This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware infection? Having weird pop-ups in firefox at random interval

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I have a Windows 7 machine. I think it might have been a drive-by download from accidentally visiting a malicious site (I wish I knew what site that could have been, though!) It seems that the only thing it did (that was plainly visible anyway) was open up tabs on firefox on its own. It opened tabs to vube.com and toplugs.com (the latter having been marked as a malicious site). I notice that the latter link always appears to be a unique link, even though it's from the same site. It is asking me to install (or upgrade, don't recall) FLV Player to view FLV files. But my guess is that it is the software bundled with adware / malware and I just ignore the pop up.

I followed this guide but I remember seeing the popups afterward. I wanted to try Kaspersky Rescue Disk 10 by loading it onto a USB stick by using this support page but I couldn't get my system to boot from the USB drive. So I just gave up for about a week, and I did uninstall all of the programs suggested from that guide except for MalwareBytes. The last thing I tried was to uncheck all of the programs under the Startup tab using msconfig.

I currently have Avira Free Antivirus and MalwareBytes Anti-Malware (both up to date) on my machine. I haven't seen much of the mentioned adware activity lately, but I have noticed that firefox started crashing a LOT. I tried uninstalling and reinstalling firefox with no luck, so it could be infected plug-ins perhaps? I also noticed some "sketchy" RealPlayer update box open up as soon as Windows booted up this morning - I didn't know if it was legit or a malicious program so I closed it. Needless to say, I have been becoming more and more paranoid about this virus. I decided to seek help on this forum as requested by the guide that I used above.

EDIT: I have noticed now with my laptop computer (which I believe is clean) that firefox has been crashing a lot there as well, with the same symptoms. I don't know if it's a hardware issue, because my laptop is not a very good piece of equipment, but perhaps a software bug and not a malware issue? Regardless, any help would be greatly appreciated.

EDIT 2: Just to clarify, I am trying to clean my desktop computer. I do not care much for cleaning my laptop computer since I have neglected it for so long, but having said that, it might very well have malware as well. But I will worry about my laptop computer afterward. My desktop computer is probably the most important hunk of metal I have ever owned, and is even more important now because I'm back at university. Let us hope that it lasts long enough to survive the rest of my time at university! :-)

Here are the logs in order as requested:

OTL.txt

OTL logfile created on: 9/14/2013 5:30:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\Users\Tyler\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 70.79% Memory free
6.00 Gb Paging File | 5.16 Gb Available in Paging File | 86.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = F: | %SystemRoot% = F:\Windows | %ProgramFiles% = F:\Program Files
Drive C: | 232.88 Gb Total Space | 29.93 Gb Free Space | 12.85% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 151.26 Gb Free Space | 64.95% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 85.47 Gb Free Space | 36.70% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 157.31 Gb Free Space | 67.55% Space Free | Partition Type: NTFS
Drive K: | 1.87 Gb Total Space | 1.14 Gb Free Space | 61.07% Space Free | Partition Type: FAT

Computer Name: TYLER-PC | User Name: Tyler | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - F:\Users\Tyler\Desktop\OTL.exe (OldTimer Tools)
PRC - F:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - F:\Program Files\FileZilla FTP Client\fzshellext.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – F:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (TeamViewer8) – F:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AntiVirSchedulerService) – F:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) – F:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – F:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MozillaMaintenance) – F:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Skype C2C Service) – F:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (Secunia PSI Agent) – F:\Program Files\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – F:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (MsgPlusService) – F:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (Yuna Software)
SRV - (SkypeUpdate) – F:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Steam Client Service) – F:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WinDefend) – F:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – F:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (RealNetworks Downloader Resolver Service) – F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (MBAMService) – F:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – F:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Te.Service) – F:\Program Files\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe (Microsoft Corporation)
SRV - (fussvc) – F:\Program Files\Windows Kits\8.0\App Certification Kit\fussvc.exe (Microsoft Corporation)
SRV - (WatAdminSvc) – F:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (TeamViewer7) – C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AMD External Events Utility) – F:\Windows\System32\atiesrxx.exe (AMD)
SRV - (McComponentHostService) – F:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe (McAfee, Inc.)
SRV - (StorSvc) – F:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – F:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – F:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (libusbd) – F:\Windows\System32\libusbd-nt.exe (http://libusb-win32.sourceforge.net)


========== Driver Services (SafeList) ==========

DRV - (mbamchameleon) – F:\Windows\System32\drivers\mbamchameleon.sys ()
DRV - (avgntflt) – F:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (gfibto) – F:\Windows\System32\drivers\gfibto.sys (GFI Software)
DRV - (avipbb) – F:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) – F:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) – F:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PSI) – F:\Windows\System32\drivers\psi_mf_x86.sys (Secunia)
DRV - (WinRing0_1_2_0) – F:\Program Files\RealTemp\WinRing0.sys (OpenLibSys.org)
DRV - (MBAMProtector) – F:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (RdpVideoMiniport) – F:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbGD) – F:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – F:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (VSPerfDrv110) – F:\Program Files\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\VSPerfDrv110.sys (Microsoft Corporation)
DRV - (amdkmdag) – F:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdap) – F:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (AtiHDAudioService) – F:\Windows\System32\drivers\AtihdW73.sys (Advanced Micro Devices)
DRV - (MotioninJoyXFilter) – F:\Windows\System32\drivers\MijXfilt.sys (MotioninJoy)
DRV - (athur) – F:\Windows\System32\drivers\athur.sys (Atheros Communications, Inc.)
DRV - (vmbus) – F:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) – F:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – F:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – F:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – F:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (VMBusHID) – F:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – F:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (WSDPrintDevice) – F:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (mcdbus) – F:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (libusb0) – F:\Windows\System32\drivers\libusb0.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securedsearch2.lavasoft.com/index.p…420DC5223B69336
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 99 DE 1A F3 15 F3 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: F:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: F:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: F:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: F:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: f:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: F:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: F:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: F:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: f:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: F:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: F:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: F:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: F:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/09/03 18:54:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: F:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/06/20 07:41:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: F:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/09/03 18:54:26 | 000,000,000 | —D | M]

[2013/09/14 14:51:05 | 000,000,000 | —D | M] (No name found) – F:\Users\Tyler\AppData\Roaming\Mozilla\Extensions

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - F:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] F:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Computer Alarm Clock] File not found
O4 - HKLM..\Run: [MessengerPlusForSkypeService] F:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (Yuna Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D611A1D1-A025-4C8C-9453-6A9AE6A1BABB}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D975556C-4523-4E68-8E57-73146508B206}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - F:\Program Files\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - F:\Program Files\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - F:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (F:\Windows\system32\userinit.exe) - F:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - F:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - F:\Program Files\SUPERAntiSpyware\SASSEH.DLL File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/26 19:53:38 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - F:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - F:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - F:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - F:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.XFR1 - F:\Windows\System32\xfcodec.dll ()

