledAddons: %7Bd78b6094-2202-49e9-97b7-d9f31635bc08%7D:10.16.1.21
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3293887&SearchSource=2&CUI=UN71053028719713211&UM=2&q="


FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/05/18 17:00:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013/08/18 10:12:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013/08/18 10:12:26 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2012/11/13 21:47:07 | 000,000,000 | —D | M] (No name found) – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Extensions
[2013/06/23 18:39:48 | 000,000,000 | —D | M] (No name found) – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\extensions
[2013/05/19 08:53:16 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/05/20 11:02:53 | 000,000,000 | —D | M] (MySearchDial) – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
[2013/05/18 21:30:23 | 000,000,000 | —D | M] (Vgrabber V1.6) – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\extensions\{d78b6094-2202-49e9-97b7-d9f31635bc08}
[2013/04/17 15:50:46 | 000,201,930 | —- | M] () (No name found) – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\extensions\[removed]
[2013/06/21 22:27:27 | 000,006,546 | —- | M] () – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\searchplugins\babylon.xml
[2013/05/18 21:30:23 | 000,001,003 | —- | M] () – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\searchplugins\conduit.xml
[2013/06/21 22:27:41 | 000,001,294 | —- | M] () – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\searchplugins\delta.xml
[2013/05/20 11:03:00 | 000,002,383 | —- | M] () – C:\Users\XPS-M1710\AppData\Roaming\Mozilla\Firefox\Profiles\evwjntzv.default\searchplugins\Mysearchdial.xml
[2013/07/11 13:06:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\Extensions
[2013/08/16 23:38:58 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\Extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/07/11 13:06:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/08/16 23:38:58 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/05/18 17:03:50 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========

CHR - default_search_provider: Babylon (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}…tc&tsp=4920
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://search.babylon.com/?babsrc=HP_ss_di…tc&tsp=4920
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.57\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: WebCake = C:\Users\XPS-M1710\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_1\
CHR - Extension: HDvid Codec = C:\Users\XPS-M1710\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli\2.0_0\
CHR - Extension: Skype Click to Call = C:\Users\XPS-M1710\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.11.0.13348_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\XPS-M1710\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: MySearchDial New Tab = C:\Users\XPS-M1710\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.1_0\
CHR - Extension: Gmail = C:\Users\XPS-M1710\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [EPSON Stylus DX4400 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Omiga Plus] C:\Program Files\Omiga Plus\omigaplus.exe (Taiwan Shui Mu Chih Ching Technology Limited.)
O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\XPS-M1710\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2C29573E-1BE8-41DE-BC94-A9FB785CE564}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084