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084

========== Files/Folders - Created Within 30 Days ==========

[2013/09/14 17:23:08 | 000,388,608 | —- | C] (Trend Micro Inc.) – F:\Users\Tyler\Desktop\HiJackThis.exe
[2013/09/14 17:22:13 | 000,602,112 | —- | C] (OldTimer Tools) – F:\Users\Tyler\Desktop\OTL.exe
[2013/09/14 14:50:54 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Roaming\Mozilla
[2013/09/14 14:50:54 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Local\Mozilla
[2013/09/14 14:50:42 | 000,000,000 | —D | C] – F:\Program Files\Mozilla Maintenance Service
[2013/09/14 13:11:20 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Roaming\com.pandora.desktop
[2013/09/14 13:11:19 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Roaming\com.pandora.desktop.E7C14276FFE9EEF0BC7DCE654C467D9A299EFD21.1
[2013/09/14 13:11:15 | 000,000,000 | —D | C] – F:\Program Files\Pandora
[2013/09/14 13:10:38 | 000,000,000 | —D | C] – F:\Program Files\Common Files\Adobe AIR
[2013/09/13 08:34:07 | 000,105,176 | —- | C] (Malwarebytes Corporation) – F:\Windows\System32\drivers\48230029.sys
[2013/09/13 08:14:12 | 000,000,000 | —D | C] – F:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/09/13 08:13:49 | 000,000,000 | —D | C] – F:\Users\Tyler\Desktop\mbar
[2013/09/13 03:11:53 | 000,000,000 | —D | C] – F:\Program Files\Wireshark
[2013/09/13 03:04:19 | 002,706,432 | —- | C] (Microsoft Corporation) – F:\Windows\System32\mshtml.tlb
[2013/09/13 03:04:18 | 002,876,928 | —- | C] (Microsoft Corporation) – F:\Windows\System32\jscript9.dll
[2013/09/13 03:04:18 | 000,061,440 | —- | C] (Microsoft Corporation) – F:\Windows\System32\iesetup.dll
[2013/09/13 03:04:18 | 000,039,424 | —- | C] (Microsoft Corporation) – F:\Windows\System32\jsproxy.dll
[2013/09/13 03:04:17 | 000,493,056 | —- | C] (Microsoft Corporation) – F:\Windows\System32\msfeeds.dll
[2013/09/13 03:04:17 | 000,391,168 | —- | C] (Microsoft Corporation) – F:\Windows\System32\ieui.dll
[2013/09/13 03:04:17 | 000,109,056 | —- | C] (Microsoft Corporation) – F:\Windows\System32\iesysprep.dll
[2013/09/13 03:04:17 | 000,071,680 | —- | C] (Microsoft Corporation) – F:\Windows\System32\RegisterIEPKEYs.exe
[2013/09/13 03:04:17 | 000,042,496 | —- | C] (Microsoft Corporation) – F:\Windows\System32\ie4uinit.exe
[2013/09/13 03:04:17 | 000,033,280 | —- | C] (Microsoft Corporation) – F:\Windows\System32\iernonce.dll
[2013/09/12 21:15:47 | 000,000,000 | —D | C] – F:\Windows\pss
[2013/09/12 20:30:22 | 000,000,000 | —D | C] – F:\Program Files\FileZilla FTP Client
[2013/09/12 05:36:43 | 000,133,056 | —- | C] (Microsoft Corporation) – F:\Windows\System32\drivers\ataport.sys
[2013/09/12 05:36:42 | 000,271,360 | —- | C] (Microsoft Corporation) – F:\Windows\System32\conhost.exe
[2013/09/12 05:36:42 | 000,169,984 | —- | C] (Microsoft Corporation) – F:\Windows\System32\winsrv.dll
[2013/09/12 05:36:42 | 000,005,120 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/09/12 05:36:42 | 000,003,584 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/12 05:36:41 | 000,006,144 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/09/12 05:36:41 | 000,004,608 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/12 05:36:41 | 000,004,608 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/12 05:36:41 | 000,004,096 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/12 05:36:41 | 000,004,096 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/09/12 05:36:41 | 000,004,096 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/09/12 05:36:41 | 000,004,096 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/12 05:36:41 | 000,004,096 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,584 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,584 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,584 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,584 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,584 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,584 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/12 05:36:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – F:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/09/12 05:36:40 | 002,348,544 | —- | C] (Microsoft Corporation) – F:\Windows\System32\win32k.sys
[2013/09/07 19:23:05 | 000,000,000 | —D | C] – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/09/07 19:23:03 | 000,022,856 | —- | C] (Malwarebytes Corporation) – F:\Windows\System32\drivers\mbam.sys
[2013/09/07 19:23:03 | 000,000,000 | —D | C] – F:\Program Files\Malwarebytes' Anti-Malware
[2013/09/05 13:35:42 | 000,000,000 | —D | C] – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/09/05 13:35:41 | 000,000,000 | —D | C] – F:\Program Files\CCleaner
[2013/09/05 13:26:12 | 000,000,000 | —D | C] – F:\AdwCleaner
[2013/09/05 13:21:37 | 000,012,872 | —- | C] (SurfRight B.V.) – F:\Windows\System32\bootdelete.exe
[2013/09/05 13:14:56 | 000,000,000 | —D | C] – F:\ProgramData\HitmanPro
[2013/09/03 08:12:34 | 000,000,000 | —D | C] – F:\TDSSKiller_Quarantine
[2013/09/02 14:18:07 | 000,000,000 | —D | C] – F:\Users\Tyler\Desktop\Old Firefox Data
[2013/09/01 17:53:12 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Roaming\LavasoftStatistics
[2013/09/01 17:50:18 | 000,000,000 | —D | C] – F:\ProgramData\Downloaded Installations
[2013/09/01 17:50:13 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Local\adawarebp
[2013/09/01 17:50:11 | 000,000,000 | —D | C] – F:\ProgramData\Ad-Aware Browsing Protection
[2013/09/01 17:50:07 | 000,000,000 | —D | C] – F:\Program Files\Toolbar Cleaner
[2013/09/01 17:49:50 | 000,000,000 | —D | C] – F:\Program Files\Lavasoft
[2013/09/01 17:48:35 | 000,044,424 | —- | C] (GFI Software) – F:\Windows\System32\sbbd.exe
[2013/09/01 17:48:35 | 000,013,560 | —- | C] (GFI Software) – F:\Windows\System32\drivers\gfibto.sys
[2013/09/01 17:32:40 | 000,000,000 | —D | C] – F:\ProgramData\Spybot - Search & Destroy
[2013/09/01 16:26:32 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Roaming\Malwarebytes
[2013/09/01 16:26:22 | 000,000,000 | —D | C] – F:\ProgramData\Malwarebytes
[2013/08/23 08:10:42 | 000,263,592 | —- | C] (Oracle Corporation) – F:\Windows\System32\javaws.exe
[2013/08/23 08:10:37 | 000,175,016 | —- | C] (Oracle Corporation) – F:\Windows\System32\javaw.exe
[2013/08/23 08:10:37 | 000,175,016 | —- | C] (Oracle Corporation) – F:\Windows\System32\java.exe
[2013/08/23 08:10:37 | 000,094,632 | —- | C] (Oracle Corporation) – F:\Windows\System32\WindowsAccessBridge.dll
[2013/08/23 08:00:41 | 000,000,000 | —D | C] – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\PuTTY
[2013/08/23 07:59:17 | 000,000,000 | —D | C] – F:\Program Files\SumatraPDF
[2013/08/23 07:55:06 | 000,000,000 | —D | C] – F:\Program Files\Adobe
[2013/08/23 07:55:05 | 000,000,000 | —D | C] – F:\Program Files\Common Files\Adobe
[2013/08/23 07:52:59 | 000,000,000 | —D | C] – F:\Program Files\Pidgin
[2013/08/23 07:51:51 | 000,000,000 | —D | C] – F:\Program Files\Common Files\PX Storage Engine
[2013/08/23 07:51:47 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Roaming\Winamp
[2013/08/23 07:51:47 | 000,000,000 | —D | C] – F:\Program Files\Winamp
[2013/08/23 07:51:00 | 000,000,000 | —D | C] – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/08/23 07:50:25 | 000,000,000 | —D | C] – F:\Program Files\VideoLAN
[2013/08/23 07:39:55 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Local\Secunia PSI
[2013/08/23 07:39:42 | 000,000,000 | —D | C] – F:\Program Files\Secunia
[2013/08/20 18:12:25 | 000,000,000 | —D | C] – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/08/20 18:11:24 | 000,000,000 | —D | C] – F:\Program Files\iPod
[2013/08/20 18:11:23 | 000,000,000 | —D | C] – F:\Program Files\iTunes
[2013/08/20 18:11:23 | 000,000,000 | —D | C] – F:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/08/20 18:08:13 | 000,000,000 | —D | C] – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[1 F:\Windows\*.tmp files -> F:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/09/14 17:26:54 | 000,067,584 | –S- | M] () – F:\Windows\bootstat.dat
[2013/09/14 17:26:49 | 2414,731,264 | -HS- | M] () – F:\hiberfil.sys
[2013/09/14 17:24:42 | 000,625,664 | —- | M] () – F:\Users\Tyler\Desktop\dds.scr
[2013/09/14 17:23:09 | 000,388,608 | —- | M] (Trend Micro Inc.) – F:\Users\Tyler\Desktop\HiJackThis.exe
[2013/09/14 17:22:15 | 000,602,112 | —- | M] (OldTimer Tools) – F:\Users\Tyler\Desktop\OTL.exe
[2013/09/14 16:39:00 | 000,000,830 | —- | M] () – F:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/14 16:13:01 | 000,000,366 | —- | M] () – F:\Windows\tasks\ReclaimerUpdateXML_Tyler.job
[2013/09/14 15:26:27 | 000,022,032 | -H– | M] () – F:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/14 15:26:27 | 000,022,032 | -H– | M] () – F:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/14 15:19:29 | 000,000,376 | —- | M] () – F:\Windows\tasks\RNUpgradeHelperLogonPrompt_Tyler.job
[2013/09/14 14:50:44 | 000,000,782 | —- | M] () – F:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/09/14 14:11:02 | 000,000,370 | —- | M] () – F:\Windows\tasks\ReclaimerUpdateFiles_Tyler.job
[2013/09/14 13:11:15 | 000,000,837 | —- | M] () – F:\Users\Public\Desktop\Pandora.lnk
[2013/09/14 01:39:06 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – F:\Windows\System32\FlashPlayerApp.exe
[2013/09/14 01:39:06 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – F:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/09/13 09:56:04 | 000,000,335 | —- | M] () – F:\local.conf
[2013/09/13 09:44:24 | 000,105,176 | —- | M] (Malwarebytes Corporation) – F:\Windows\System32\drivers\48230029.sys
[2013/09/13 08:26:43 | 000,031,560 | —- | M] () – F:\Windows\System32\drivers\mbamchameleon.sys
[2013/09/13 03:24:41 | 000,273,112 | —- | M] () – F:\Windows\System32\FNTCACHE.DAT
[2013/09/12 19:33:11 | 000,662,384 | —- | M] () – F:\Windows\System32\perfh009.dat
[2013/09/12 19:33:11 | 000,122,252 | —- | M] () – F:\Windows\System32\perfc009.dat
[2013/09/11 20:55:53 | 000,000,600 | —- | M] () – F:\Users\Tyler\AppData\Local\PUTTY.RND
[2013/09/10 21:28:56 | 001,927,606 | —- | M] () – F:\Users\Tyler\Desktop\HR2-Final-Multi.wad
[2013/09/06 19:53:34 | 000,001,945 | —- | M] () – F:\Windows\epplauncher.mif
[2013/09/06 19:13:42 | 000,000,079 | —- | M] () – F:\Windows\wininit.ini
[2013/09/05 13:35:42 | 000,000,975 | —- | M] () – F:\Users\Public\Desktop\CCleaner.lnk
[2013/09/05 13:29:20 | 000,001,190 | —- | M] () – F:\Windows\System32\ServiceConfig.xml
[2013/09/05 13:21:37 | 000,012,872 | —- | M] (SurfRight B.V.) – F:\Windows\System32\bootdelete.exe
[2013/09/04 07:15:26 | 000,088,840 | —- | M] (Avira Operations GmbH & Co. KG) – F:\Windows\System32\drivers\avgntflt.sys
[2013/09/01 17:48:35 | 000,044,424 | —- | M] (GFI Software) – F:\Windows\System32\sbbd.exe
[2013/09/01 17:48:35 | 000,013,560 | —- | M] (GFI Software) – F:\Windows\System32\drivers\gfibto.sys
[2013/08/29 07:10:29 | 000,136,672 | —- | M] (Avira Operations GmbH & Co. KG) – F:\Windows\System32\drivers\avipbb.sys
[2013/08/29 07:10:29 | 000,066,144 | —- | M] (Avira Operations GmbH & Co. KG) – F:\Windows\System32\drivers\avnetflt.sys
[2013/08/23 08:15:52 | 000,000,962 | —- | M] () – F:\Users\Public\Desktop\VLC media player.lnk
[2013/08/23 08:10:33 | 000,867,240 | —- | M] (Oracle Corporation) – F:\Windows\System32\npDeployJava1.dll
[2013/08/23 08:10:33 | 000,789,416 | —- | M] (Oracle Corporation) – F:\Windows\System32\deployJava1.dll
[2013/08/23 08:10:33 | 000,263,592 | —- | M] (Oracle Corporation) – F:\Windows\System32\javaws.exe
[2013/08/23 08:10:33 | 000,175,016 | —- | M] (Oracle Corporation) – F:\Windows\System32\javaw.exe
[2013/08/23 08:10:33 | 000,175,016 | —- | M] (Oracle Corporation) – F:\Windows\System32\java.exe
[2013/08/23 08:10:33 | 000,094,632 | —- | M] (Oracle Corporation) – F:\Windows\System32\WindowsAccessBridge.dll
[2013/08/23 07:55:33 | 000,001,999 | —- | M] () – F:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/08/23 07:52:24 | 000,000,971 | —- | M] () – F:\Users\Tyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2013/08/23 07:52:24 | 000,000,947 | —- | M] () – F:\Users\Public\Desktop\Winamp.lnk
[2013/08/20 18:12:25 | 000,001,763 | —- | M] () – F:\Users\Public\Desktop\iTunes.lnk
[1 F:\Windows\*.tmp files -> F:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/09/14 17:24:40 | 000,625,664 | —- | C] () – F:\Users\Tyler\Desktop\dds.scr
[2013/09/14 14:50:44 | 000,000,782 | —- | C] () – F:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/09/14 14:50:44 | 000,000,782 | —- | C] () – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/09/14 13:11:15 | 000,000,849 | —- | C] () – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pandora.lnk
[2013/09/14 13:11:15 | 000,000,837 | —- | C] () – F:\Users\Public\Desktop\Pandora.lnk
[2013/09/13 09:33:29 | 000,000,335 | —- | C] () – F:\local.conf
[2013/09/13 08:26:43 | 000,031,560 | —- | C] () – F:\Windows\System32\drivers\mbamchameleon.sys
[2013/09/10 21:28:54 | 001,927,606 | —- | C] () – F:\Users\Tyler\Desktop\HR2-Final-Multi.wad
[2013/09/10 16:09:03 | 000,000,376 | —- | C] () – F:\Windows\tasks\RNUpgradeHelperLogonPrompt_Tyler.job
[2013/09/10 16:09:02 | 000,000,370 | —- | C] () – F:\Windows\tasks\ReclaimerUpdateFiles_Tyler.job
[2013/09/10 16:09:01 | 000,000,366 | —- | C] () – F:\Windows\tasks\ReclaimerUpdateXML_Tyler.job
[2013/09/06 19:13:23 | 000,000,079 | —- | C] () – F:\Windows\wininit.ini
[2013/09/05 13:35:42 | 000,000,975 | —- | C] () – F:\Users\Public\Desktop\CCleaner.lnk
[2013/09/05 13:29:20 | 000,001,190 | —- | C] () – F:\Windows\System32\ServiceConfig.xml
[2013/08/23 07:59:18 | 000,001,813 | —- | C] () – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumatraPDF.lnk
[2013/08/23 07:56:24 | 000,001,676 | —- | C] () – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark.lnk
[2013/08/23 07:55:33 | 000,002,441 | —- | C] () – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/08/23 07:55:33 | 000,001,999 | —- | C] () – F:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/08/23 07:53:14 | 000,000,887 | —- | C] () – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk
[2013/08/23 07:52:24 | 000,000,971 | —- | C] () – F:\Users\Tyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2013/08/23 07:52:24 | 000,000,947 | —- | C] () – F:\Users\Public\Desktop\Winamp.lnk
[2013/08/23 07:51:00 | 000,000,962 | —- | C] () – F:\Users\Public\Desktop\VLC media player.lnk
[2013/08/23 07:39:44 | 000,001,037 | —- | C] () – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2013/08/20 18:12:25 | 000,001,763 | —- | C] () – F:\Users\Public\Desktop\iTunes.lnk
[2013/07/04 12:39:19 | 000,070,025 | —- | C] () – F:\Windows\System32\nglide_uninst.exe
[2013/06/30 11:57:07 | 000,174,749 | —- | C] () – F:\Windows\hpoins50.dat
[2013/06/30 11:57:07 | 000,001,241 | —- | C] () – F:\Windows\hpomdl50.dat
[2013/06/29 17:29:59 | 000,007,605 | —- | C] () – F:\Users\Tyler\AppData\Local\Resmon.ResmonCfg
[2013/06/07 12:19:39 | 000,112,100 | -H– | C] () – F:\Windows\System32\mlfcache.dat
[2013/04/20 09:02:05 | 000,000,632 | RHS- | C] () – F:\Users\Tyler\ntuser.pol
[2013/03/21 00:10:18 | 000,042,880 | —- | C] () – F:\Windows\System32\xfcodec.dll
[2013/02/15 15:29:42 | 001,318,912 | —- | C] () – F:\Windows\System32\glide3x.dll
[2012/12/25 17:53:25 | 000,033,792 | —- | C] () – F:\Windows\System32\drivers\libusb0.sys
[2012/11/02 20:04:26 | 000,053,248 | —- | C] () – F:\Windows\System32\nglide_config.exe
[2012/09/06 07:48:50 | 000,002,533 | —- | C] () – F:\Program Files\mcedit.ini
[2012/09/03 18:40:50 | 000,167,623 | —- | C] () – F:\Windows\hphins32.dat
[2012/09/03 18:24:52 | 000,167,598 | —- | C] () – F:\Windows\hphins32.dat.temp
[2012/09/03 18:12:07 | 000,000,632 | —- | C] () – F:\Windows\hphmdl32.dat.temp
[2012/07/23 08:49:01 | 000,000,600 | —- | C] () – F:\Users\Tyler\AppData\Local\PUTTY.RND
[2012/07/20 21:03:51 | 000,000,000 | —- | C] () – F:\Windows\ativpsrm.bin
[2012/06/11 16:50:42 | 000,159,232 | —- | C] () – F:\Windows\System32\clinfo.exe
[2012/06/11 12:41:48 | 000,204,952 | —- | C] () – F:\Windows\System32\ativvsvl.dat
[2012/06/11 12:41:48 | 000,157,144 | —- | C] () – F:\Windows\System32\ativvsva.dat
[2012/05/10 19:35:16 | 000,029,184 | —- | C] () – F:\Windows\System32\kdbsdk32.dll
[2012/04/12 15:30:10 | 000,637,743 | —- | C] () – F:\Windows\System32\atiicdxx.dat