========== Files/Folders - Created Within 30 Days ==========

[2013/08/24 16:48:20 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/08/20 18:40:38 | 000,000,000 | —D | C] – C:\Users\XPS-M1710\Documents\Flemming house pictures
[2013/08/19 23:05:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/08/19 23:04:08 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/08/19 23:04:06 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/08/19 23:04:06 | 000,000,000 | —D | C] – C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/08/18 10:12:26 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Thunderbird
[2013/07/30 09:56:24 | 000,000,000 | —D | C] – C:\Users\XPS-M1710\AppData\Roaming\EPSON
[2013/07/29 22:20:35 | 000,000,000 | —D | C] – C:\Users\XPS-M1710\Desktop\INSULATION
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\XPS-M1710\Documents\*.tmp files -> C:\Users\XPS-M1710\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/24 22:32:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/24 22:32:14 | 2414,710,784 | -HS- | M] () – C:\hiberfil.sys
[2013/08/24 22:30:30 | 204,637,547 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/08/24 22:04:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/24 21:50:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/24 18:30:37 | 000,018,776 | —- | M] () – C:\Users\XPS-M1710\Documents\cc_20130824_183031.reg
[2013/08/24 18:26:56 | 000,021,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/24 18:26:56 | 000,021,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/24 18:18:40 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/23 12:24:05 | 000,518,446 | —- | M] () – C:\Users\XPS-M1710\Desktop\img006.jpg
[2013/08/23 12:14:53 | 000,365,907 | —- | M] () – C:\Users\XPS-M1710\Desktop\img005.jpg
[2013/08/22 14:03:19 | 000,664,780 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/08/22 14:03:19 | 000,125,484 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/08/21 12:23:04 | 000,355,365 | —- | M] () – C:\Users\XPS-M1710\Documents\Acorn Timber Frame Homes Limited accounts.slr
[2013/08/21 11:46:51 | 000,018,651 | —- | M] () – C:\Users\XPS-M1710\Documents\Acorn Timber Frame Homes Ltd.slr NEW.slr
[2013/08/21 00:12:28 | 000,002,129 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/20 18:41:46 | 000,002,151 | —- | M] () – C:\Users\XPS-M1710\Desktop\Flemming house pictures - Shortcut.lnk
[2013/08/19 23:05:07 | 000,001,753 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/19 11:58:20 | 000,001,258 | —- | M] () – C:\Users\XPS-M1710\Desktop\ct600-guide-2007.pdf - Shortcut.lnk
[2013/08/18 12:16:09 | 000,002,060 | —- | M] () – C:\Users\XPS-M1710\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2013/08/17 07:05:51 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/08/17 07:05:51 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/07/30 08:55:06 | 000,099,187 | —- | M] () – C:\Users\XPS-M1710\Desktop\AcornShorrock4617.HSM.Q1.pdf
[2013/07/30 08:55:06 | 000,097,138 | —- | M] () – C:\Users\XPS-M1710\Desktop\AcornShorrock4617.HSM.Q2.pdf
[2013/07/29 19:10:21 | 000,001,240 | —- | M] () – C:\Users\XPS-M1710\Desktop\Shorrock4617.1.pdf - Shortcut.lnk
[2013/07/26 15:00:47 | 000,065,407 | —- | M] () – C:\Users\XPS-M1710\Desktop\Elliott Plan.pdf
[2013/07/26 11:54:19 | 000,354,829 | —- | M] () – C:\Users\XPS-M1710\Documents\Acorn Timber Frame Homes Limited accounts (Backup).slr
[2013/07/26 07:24:18 | 000,154,230 | —- | M] () – C:\Users\XPS-M1710\Desktop\Acorn.MAK.4613Q1lsmm.pdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\XPS-M1710\Documents\*.tmp files -> C:\Users\XPS-M1710\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/24 18:30:34 | 000,018,776 | —- | C] () – C:\Users\XPS-M1710\Documents\cc_20130824_183031.reg
[2013/08/24 16:47:35 | 204,637,547 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/08/23 12:24:04 | 000,518,446 | —- | C] () – C:\Users\XPS-M1710\Desktop\img006.jpg
[2013/08/23 12:14:53 | 000,365,907 | —- | C] () – C:\Users\XPS-M1710\Desktop\img005.jpg