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – F:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/07/25 21:55:59 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 17:29:20 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/03/30 14:12:14 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\.doomseeker
[2012/12/24 17:44:51 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\.minecraft
[2013/09/14 13:11:20 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\com.pandora.desktop
[2013/09/14 13:11:19 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\com.pandora.desktop.E7C14276FFE9EEF0BC7DCE654C467D9A299EFD21.1
[2013/09/07 18:14:51 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\Dropbox
[2012/09/12 09:47:21 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\e-academy Inc
[2012/07/21 12:12:46 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\Fatshark
[2013/09/13 03:20:08 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\FileZilla
[2013/01/15 07:31:48 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\Juniper Networks
[2012/11/14 20:11:06 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\NuGet
[2012/08/22 22:17:23 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\OpenOffice.org
[2012/12/27 16:24:58 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\Red Alert 3
[2012/08/09 16:34:11 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\SLumpEd
[2012/12/27 14:53:04 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\TeamViewer
[2013/09/05 13:38:04 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\uTorrent
[2012/08/01 12:15:27 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\Vessel
[2012/08/16 22:10:26 | 000,000,000 | —D | M] – F:\Users\Tyler\AppData\Roaming\ZombieDriver

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009/07/14 00:53:46 | 000,026,886 | —- | C] () – F:\Windows\Tasks\SCHEDLGU.TXT
[2009/07/14 00:53:47 | 000,000,006 | -H– | C] () – F:\Windows\Tasks\SA.DAT
[2012/07/20 21:06:59 | 000,000,830 | —- | C] () – F:\Windows\Tasks\Adobe Flash Player Updater.job
[2013/09/10 16:09:01 | 000,000,366 | —- | C] () – F:\Windows\Tasks\ReclaimerUpdateXML_Tyler.job
[2013/09/10 16:09:02 | 000,000,370 | —- | C] () – F:\Windows\Tasks\ReclaimerUpdateFiles_Tyler.job
[2013/09/10 16:09:03 | 000,000,376 | —- | C] () – F:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Tyler.job

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2011/04/11 22:15:49 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – F:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2011/04/11 22:15:49 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – F:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – F:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – F:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.BMP >
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1028\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1031\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1033\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1036\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1040\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1041\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1042\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\1049\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\2052\explorer.bmp
[2011/12/12 13:29:50 | 000,000,246 | —- | M] () MD5=EB73135E745C47670BF509ACF5E91698 – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\templates\3082\explorer.bmp

< MD5 for: EXPLORER.DESIGNER.VB >
[2011/12/12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb
[2011/12/12 13:52:40 | 000,036,545 | —- | M] () MD5=0BFA552D19A4A7F9130A71DFBBCB1407 – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.designer.vb

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 17:29:20 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – F:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – F:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2011/04/11 22:15:39 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – F:\Windows\en-US\explorer.exe.mui
[2011/04/11 22:15:39 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – F:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/09/13 19:16:55 | 000,056,074 | —- | M] () MD5=CF8A6E796CAFFE713B8C18DE37A31DA1 – F:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf

< MD5 for: EXPLORER.GIF >
[2012/06/24 21:45:02 | 000,001,483 | —- | M] () MD5=4ABBABE57F99C84C4154DD289B766E5E – F:\Program Files\Microsoft Visual Studio 11.0\VC\VCWizards\AppWiz\MFC\Application\images\Explorer.gif

< MD5 for: EXPLORER.RESX >
[2011/12/12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.resx
[2011/12/12 13:52:40 | 000,040,049 | —- | M] () MD5=B16D2C77324DE7222CB0EA55C7B32784 – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.resx

< MD5 for: EXPLORER.VB >
[2011/12/12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vb
[2011/12/12 13:52:40 | 000,008,501 | —- | M] () MD5=55808E7AF87B5C18B97707BEF8EBDDEA – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vb

< MD5 for: EXPLORER.VSTEMPLATE >
[2011/12/12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplates\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate
[2011/12/12 13:52:40 | 000,006,491 | —- | M] () MD5=FB731348042E3356E2215A6747CE893C – F:\Program Files\Microsoft Visual Studio 11.0\Common7\IDE\ItemTemplatesCache\VisualBasic\Windows Forms\1033\Explorer\explorer.vstemplate

< MD5 for: IEXPLORE.EXE >
[2013/05/16 22:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_ba6545dc65e543de\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_b1148f09c82553c5\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_b119907bc820d278\iexplore.exe
[2013/03/14 03:01:26 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=2859EBC065D2E1CCC94161CE28BAC085 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_ba715a6a65dbf461\iexplore.exe
[2013/06/12 00:41:27 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=2A5F565327BFD679EC5F790DC15BBF25 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_a38ffdc27f91d847\iexplore.exe
[2013/04/05 01:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_a39ee59e7f860811\iexplore.exe
[2013/06/11 20:23:57 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_ba672fa865e3902d\iexplore.exe
[2012/07/21 10:05:41 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_b12660fbc816e935\iexplore.exe
[2013/08/10 00:18:11 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – F:\Program Files\Internet Explorer\iexplore.exe
[2013/08/10 00:18:11 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_ba6c1a5265df2881\iexplore.exe
[2013/05/16 21:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_a38c5d6c7f953fa9\iexplore.exe
[2013/08/10 01:13:42 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=48A1306191216997F717C451B8D15139 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_a394d1a47f8d8a3c\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_b1a52ddae13ca4f0\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_b10dc045c829d512\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_ba6aa26e65e05c0d\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_b1276145c816028c\iexplore.exe
[2013/02/24 19:52:40 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=A11C5E3E288256C540B7ED8BE3A04B01 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_a39aa01e7f89ef98\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_b17dbc10e15b4762\iexplore.exe
[2013/04/05 02:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_ba75e9f465d7f339\iexplore.exe
[2012/11/16 12:33:24 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=B201AF83DF2E85323E29EB83E4046810 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_b11b910fc81f0526\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – F:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/11/15 23:08:47 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=C0BA71C1B3FB6E3DD432FF3CCAEBDC62 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_b1985d5ae1468e33\iexplore.exe
[2010/11/20 17:29:33 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_b1955c7ce149422e\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_b0feef31c8358ba7\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_ba7371c665da0d6e\iexplore.exe
[2013/07/26 01:09:39 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_a39175a67f90a4bb\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_b1a22cfce13f58eb\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – F:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_b18b8cdae1507776\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/07/21 10:05:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – F:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/03/14 03:01:26 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – F:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/14 03:01:26 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – F:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – F:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/09/14 14:49:35 | 000,189,250 | —- | M] () MD5=E2C5188FBC658B2E2EE0451BEA49773A – F:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf

< MD5 for: SERVICES >
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – F:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – F:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
[2013/09/10 13:54:42 | 000,923,266 | —- | M] () MD5=DAA394ED6647EEDF7AC6E7553A7550CD – F:\Program Files\Wireshark\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – F:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 06:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – F:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – F:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – F:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2011/04/11 22:15:38 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – F:\Windows\System32\en-US\services.exe.mui
[2011/04/11 22:15:38 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – F:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | -H– | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | -H– | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – F:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – F:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – F:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2011/04/11 22:15:37 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – F:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – F:\Windows\System32\services.msc
[2011/04/11 22:15:37 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – F:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – F:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – F:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – F:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2011/04/11 22:15:49 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – F:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2011/04/11 22:15:49 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – F:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – F:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – F:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 17:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – F:\Windows\System32\winlogon.exe
[2010/11/20 17:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – F:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – F:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2011/04/11 22:15:37 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – F:\Windows\System32\en-US\winlogon.exe.mui
[2011/04/11 22:15:37 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – F:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2011/04/11 22:15:38 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – F:\Windows\System32\wbem\en-US\winlogon.mfl
[2011/04/11 22:15:38 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – F:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – F:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – F:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – F:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – F:\config.sys
[2012/08/04 14:20:08 | 000,004,083 | —- | M] () – F:\END1.TXT
[2012/08/04 14:20:08 | 002,943,658 | —- | M] () – F:\END1.WAD
[2012/08/04 14:19:43 | 000,004,859 | —- | M] () – F:\End2.txt
[2012/08/04 14:19:43 | 002,567,556 | —- | M] () – F:\End2.wad
[2012/08/04 14:20:08 | 000,424,944 | —- | M] () – F:\END_SND.WAD
[2012/07/20 18:55:06 | 601,538,560 | —- | M] () – F:\en_windows_7_professional_with_sp1_x86_dvd_u_677056.iso
[2013/09/14 17:26:49 | 2414,731,264 | -HS- | M] () – F:\hiberfil.sys
[2013/09/13 09:56:04 | 000,000,335 | —- | M] () – F:\local.conf
[2012/08/04 13:52:17 | 000,002,689 | —- | M] () – F:\Mspd Readme!.txt
[2012/08/04 13:52:17 | 000,000,553 | —- | M] () – F:\mspd-dbpistolspawnv2.pk3
[2012/08/04 13:52:17 | 000,000,813 | —- | M] () – F:\mspd-lmsfixv4.pk3
[2012/08/04 13:52:17 | 000,003,247 | —- | M] () – F:\mspd-randomspawner5.2.pk3
[2012/08/04 13:52:17 | 010,851,318 | —- | M] () – F:\mspdbet52.pk3
[2012/08/04 13:52:17 | 005,250,178 | —- | M] () – F:\mspdmaps-v1.pk3
[2013/09/14 17:26:49 | 3219,644,416 | -HS- | M] () – F:\pagefile.sys
[2013/09/03 08:12:46 | 000,287,144 | —- | M] () – F:\TDSSKiller.2.8.16.0_03.09.2013_08.10.07_log.txt
[2013/09/03 08:16:46 | 000,466,174 | —- | M] () – F:\TDSSKiller.2.8.16.0_03.09.2013_08.14.59_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – F:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – F:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – F:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – F:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – F:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/04/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – F:\Windows\system32\spool\prtprocs\w32x86\CNMPDA0.DLL
[2010/04/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – F:\Windows\system32\spool\prtprocs\w32x86\CNMPPA0.DLL
[2010/05/07 14:56:18 | 000,319,488 | —- | M] (Hewlett-Packard Corporation) – F:\Windows\system32\spool\prtprocs\w32x86\hpfpp101.dll
[2008/12/16 18:17:56 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – F:\Windows\system32\spool\prtprocs\w32x86\hpfpp6en.dll
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – F:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 17:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – F:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – F:\Program Files\desktop.ini
[2012/09/06 08:12:24 | 000,002,533 | —- | M] () – F:\Program Files\mcedit.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive F is New Volume
Volume Serial Number is 5CB6-C646
Directory of F:\
07/14/2009 12:53 AM Documents and Settings [F:\Users]
0 File(s) 0 bytes
Directory of F:\ProgramData
07/14/2009 12:53 AM Application Data [F:\ProgramData]
07/14/2009 12:53 AM Desktop [F:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [F:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [F:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [F:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [F:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of F:\Users
07/14/2009 12:53 AM All Users [F:\ProgramData]
07/14/2009 12:53 AM Default User [F:\Users\Default]
0 File(s) 0 bytes
Directory of F:\Users\All Users
07/14/2009 12:53 AM Application Data [F:\ProgramData]
07/14/2009 12:53 AM Desktop [F:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [F:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [F:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [F:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [F:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of F:\Users\Default
07/14/2009 12:53 AM Application Data [F:\Users\Default\AppData\Roaming]
07/14/2009 12:53 AM Cookies [F:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:53 AM Local Settings [F:\Users\Default\AppData\Local]
07/14/2009 12:53 AM My Documents [F:\Users\Default\Documents]
07/14/2009 12:53 AM NetHood [F:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:53 AM PrintHood [F:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:53 AM Recent [F:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:53 AM SendTo [F:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:53 AM Start Menu [F:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [F:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of F:\Users\Default\AppData\Local
07/14/2009 12:53 AM Application Data [F:\Users\Default\AppData\Local]
07/14/2009 12:53 AM History [F:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:53 AM Temporary Internet Files [F:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of F:\Users\Default\Documents
07/14/2009 12:53 AM My Music [F:\Users\Default\Music]
07/14/2009 12:53 AM My Pictures [F:\Users\Default\Pictures]
07/14/2009 12:53 AM My Videos [F:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of F:\Users\Public\Documents
07/14/2009 12:53 AM My Music [F:\Users\Public\Music]
07/14/2009 12:53 AM My Pictures [F:\Users\Public\Pictures]
07/14/2009 12:53 AM My Videos [F:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of F:\Users\Tyler
07/20/2012 11:12 PM Application Data [F:\Users\Tyler\AppData\Roaming]
07/20/2012 11:12 PM Cookies [F:\Users\Tyler\AppData\Roaming\Microsoft\Windows\Cookies]
07/20/2012 11:12 PM Local Settings [F:\Users\Tyler\AppData\Local]
07/20/2012 11:12 PM My Documents [F:\Users\Tyler\Documents]
07/20/2012 11:12 PM NetHood [F:\Users\Tyler\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/20/2012 11:12 PM PrintHood [F:\Users\Tyler\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/20/2012 11:12 PM Recent [F:\Users\Tyler\AppData\Roaming\Microsoft\Windows\Recent]
07/20/2012 11:12 PM SendTo [F:\Users\Tyler\AppData\Roaming\Microsoft\Windows\SendTo]
07/20/2012 11:12 PM Start Menu [F:\Users\Tyler\AppData\Roaming\Microsoft\Windows\Start Menu]
07/20/2012 11:12 PM Templates [F:\Users\Tyler\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of F:\Users\Tyler\AppData\Local
07/20/2012 11:12 PM Application Data [F:\Users\Tyler\AppData\Local]
07/20/2012 11:12 PM History [F:\Users\Tyler\AppData\Local\Microsoft\Windows\History]
07/20/2012 11:12 PM Temporary Internet Files [F:\Users\Tyler\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of F:\Users\Tyler\Documents
07/20/2012 11:12 PM My Music [F:\Users\Tyler\Music]
07/20/2012 11:12 PM My Pictures [F:\Users\Tyler\Pictures]
07/20/2012 11:12 PM My Videos [F:\Users\Tyler\Videos]
0 File(s) 0 bytes
Directory of F:\Users\Work Station
04/20/2013 09:12 AM Application Data [F:\Users\Work Station\AppData\Roaming]
04/20/2013 09:12 AM Cookies [F:\Users\Work Station\AppData\Roaming\Microsoft\Windows\Cookies]
04/20/2013 09:12 AM Local Settings [F:\Users\Work Station\AppData\Local]
04/20/2013 09:12 AM My Documents [F:\Users\Work Station\Documents]
04/20/2013 09:12 AM NetHood [F:\Users\Work Station\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/20/2013 09:12 AM PrintHood [F:\Users\Work Station\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/20/2013 09:12 AM Recent [F:\Users\Work Station\AppData\Roaming\Microsoft\Windows\Recent]
04/20/2013 09:12 AM SendTo [F:\Users\Work Station\AppData\Roaming\Microsoft\Windows\SendTo]
04/20/2013 09:12 AM Start Menu [F:\Users\Work Station\AppData\Roaming\Microsoft\Windows\Start Menu]
04/20/2013 09:12 AM Templates [F:\Users\Work Station\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of F:\Users\Work Station\AppData\Local
04/20/2013 09:12 AM Application Data [F:\Users\Work Station\AppData\Local]
04/20/2013 09:12 AM History [F:\Users\Work Station\AppData\Local\Microsoft\Windows\History]
04/20/2013 09:12 AM Temporary Internet Files [F:\Users\Work Station\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of F:\Users\Work Station\Documents
04/20/2013 09:12 AM My Music [F:\Users\Work Station\Music]
04/20/2013 09:12 AM My Pictures [F:\Users\Work Station\Pictures]
04/20/2013 09:12 AM My Videos [F:\Users\Work Station\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
66 Dir(s) 168,801,398,784 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/07/21 10:26:58 | 000,000,221 | -HS- | M] () – F:\Users\Tyler\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/09/14 17:23:09 | 000,388,608 | —- | M] (Trend Micro Inc.) – F:\Users\Tyler\Desktop\HiJackThis.exe
[2013/09/14 17:22:15 | 000,602,112 | —- | M] (OldTimer Tools) – F:\Users\Tyler\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2012/05/29 09:35:38 | 000,001,422 | —- | M] () – F:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-09-13 07:56:22

< End of report >



Extras.txt

OTL Extras logfile created on: 9/14/2013 5:30:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = F:\Users\Tyler\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 70.79% Memory free
6.00 Gb Paging File | 5.16 Gb Available in Paging File | 86.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = F: | %SystemRoot% = F:\Windows | %ProgramFiles% = F:\Program Files
Drive C: | 232.88 Gb Total Space | 29.93 Gb Free Space | 12.85% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 151.26 Gb Free Space | 64.95% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 85.47 Gb Free Space | 36.70% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 157.31 Gb Free Space | 67.55% Space Free | Partition Type: NTFS
Drive K: | 1.87 Gb Total Space | 1.14 Gb Free Space | 61.07% Space Free | Partition Type: FAT