[2013/08/21 11:28:21 | 000,018,651 | —- | C] () – C:\Users\XPS-M1710\Documents\Acorn Timber Frame Homes Ltd.slr NEW.slr
[2013/08/20 18:41:46 | 000,002,151 | —- | C] () – C:\Users\XPS-M1710\Desktop\Flemming house pictures - Shortcut.lnk
[2013/08/19 23:05:07 | 000,001,753 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/19 11:58:20 | 000,001,258 | —- | C] () – C:\Users\XPS-M1710\Desktop\ct600-guide-2007.pdf - Shortcut.lnk
[2013/07/30 18:29:45 | 000,002,036 | —- | C] () – C:\Users\XPS-M1710\Documents\Mozilla Thunderbird.lnk
[2013/07/30 17:55:34 | 000,099,187 | —- | C] () – C:\Users\XPS-M1710\Desktop\AcornShorrock4617.HSM.Q1.pdf
[2013/07/30 17:55:34 | 000,097,138 | —- | C] () – C:\Users\XPS-M1710\Desktop\AcornShorrock4617.HSM.Q2.pdf
[2013/07/29 19:10:21 | 000,001,240 | —- | C] () – C:\Users\XPS-M1710\Desktop\Shorrock4617.1.pdf - Shortcut.lnk
[2013/07/26 16:24:56 | 000,154,230 | —- | C] () – C:\Users\XPS-M1710\Desktop\Acorn.MAK.4613Q1lsmm.pdf
[2013/07/26 15:00:47 | 000,065,407 | —- | C] () – C:\Users\XPS-M1710\Desktop\Elliott Plan.pdf
[2013/06/27 22:55:55 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys.sum
[2013/06/26 22:39:42 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSP.sys.sum
[2013/06/26 22:39:42 | 000,000,175 | —- | C] () – C:\Windows\System32\drivers\aswSnx.sys.sum
[2013/06/21 22:02:16 | 000,111,932 | —- | C] () – C:\Windows\System32\EPPICPrinterDB.dat
[2013/06/21 22:02:16 | 000,031,053 | —- | C] () – C:\Windows\System32\EPPICPattern131.dat
[2013/06/21 22:02:16 | 000,027,417 | —- | C] () – C:\Windows\System32\EPPICPattern121.dat
[2013/06/21 22:02:16 | 000,026,154 | —- | C] () – C:\Windows\System32\EPPICPattern1.dat
[2013/06/21 22:02:16 | 000,024,903 | —- | C] () – C:\Windows\System32\EPPICPattern3.dat
[2013/06/21 22:02:16 | 000,021,390 | —- | C] () – C:\Windows\System32\EPPICPattern5.dat
[2013/06/21 22:02:16 | 000,020,148 | —- | C] () – C:\Windows\System32\EPPICPattern2.dat
[2013/06/21 22:02:16 | 000,011,811 | —- | C] () – C:\Windows\System32\EPPICPattern4.dat
[2013/06/21 22:02:16 | 000,004,943 | —- | C] () – C:\Windows\System32\EPPICPattern6.dat
[2013/06/21 22:02:16 | 000,001,146 | —- | C] () – C:\Windows\System32\EPPICPresetData_DU.dat
[2013/06/21 22:02:16 | 000,001,139 | —- | C] () – C:\Windows\System32\EPPICPresetData_PT.dat
[2013/06/21 22:02:16 | 000,001,139 | —- | C] () – C:\Windows\System32\EPPICPresetData_BP.dat
[2013/06/21 22:02:16 | 000,001,136 | —- | C] () – C:\Windows\System32\EPPICPresetData_ES.dat
[2013/06/21 22:02:16 | 000,001,129 | —- | C] () – C:\Windows\System32\EPPICPresetData_FR.dat
[2013/06/21 22:02:16 | 000,001,129 | —- | C] () – C:\Windows\System32\EPPICPresetData_CF.dat
[2013/06/21 22:02:16 | 000,001,120 | —- | C] () – C:\Windows\System32\EPPICPresetData_IT.dat
[2013/06/21 22:02:16 | 000,001,107 | —- | C] () – C:\Windows\System32\EPPICPresetData_GE.dat
[2013/06/21 22:02:16 | 000,001,104 | —- | C] () – C:\Windows\System32\EPPICPresetData_EN.dat
[2013/06/21 22:02:16 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2013/06/21 21:52:55 | 000,007,605 | —- | C] () – C:\Users\XPS-M1710\AppData\Local\Resmon.ResmonCfg
[2013/06/21 17:27:08 | 000,000,005 | —- | C] () – C:\Users\XPS-M1710\AppData\Roaming\WBPU-TTL.DAT
[2013/06/07 16:42:02 | 000,000,027 | —- | C] () – C:\Windows\CDE DX4400DEFGIPS.ini
[2013/05/19 19:39:43 | 000,572,439 | —- | C] () – C:\Users\XPS-M1710\AppData\Local\mysearchdial.crx
[2013/05/18 17:04:55 | 000,015,672 | —- | C] () – C:\Windows\System32\drivers\SmartDefragDriver.sys
[2013/05/18 17:01:20 | 000,175,176 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/05/18 17:01:19 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/05/01 13:38:53 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/04/24 22:50:44 | 000,079,360 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2012/12/22 02:20:29 | 000,043,520 | —- | C] () – C:\Windows\System32\CmdLineExt03.dll
[2012/07/29 17:38:25 | 000,645,632 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2012/07/29 17:38:25 | 000,240,640 | —- | C] () – C:\Windows\System32\xvidvfw.dll