Computer Name: TYLER-PC | User Name: Tyler | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – F:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – F:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "F:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "F:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E2F8900-A29C-48E1-B1E0-40149D35C2FE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{10C2E8E1-CF5F-44EA-8771-9A10F2A3E979}" = lport=445 | protocol=6 | dir=in | app=system |
"{19E4DA6F-26C2-4456-AAF1-77F1E0EC5328}" = rport=137 | protocol=17 | dir=out | app=system |
"{1EC7ADA1-8452-4842-82FB-4038BD0121DA}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{1F9CCE20-3C29-4DBF-BC96-4A907FCC2D9B}" = lport=137 | protocol=17 | dir=in | app=system |
"{22EFB0B8-0872-45AC-A5FC-13E8FA7189A0}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=f:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{25C5EC3B-3A64-4315-8781-41953157ECED}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{28A8B4B1-8343-46BD-AEBB-AD145176ED57}" = lport=10243 | protocol=6 | dir=in | app=system |
"{373A832A-B747-4B49-9AED-0A281D5C18C0}" = lport=139 | protocol=6 | dir=in | app=system |
"{44F7C055-421C-46FB-8CF0-1BDD0F7C96DB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{47C968DD-A84F-4176-AD37-3192D1470BE1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4BFE7807-D848-45E1-86D3-E1C7A48F1465}" = rport=445 | protocol=6 | dir=out | app=system |
"{50065488-E7C4-427E-83A1-98D91006239A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5BA28E26-EE93-4B7E-B413-3158E29A287C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5FAF186B-EC03-43D0-B787-FBE4904CAF58}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=f:\windows\system32\svchost.exe |
"{7732DBB3-6174-44A4-B5B7-1827DC25C7FD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7B960989-87E3-4EA4-B275-399B9497B513}" = lport=3702 | protocol=17 | dir=in | app=f:\program files\microsoft visual studio 11.0\common7\ide\devenv.exe |
"{9926E5B1-D592-42C1-95B8-535240E1310C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B5165DEF-84AF-4901-8A06-CA329792CDCC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B6605186-7C8D-423B-94E9-0C2F16F63818}" = rport=138 | protocol=17 | dir=out | app=system |
"{D7A2C3C7-7BFB-4DD4-A3D3-B0B68F7370C1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DAA290EC-E239-490D-8E3F-0FBD61D9AA0E}" = lport=138 | protocol=17 | dir=in | app=system |
"{DC819E1A-0013-4FE9-B874-24C268274DC3}" = rport=10243 | protocol=6 | dir=out | app=system |
"{E2DFCAED-DF7E-461A-8EA8-75EC85C9ED35}" = rport=139 | protocol=6 | dir=out | app=system |
"{E787A757-7913-4E10-A9C8-1D054552BA42}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{E9A3A30E-3917-443A-92A0-B4DC772798CD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EB46FB04-5CD4-4B8C-BCDE-219C1C2F74ED}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EC800FDD-5A4C-4439-A1DA-700B2BB9417A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{006EB2FF-98E6-4971-8BBD-FAF2D8939A37}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (v) chronicles\pctomb5.exe |
"{02AC3E07-8611-48FC-8394-C1E14E82E5C2}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{06331253-AB78-4498-8B03-EA4E6C0C1D14}" = protocol=17 | dir=in | app=f:\program files\teamviewer\version8\teamviewer_service.exe |
"{0895D0A7-9DF1-4055-B572-003D1C3489FB}" = protocol=17 | dir=in | app=e:\steamapps\common\tomb raider (v) chronicles\pctomb5.exe |
"{0959CB4C-29C9-4D4C-9E4E-515AE161C8B7}" = protocol=17 | dir=in | app=f:\program files\bonjour\mdnsresponder.exe |
"{0992BC07-A7FD-482C-A812-302B2DDDE376}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\dosbox.exe |
"{0A2D7DFB-5C24-49D2-B182-34B9D35AC74D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0B911C1C-B6D0-4816-BD84-B7D5E1FBA42F}" = protocol=6 | dir=in | app=e:\steamapps\common\killingfloor\system\killingfloor.exe |
"{0C349DF1-E0A5-4249-BF55-37919E28D731}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{0C5E17B7-599A-471B-96AC-00FCE1447968}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\vanguard saga of heroes f2p\launchpad.exe |
"{0E1AA1A2-D1D5-40F2-AD66-95AFD43F7030}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\heretic shadow of the serpent riders\base\dosbox.exe |
"{0E290C48-1667-4F0B-A655-570534B7F045}" = protocol=6 | dir=in | app=e:\steamapps\common\supermnc\uberlauncher.exe |
"{0E857BA1-72CF-4530-8BF3-8D519B641C02}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\vessel\vessel.exe |
"{110DA76B-96FE-4C9B-AFB7-908BF89C0F17}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{113FEFDF-3EA6-43E9-92C8-499B24D07578}" = protocol=17 | dir=in | app=d:\doom\zandronum\zandronum.exe |
"{11EFA5A5-EBF4-4798-880D-FEC4A0B75E61}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider anniversary\tra.exe |
"{127F7B97-DF23-4F39-9CD5-1B4460B4D807}" = protocol=6 | dir=out | app=system |
"{139C8A8F-4784-4F82-849B-2C0F7F4B978B}" = protocol=6 | dir=in | app=d:\doom\zandronum\doomseeker\doomseeker.exe |
"{13B63FC5-8CE9-43B1-8CF5-122100ABC208}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1474FE29-0F44-4B0A-8609-CE4A1C1AD17F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\brink\brink.exe |
"{14FB35FA-521F-4C31-85CB-E2FD2FBD2BD9}" = protocol=6 | dir=in | app=d:\doom\zandronum\zandronum.exe |
"{183237D0-D32A-4747-A5EE-DDD368D4635B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{187B144E-EF71-4642-9F43-46BF8F6FB072}" = protocol=6 | dir=in | app=e:\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{19A18992-EDA4-4F6B-B90A-6824C09D448B}" = protocol=17 | dir=in | app=d:\doom\zandronum\doomseeker\doomseeker.exe |
"{1A487B62-B56A-4338-8EFE-BB0325578326}" = protocol=17 | dir=in | app=e:\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{1C6774A5-EFBE-44D0-9791-35BF733BF448}" = protocol=17 | dir=in | app=e:\steamapps\common\supermnc\uberlauncher.exe |
"{1D3042A6-0591-4345-8209-53AC3D93F4CB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{1D776147-FFAC-49D4-A4A0-591AD6622976}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\altitude\altitude.exe |
"{1D99C6BA-31CE-4551-BD06-9935199CEDA2}" = dir=in | app=f:\program files\itunes\itunes.exe |
"{1E706613-935A-4E30-B6A1-8268F570139B}" = dir=in | app=f:\users\tyler\appdata\local\temp\7zs0879\setup\hpznui01.exe |
"{1F379A8F-F34E-4C19-8773-65FC57157694}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{20568222-7282-405B-A4E5-FB3B38281C0A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\qube\binaries\win32\qube.exe |
"{211580E5-9A8A-4706-850A-5C7CD9724F77}" = protocol=6 | dir=in | app=f:\programdata\battle.net\agent\agent.1675\agent.exe |
"{21DE8AD1-ED01-4DD0-884E-B5458CBF1857}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\brink\brink.exe |
"{228E298E-5D3D-4E0D-A186-550A52A1CFFC}" = protocol=6 | dir=in | app=f:\programdata\battle.net\agent\agent.1737\agent.exe |
"{22B3955B-C355-4DE6-BE9A-FC7010109656}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\metro 2033\metro2033.exe |
"{24F160BF-ABD3-43DA-8B6C-FF5D692CB585}" = protocol=6 | dir=in | app=e:\steamapps\common\krater\run_game.exe |
"{27A3FA3A-857B-4616-B206-5610DB2ADF8A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\half-life 2\hl2.exe |
"{29248394-5F9E-42ED-BA2D-3240D4B17B8D}" = protocol=6 | dir=in | app=f:\users\tyler\appdata\roaming\dropbox\bin\dropbox.exe |
"{2B95A4F1-3207-4659-AA1C-5F1630019CFC}" = protocol=6 | dir=in | app=e:\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{2CF2FB42-5B47-4C43-AB4A-9A2343B62C23}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mirrors edge\support\ea help\electronic_arts_technical_support.htm |
"{2E521FC9-B0EF-4293-AB2E-8F3801218CD7}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{307F218B-F43D-45E7-9CE9-BA30470B109B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\hunted\binaries\win32\hunted.exe |
"{30E587BE-59D3-449C-A593-3CE91AA31F98}" = protocol=17 | dir=in | app=f:\programdata\battle.net\agent\agent.2045\agent.exe |
"{33CAA024-7B7C-4683-B8AB-C0FCF0BDAE41}" = protocol=6 | dir=in | app=e:\steamapps\common\microvolts\launcher.exe |
"{3461B733-1198-4010-93DB-E6D0DB552C8D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{350DCE75-F7BB-4F28-9B39-098A0DFC74B0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{35D2E3BA-9C67-4FF8-A8C8-7A21A2EE6B2B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{390859BD-3314-40EF-8F45-21430E97CE9C}" = protocol=6 | dir=in | app=e:\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{3B0F6DA0-EA35-4F9B-914C-13A411D3BAC3}" = protocol=17 | dir=in | app=f:\program files\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{3B63C57C-9BF5-47F3-B38B-0408F8760F7E}" = protocol=17 | dir=in | app=f:\programdata\battle.net\agent\agent.1675\agent.exe |
"{3D77EE6F-B717-43FE-A22A-08B50E3EFC41}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{413B0FF5-A537-42B6-B349-676D4F5C6900}" = protocol=17 | dir=in | app=f:\users\tyler\appdata\roaming\dropbox\bin\dropbox.exe |
"{4148C3BB-4967-4DD8-A2C7-E3B28169A098}" = protocol=17 | dir=in | app=c:\program files\starcraft ii\versions\base26490\sc2.exe |
"{41EE880C-AFC7-46B1-8838-8FEE1CC4219B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\hexen\base\dosbox.exe |
"{42708EA8-108F-4B02-80DC-A318C0A6F240}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\microvolts\launcher.exe |