========== ZeroAccess Check ==========

[2009/07/14 06:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 06:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:29:20 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/14 03:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/07/16 14:21:45 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\337
[2013/07/16 14:23:14 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\337 Wallpaper
[2013/06/21 22:27:33 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\BabSolution
[2013/06/21 16:27:46 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\Babylon
[2013/06/13 20:00:04 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\DAEMON Tools Lite
[2013/06/21 16:28:09 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\DealPly
[2013/06/02 15:56:40 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\Desk 365
[2013/08/24 18:19:19 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\Dropbox
[2013/06/21 16:27:50 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\DSite
[2013/07/30 09:56:24 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\EPSON
[2013/05/18 17:04:55 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\IObit
[2013/05/19 19:39:45 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\mysearchdial
[2013/06/10 09:38:25 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\Omiga Plus
[2013/06/21 21:34:12 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\player
[2013/05/18 16:18:38 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\Thunderbird
[2013/05/18 15:22:27 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\URSoft
[2013/06/21 16:48:06 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\WinZipper
[2013/06/21 22:40:10 | 000,000,000 | —D | M] – C:\Users\XPS-M1710\AppData\Roaming\Zip Opener Packages

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 02:38:36 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2010/11/21 02:38:36 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 23:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 23:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 07:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 23:29:20 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 07:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 02:38:27 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 02:38:27 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2013/02/22 06:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_b104f0edc83023b1\iexplore.exe
[2012/07/29 17:15:50 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_b12660fbc816e935\iexplore.exe
[2013/04/05 00:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_b0f72023c83af39d\iexplore.exe
[2013/02/22 06:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_b183bdcce155df6c\iexplore.exe
[2013/05/17 01:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Program Files\Internet Explorer\iexplore.exe
[2013/05/17 01:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_b0e94f59c845c389\iexplore.exe
[2013/05/17 00:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_b1d43d56e11a6501\iexplore.exe
[2013/04/04 23:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_b175ed02e160af58\iexplore.exe
[2010/11/20 23:29:33 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/07/29 17:15:50 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/29 17:15:50 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2009/07/14 04:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 23:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 23:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.CFG >
[2012/09/23 21:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 12:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/14 03:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/14 03:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 02:38:26 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2010/11/21 02:38:26 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 06:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 06:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 23:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 23:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 02:38:25 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2010/11/21 02:38:25 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 23:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 22:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 22:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 02:38:36 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2010/11/21 02:38:36 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 23:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 23:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 23:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 23:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 02:38:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/21 02:38:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 02:38:26 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2010/11/21 02:38:26 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 22:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 22:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/06/10 23:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 23:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/05/18 21:31:12 | 000,000,009 | —- | M] () – C:\END
[2013/08/24 22:32:14 | 2414,710,784 | -HS- | M] () – C:\hiberfil.sys
[2013/08/24 22:32:16 | 3219,615,744 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 06:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 06:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 06:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 06:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 23:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 03:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 23:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2013/05/09 10:58:37 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 06:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 463C-48B6
Directory of C:\
14/07/2009 06:53 Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
14/07/2009 06:53 Application Data [C:\ProgramData]
14/07/2009 06:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 06:53 Documents [C:\Users\Public\Documents]
14/07/2009 06:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 06:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 06:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
14/07/2009 06:53 All Users [C:\ProgramData]
14/07/2009 06:53 Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
14/07/2009 06:53 Application Data [C:\ProgramData]
14/07/2009 06:53 Desktop [C:\Users\Public\Desktop]
14/07/2009 06:53 Documents [C:\Users\Public\Documents]
14/07/2009 06:53 Favorites [C:\Users\Public\Favorites]
14/07/2009 06:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
14/07/2009 06:53 Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
14/07/2009 06:53 Application Data [C:\Users\Default\AppData\Roaming]
14/07/2009 06:53 Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
14/07/2009 06:53 Local Settings [C:\Users\Default\AppData\Local]
14/07/2009 06:53 My Documents [C:\Users\Default\Documents]
14/07/2009 06:53 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
14/07/2009 06:53 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
14/07/2009 06:53 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
14/07/2009 06:53 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
14/07/2009 06:53 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
14/07/2009 06:53 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
14/07/2009 06:53 Application Data [C:\Users\Default\AppData\Local]
14/07/2009 06:53 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
14/07/2009 06:53 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
14/07/2009 06:53 My Music [C:\Users\Default\Music]
14/07/2009 06:53 My Pictures [C:\Users\Default\Pictures]
14/07/2009 06:53 My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
14/07/2009 06:53 My Music [C:\Users\Public\Music]
14/07/2009 06:53 My Pictures [C:\Users\Public\Pictures]
14/07/2009 06:53 My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\XPS-M1710
29/07/2012 16:29 Application Data [C:\Users\XPS-M1710\AppData\Roaming]
29/07/2012 16:29 Cookies [C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\Cookies]
29/07/2012 16:29 Local Settings [C:\Users\XPS-M1710\AppData\Local]
29/07/2012 16:29 My Documents [C:\Users\XPS-M1710\Documents]
29/07/2012 16:29 NetHood [C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
29/07/2012 16:29 PrintHood [C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
29/07/2012 16:29 Recent [C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\Recent]
29/07/2012 16:29 SendTo [C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\SendTo]
29/07/2012 16:29 Start Menu [C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\Start Menu]
29/07/2012 16:29 Templates [C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\XPS-M1710\AppData\Local
29/07/2012 16:29 Application Data [C:\Users\XPS-M1710\AppData\Local]
29/07/2012 16:29 History [C:\Users\XPS-M1710\AppData\Local\Microsoft\Windows\History]
29/07/2012 16:29 Temporary Internet Files [C:\Users\XPS-M1710\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\XPS-M1710\Documents
29/07/2012 16:29 My Music [C:\Users\XPS-M1710\Music]
29/07/2012 16:29 My Pictures [C:\Users\XPS-M1710\Pictures]
29/07/2012 16:29 My Videos [C:\Users\XPS-M1710\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 243,878,883,328 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/07/29 18:01:05 | 000,000,221 | -HS- | M] () – C:\Users\XPS-M1710\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-06-13 10:36:15

========== Alternate Data Streams ==========

@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >

.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by [removed] at 23:02:40.94 on 24/08/2013
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.25.2
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.3070.2320 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\XPS-M1710\Downloads\OTL.exe
C:\Windows\notepad.exe
C:\Windows\notepad.exe
C:\Users\XPS-M1710\Downloads\HiJackThis.exe
C:\Windows\notepad.exe
C:\Windows\notepad.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\XPS-M1710\Downloads\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://start.mysearchdial.com/?f=1&a=airmsd&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtD0AtCtA0DyE0EyEzz0ByCtN0D0Tzu0CyDtDyDtN1L2Xzut
BtFtBtFtCtFyCtCzztN1L1Czu1T1L1C1H1B1Q&cr=646220864&ir=
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
uRun: [Xvid] c:\program files\xvid\CheckUpdate.exe
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Omiga Plus] "c:\program files\omiga plus\omigaplus.exe" /autorun
uRun: [EPSON Stylus DX4400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticae.exe /fu "c:\windows\temp\E_SE989.tmp" /EF "HKCU"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\xps-m1~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\xps-m1710\appdata\roaming\dropbox\bin\Dropbox.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\29.0.1547.57\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\xps-m1~1\appdata\roaming\mozilla\firefox\profiles\evwjntzv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3293887&CUI=UN71053028719713211&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3293887&SearchSource=2&CUI=UN71053028719713211&UM=2&q=
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\users\xps-m1710\appdata\roaming\mozilla\firefox\profiles\evwjntzv.default\extensions\{d78b6094-2202-49e9-97b7-d9f31635bc08}\plugins\np-mswmp.dll
FF - plugin: c:\users\xps-m1710\appdata\roaming\mozilla\firefox\profiles\evwjntzv.default\extensions\{d78b6094-2202-49e9-97b7-d9f31635bc08}\plugins\npConduitFirefoxPlugin.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
FF - user.js: extensions.mysearchdial.hmpg - true
FF - user.js: extensions.mysearchdial.hmpgUrl - hxxp://start.mysearchdial.com/?f=1&a=airmsd&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtD0AtCtA0DyE0EyEzz0ByCtN0D0Tzu0CyDtDyDtN1L2Xzut
BtFtBtFtCtFyCtCzztN1L1Czu1T1L1C1H1B1Q&cr=646220864&ir=
FF - user.js: extensions.mysearchdial.dfltSrch - true
FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial
FF - user.js: extensions.mysearchdial.dnsErr - true
FF - user.js: extensions.mysearchdial_i.newTab - false
FF - user.js: extensions.mysearchdial.newTabUrl - hxxp://start.mysearchdial.com/?f=2&a=airmsd&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtD0AtCtA0DyE0EyEzz0ByCtN0D0Tzu0CyDtDyDtN1L2Xzut
BtFtBtFtCtFyCtCzztN1L1Czu1T1L1C1H1B1Q&cr=646220864&ir=
FF - user.js: extensions.mysearchdial.tlbrSrchUrl - hxxp://start.mysearchdial.com/?f=3&a=airmsd&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtD0AtCtA0DyE0EyEzz0ByCtN0D0Tzu0CyDtDyDtN1L2Xzut
BtFtBtFtCtFyCtCzztN1L1Czu1T1L1C1H1B1Q&cr=646220864&ir=&q=
FF - user.js: extensions.mysearchdial.id - 002170A13D4E48B6
FF - user.js: extensions.mysearchdial.instlDay - 15844
FF - user.js: extensions.mysearchdial.vrsn -
FF - user.js: extensions.mysearchdial.vrsni -
FF - user.js: extensions.mysearchdial_i.vrsnTs - 19:39:26
FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial
FF - user.js: extensions.mysearchdial.prdct - mysearchdial
FF - user.js: extensions.mysearchdial.aflt - airmsd
FF - user.js: extensions.mysearchdial_i.smplGrp - none
FF - user.js: extensions.mysearchdial.tlbrId - base