"{44051EC1-6AD2-43EB-BFC2-34C02A5AD01C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (ii)\tomb2.exe |
"{448D3974-13C1-44E7-8821-A1F09688BFFD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (v) chronicles\pctomb5.exe |
"{4577CF0A-F14C-4670-A553-274905433558}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{4783E5B5-48DA-43BA-B51E-E3B2E7218FF6}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (i)\dosbox.exe |
"{4855CBFC-36DA-4F79-9AB8-3671BFC47E8A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\defcon\defcon.exe |
"{4ACE9065-B6EF-491D-80AE-BFEF7B580F61}" = protocol=17 | dir=in | app=e:\steamapps\common\combat arms\calauncher.exe |
"{4D2EE0CC-DA80-47F1-9DAF-5899E1894B38}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\combat arms\calauncher.exe |
"{51572F39-804A-43C9-870E-60CE8CD3AF61}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{53355FCA-F745-40AC-A590-B74B6BD3BDBF}" = protocol=17 | dir=in | app=e:\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{58E65396-EB76-4FB9-9517-5EB83B6470C7}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\altitude\altitude.exe |
"{5C76924A-DD77-4817-B893-B28C337034B6}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpqste08.exe |
"{5E213638-2DA9-41EF-B16C-9369ED00F54C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{5E405D87-A0E7-410B-B1F2-609B7B595A66}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
"{5F1026FE-9046-4D73-BE46-1697AE2A6E28}" = dir=in | app=f:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{5F68D5C2-9D0C-4338-BCC1-BE6DB61511C6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\final doom\base\dosbox.exe |
"{606900A9-2062-4883-9636-C122465B9F2D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{60840F9D-FA82-4D88-A156-21FD8B76DEB3}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider legend\trl.exe |
"{62A91AFC-A06F-4245-8FB3-E05180627EAB}" = protocol=17 | dir=in | app=e:\steamapps\common\qube\binaries\win32\qube.exe |
"{6446AE46-D516-4D6A-B6AE-A898B371D135}" = dir=in | app=f:\program files\hp\hp software update\hpwucli.exe |
"{6915F2D8-AF80-4B31-86B0-1D974C16C12E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{694FD659-D6FF-4524-9027-971E5B15F125}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\qube\binaries\win32\qube.exe |
"{697648E2-8FCF-467B-99AA-153DC1B4DB2E}" = protocol=17 | dir=in | app=e:\steamapps\common\killingfloor\system\killingfloor.exe |
"{6AEC46D2-288E-46DF-A18B-1CDC8F787D24}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\kfed.exe |
"{6BF114FF-FC2A-463D-BC5F-24A16C235CE5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6BF72409-6968-44DD-808A-7AE749A427A1}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\surgeon simulator 2013\ss2013.exe |
"{6D0CD249-EB87-4DBB-869B-6FB679355F30}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6D620B32-05CB-41C8-9411-DEE410961EDC}" = protocol=6 | dir=in | app=f:\program files\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{6DA637BA-6217-4530-8991-7EA86ACEDE81}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\half-life\hl.exe |
"{6DD1EC70-E0CE-4F7F-B651-C524E9FB8E5F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{6E98AC8A-7AD0-4DB6-9ABC-04E956BE8EBD}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{6EC8C4DB-B85F-41FA-BA9D-BCED530C4F00}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{6EE6DAFA-2B79-42BA-AA5C-76D6D50C9703}" = protocol=6 | dir=in | app=c:\program files\starcraft ii\versions\base26490\sc2.exe |
"{7054368A-E7BE-47B6-827D-250ED7C1FE64}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\avadon the black fortress\avadon.exe |
"{70ACE8F0-E6A4-49A1-AB8A-9919873F3CEC}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{70BCAC71-93E6-4AB9-8B55-8E5B76B6F415}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2.bat |
"{72A903AB-DB48-4878-9DAB-AE265C6BE610}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{72C8851F-AD14-4E5F-9C5A-9C713239EDFE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{7368E8AE-2497-45B8-9276-D7814CD34D27}" = protocol=17 | dir=in | app=e:\steamapps\common\bastion\bastion.exe |
"{74E4EEBC-6AA0-4CFE-A942-4438626B4C3C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 test\dota.exe |
"{75D1D7C1-6367-43BA-9F29-878E93316DC1}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2 demo\justcause2.exe |
"{775D7018-2A69-4A23-AF7C-CCCB67A1B85E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{777C0B39-8CA7-47DD-BEDE-F24AE845B080}" = protocol=6 | dir=in | app=e:\steamapps\common\qube\binaries\win32\qube.exe |
"{779401F6-0D0F-48EF-BB6C-A73B3D9E262E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\krater\run_game.exe |
"{791A664F-1EEF-409D-BFB2-5A214C4D744D}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{79751BA8-E751-4C2E-A9FB-9E9883C6BBD8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\avadon the black fortress\avadon.exe |
"{798B02AF-D67A-4066-9338-CBC51522FF25}" = protocol=17 | dir=in | app=f:\programdata\battle.net\agent\agent.1040\agent.exe |
"{79B74CD6-6FF0-41D3-82AD-F81D2381081F}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{79DEF8BB-231C-4348-9E02-1AE6AE11BE23}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\kfed.exe |
"{7B8248B2-D9B6-4D69-BBA9-C0189836A281}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
"{7B9E5C4B-9CFF-4495-90A5-83B66D021130}" = protocol=6 | dir=in | app=e:\steamapps\common\skyrim\skyrimlauncher.exe |
"{7CB8AB3A-C00D-4F76-8042-DAA02CA772CD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{7E3DD65A-D00A-43F6-A499-60576BEB2642}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\ultimate doom\base\dosbox.exe |
"{7E5EE7BF-E8E4-4C15-8976-7B78E268393E}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpoews01.exe |
"{7F9B6094-6B31-49A5-BED1-A0835789B13E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2.bat |
"{81410207-0411-4D01-B911-46787556FEEC}" = dir=in | app=f:\program files\windows live\contacts\wlcomm.exe |
"{81758FBA-A6F9-4297-8DA2-9B8473E4225E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\krater\run_game.exe |
"{81F59ACC-ABD8-46A2-B2F9-3520E0F7F06F}" = protocol=6 | dir=in | app=e:\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{8242E4BA-7050-4A4D-B88C-1F3EBB5639D5}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\ultimate doom\base\dosbox.exe |
"{842B5870-5142-498D-9643-8716B1B1C78D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\combat arms\calauncher.exe |
"{84B21241-562F-4100-97B1-2B5D3E370560}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2 demo\justcause2.exe |
"{84B75AEA-69EB-4294-9E64-7F7E50C6FB36}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{88237B93-47F3-42B5-B9B0-89F8ACBDD0AC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mirrors edge\binaries\mirrorsedge.exe |
"{89D27EF4-97C8-4684-9623-3F1754CE9ADF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\half-life\hl.exe |
"{8B3BD6C7-93BF-4982-8D47-0EF9F43847B0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\dosbox.exe |
"{8B4CC384-158B-4546-9C3A-93317CDD6694}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\hexen deathkings of the dark citadel\base\dosbox.exe |
"{8CC581AF-7E08-468A-A562-6B1D4273117C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{8CEAF106-5653-45A6-8067-461BB543EA99}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\vanguard saga of heroes f2p\launchpad.exe |
"{8D25566B-2C1F-4A0C-BC96-7D62707B191F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\doom 3\doom3.exe |
"{8D6B7964-5108-4CFB-84C7-216493C399EF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mirrors edge\binaries\mirrorsedge.exe |
"{8F6209A8-407D-4957-BBEF-E6B4806B3A4C}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{93454B5D-C8E2-4F07-8203-2F883BED56A0}" = protocol=17 | dir=in | app=f:\users\tyler\downloads\winbuilder.exe |
"{93B168DB-E7F4-4269-B894-2BB7BD40D95B}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{93E731FD-E285-49E3-938C-30BCDAA033C8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\microvolts\launcher.exe |
"{94004E2C-0FCA-4E21-9056-118843D31217}" = dir=in | app=f:\program files\windows live\messenger\msnmsgr.exe |
"{94EE3CB5-6E36-4664-86C4-09385CE3EC7A}" = protocol=6 | dir=in | app=e:\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
"{966CF028-4729-499A-8A03-995863C7F4FD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
"{968CFD3E-65B0-410C-81B7-B50080B1170D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{99060C5E-E32A-4EA2-8C68-2BC7FCEBA248}" = protocol=17 | dir=in | app=f:\program files\teamviewer\version8\teamviewer.exe |
"{99A5DA38-79D0-40A5-86C3-B43DBB7C2552}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (ii)\tomb2.exe |
"{9C6E2D55-E637-4437-87B7-7EE2824FFCD8}" = protocol=6 | dir=in | app=f:\program files\teamviewer\version8\teamviewer.exe |
"{9D11D8A1-0833-480A-A3D1-3F30F26E7D02}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider underworld\tru.exe |
"{9D15B6D0-58DC-44EC-944F-CEFF02F14FCE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9D1DD736-EE2A-4949-8A78-013B689D3FD2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\hexen deathkings of the dark citadel\base\dosbox.exe |
"{9F7B12D1-2C98-4104-BA2B-D0CAED813153}" = dir=in | app=f:\program files\hp\digital imaging\bin\hposid01.exe |
"{9FEBDE18-99A5-4607-A1C0-361BB55F37E2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\gamemaker_studio\gamemakerplayer.exe |
"{A1F619F0-44C9-429F-9F4F-4E8245885CA1}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\bastion\bastion.exe |
"{A22B5635-DF5C-4E29-B657-0A6CD5BBE898}" = protocol=6 | dir=in | app=e:\steamapps\common\killingfloor\system\kfed.exe |
"{A3BB5452-799F-47EA-A758-FD982495048D}" = protocol=6 | dir=in | app=f:\programdata\battle.net\agent\agent.1040\agent.exe |
"{A4C9EF9C-2ABE-49EE-B459-94560CFE3F68}" = protocol=17 | dir=in | app=e:\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{A672D4F4-7705-4ACA-83A9-1589682128EE}" = protocol=17 | dir=in | app=c:\program files\starcraft ii\starcraft ii public test.exe |
"{A6B8627E-9596-47B3-9851-591B9F8B08FF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{A86269D1-043F-4D04-B06E-476027BFD048}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\hexen 2\glh2.exe |
"{AB1F9AE1-6CFD-4E1F-9CCA-6F4F8EDCACF6}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{AD05304C-DA7C-4DA3-AB6E-4368DBFFAC29}" = protocol=6 | dir=in | app=c:\program files\starcraft ii\starcraft ii.exe |
"{B08922EE-3A78-40EF-B4D3-BBE69C67EF6D}" = protocol=6 | dir=in | app=f:\program files\bonjour\mdnsresponder.exe |
"{B0A7828D-183C-4690-A494-337F73AD41BE}" = protocol=17 | dir=in | app=e:\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{B2318643-ECFA-4E18-AE7E-637E0F8BA5CC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\half-life 2\hl2.exe |
"{B9CD47BF-C6C8-4AB1-BFA6-4910F554470A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tombraider (iii)\tomb3.exe |
"{BBCEF976-8C5F-4618-8E47-A60874DDD0AF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BCA332F5-6984-43ED-80C7-5A0345D8722D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider legend\trl.exe |
"{BD6E23AA-423A-4145-9FB8-8B67FFA6AD8B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\defcon\defcon.exe |
"{BE1EF463-5267-400D-8B99-C1AC095E0972}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\final doom\base\dosbox.exe |
"{BE3361E5-4DF5-4731-9FCA-B343D2D52942}" = protocol=6 | dir=in | app=e:\steamapps\common\combat arms\calauncher.exe |
"{C039925E-2D60-4BB0-B354-851F83C5FB84}" = protocol=17 | dir=in | app=e:\steamapps\common\microvolts\launcher.exe |
"{C07740A2-9C74-43A5-95AD-A6898841CF95}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (vi) the angel of darkness\launcher.exe |
"{C2AF424D-F5B5-40EF-A882-DE4920127E12}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{C4DC8E79-6B9A-4CA4-A725-79CEEE4A04AF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\vessel\vessel.exe |
"{C5E21B3E-8CCB-445A-ADAA-4C70E7BB93C7}" = protocol=6 | dir=in | app=f:\program files\teamviewer\version8\teamviewer_service.exe |
"{C68978C3-FDAB-486F-B6BB-8D8D9DDCAE26}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{C94C126A-B87F-48B7-B381-07B4E6324B9F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tombraider (iii)\tomb3.exe |
"{C961CC5A-6927-47DA-BD3F-3E60B8C59360}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (iv) the last revelation\tomb4.exe |
"{C9664453-AA42-4E0C-9C34-B914FB5E24C3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CB437F8A-DB7F-4A99-8779-1A965A915EB8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{CEDCFA8A-1EBF-42F6-9BC2-B332A9B796B1}" = dir=in | app=f:\program files\skype\phone\skype.exe |
"{CF15EA7A-AFC5-415A-A394-EB9569DD0D07}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
"{CF7E9A28-EB6C-4466-9358-2294BFA573AF}" = protocol=17 | dir=in | app=f:\programdata\battle.net\agent\agent.1737\agent.exe |
"{D2F2B3CE-0712-4EDD-A2E2-C1151A6D6EC2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\metro 2033\metro2033.exe |
"{D6A39AC1-2FBE-49FD-9C86-2F669B89BB64}" = protocol=6 | dir=in | app=c:\program files\starcraft ii\starcraft ii public test.exe |
"{D6F0AFA5-C992-4ABC-BF6E-441D57F51068}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{D7C13B00-F7F6-4E84-917A-45BF141150F7}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (iv) the last revelation\tomb4.exe |
"{D8231BE6-D7D4-448C-AE0F-AA8347BFCAFE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mirrors edge\support\ea help\electronic_arts_technical_support.htm |
"{D95BCFBE-C732-41FF-8226-E519F1E668D7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D9F72BC5-012E-4928-B23C-672FE9F9E384}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2 + mouse.bat |
"{DBDD06FA-9127-4BE0-B63E-7F7A36180B35}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider underworld\tru.exe |
"{DCB8046A-A5B4-4FCF-BC3E-6B587B463C62}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{DD97F3C4-4D42-4D7A-9419-E56D985D759B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\hexen\base\dosbox.exe |
"{DDF0AD06-4102-438F-8D41-D7A0D810209B}" = dir=in | app=f:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{DFCC6C91-6A10-44DC-96BB-439F3074FB54}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E16774D0-E979-4C2B-A636-01812850AC99}" = protocol=6 | dir=in | app=e:\steamapps\common\tomb raider (v) chronicles\pctomb5.exe |
"{E1CEB7D5-D501-4F4B-9170-F205E3EF022B}" = protocol=17 | dir=in | app=e:\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{E37A8A56-7541-4352-8EBD-959BB9A01D62}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{E4D9CBF8-71EA-40B8-AD7D-724AE2F1BE85}" = dir=in | app=f:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{E7DF2413-4FE6-4CF5-B144-BF999449B8C3}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\hunted\binaries\win32\hunted.exe |
"{E84427A1-4F7C-47FE-8D9F-EC23CCBE66DC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\bastion\bastion.exe |
"{E883BE0D-86DA-45F6-9F5A-CADC2048098D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 test\dota.exe |
"{E92C39CB-3FF3-496F-AAE2-4D0B63653125}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\sourcefilmmaker\game\sfm.exe |
"{EA176837-61B0-4E9B-9993-2C63A2D313E2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\doom 3\doom3.exe |
"{EA1A4511-5834-48DC-95FD-F4987D2CCC2A}" = protocol=17 | dir=in | app=e:\steamapps\common\skyrim\skyrimlauncher.exe |
"{EAE07F47-CAF0-4FA3-AD82-7423A07CC8D1}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{ED0C2324-DDF8-4E8E-829F-D0976AA8C95B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\gamemaker_studio\gamemakerplayer.exe |
"{EF8D187E-0A28-4660-A5B9-FF6BEAF837D8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{EFAC1AB7-8F6A-40D1-A06D-8D5222112470}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{EFD5DDAF-1D85-4B19-A981-C44970FAA132}" = protocol=6 | dir=in | app=e:\steamapps\common\bastion\bastion.exe |
"{F03C1D8A-B2BC-475C-9077-F321612F6C63}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2 + mouse.bat |
"{F1399224-3A4B-4C69-ACAF-62C3350B4DD7}" = protocol=6 | dir=in | app=f:\users\tyler\downloads\winbuilder.exe |
"{F2BFE71C-935D-4239-9FD2-582E44B6ED63}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\surgeon simulator 2013\ss2013.exe |
"{F3F0877F-471A-4EE9-8C0C-F79825972E9B}" = protocol=17 | dir=in | app=e:\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
"{F4FABB64-9E40-47D8-82D9-B2BDE5F1850A}" = protocol=6 | dir=in | app=e:\steamapps\common\sourcefilmmaker\game\bin\qsdklauncher.exe |
"{F556F50F-5B15-4C5F-9AC1-C64967D507D5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (vi) the angel of darkness\launcher.exe |
"{F55D85AC-12FA-41D8-8BE0-2202C3CA9F0E}" = dir=in | app=f:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{F753BE5E-E0E6-44B3-B315-11CCCBEA5242}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F7D9DB33-1CEC-4B40-82DE-7CC31CE9A2F7}" = protocol=17 | dir=in | app=e:\steamapps\common\krater\run_game.exe |
"{F817F81F-4C98-445F-89BC-29D17FD5A4A4}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider anniversary\tra.exe |
"{F94EDC02-1707-49AC-8900-14CC603B2C5F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tomb raider (i)\dosbox.exe |
"{FCE59832-A92C-4BD2-9B31-65D1B321C519}" = protocol=6 | dir=in | app=f:\programdata\battle.net\agent\agent.2045\agent.exe |
"{FE1B987C-F1E8-4784-8D60-EA388D4D5DC4}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\hexen 2\glh2.exe |
"{FE7F104C-4E85-476C-8D08-0DBACBF8D67A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\heretic shadow of the serpent riders\base\dosbox.exe |
"{FF435BFE-CC29-458A-A358-3D4925F1BA85}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{FF6B60F2-51B8-403F-855C-5FB96C482CB7}" = protocol=17 | dir=in | app=c:\program files\starcraft ii\starcraft ii.exe |
"{FFDAB423-CC3C-40F0-BFE9-B55299CEC2E7}" = protocol=17 | dir=in | app=e:\steamapps\common\killingfloor\system\kfed.exe |
"TCP Query User{0548AC40-2CF2-4EE2-B0FA-C73F19F1DEB7}C:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe" = protocol=6 | dir=in | app=c:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe |
"TCP Query User{077A3DFB-7B1C-4E5B-8E15-108C3235F0DD}F:\users\tyler\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=f:\users\tyler\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{08D911A2-CB42-4344-AEB4-B291E606A9D7}C:\program files\electronic arts\red alert 3\data\ra3_1.12.game" = protocol=6 | dir=in | app=c:\program files\electronic arts\red alert 3\data\ra3_1.12.game |
"TCP Query User{21E9B636-F99C-4C8D-A202-0FF4A4A7DCB0}D:\doom\skulltag\idese.exe" = protocol=6 | dir=in | app=d:\doom\skulltag\idese.exe |
"TCP Query User{53571908-EAC6-449B-840C-F