FF - user.js: extensions.mysearchdial.instlRef -
FF - user.js: extensions.mysearchdial.dfltLng -
FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
FF - user.js: extensions.mysearchdial.excTlbr - false
FF - user.js: extensions.mysearchdial_i.hmpg - true
FF - user.js: extensions.irspeeddial.aflt - airmsd
FF - user.js: extensions.irspeeddial.instlRef -
FF - user.js: extensions.irspeeddial.cr - 646220864
FF - user.js: extensions.irspeeddial.cd - 2XzuyEtN2Y1L1QzutDtDtBtCyBtD0AtCtA0DyE0EyEzz0ByCtN0D0Tzu0CyDtDyDtN1L2XzutBtFtBtF
tCtFyCtCzztN1L1Czu1T1L1C1H1B1Q
.
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 463c48b60000000000000013028db5d1
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15877
FF - user.js: extensions.delta.vrsn - [removed]
FF - user.js: extensions.delta.vrsni - [removed]
FF - user.js: extensions.delta.vrsnTs - 1.8.21.522:27:39
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=119357&tt=180613_ndtc&tsp=4920
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2013-5-18 15672]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2013-5-18 242240]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2012-6-19 374648]
R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-5-18 49376]
S0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-5-18 175176]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-5-18 770344]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-5-18 369584]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2013-5-11 65640]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-5-18 29816]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-5-18 66336]
S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-5-18 46808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2013-4-27 116648]
S2 omigaplussvc;Omiga plus service;c:\program files\omiga plus\omigaplusSvc.exe [2013-6-2 424104]
S2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2013-8-14 3291008]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-6-21 162408]
S2 winzipersvc;WinZiper service;c:\program files\winzipper\winzipersvc.exe [2013-6-2 424104]
S2 WsysSvc;Wsys Service;c:\programdata\esafe\eGdpSvc.exe [2013-7-19 301120]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-7-29 257416]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2013-4-27 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2013-5-18 117144]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-14 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-14 661504]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
.
=============== Created Last 30 ================
.
2013-08-19 21:04:08 ——– d—–w- c:\program files\iPod
2013-08-19 21:04:06 ——– d—–w- c:\program files\iTunes
2013-08-19 21:04:06 ——– d—–w- c:\progra~2\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-08-14 09:11:04 4774272 —-a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2013-08-14 09:11:04 4774272 —-a-w- c:\program files\mozilla firefox\browser\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
.
==================== Find3M ====================
.
2013-08-17 05:05:51 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-17 05:05:51 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 19:48:23 867240 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-06-12 19:48:17 789416 —-a-w- c:\windows\system32\deployJava1.dll
2013-06-12 19:48:00 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
.
============= FINISH: 23:02:58.42 ===============


I had to use safe mode with networking to hook up.
Many thanks,
Jon

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Jon

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

Sorry for the late reply. Do you still need help?

—————————————————————————————————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI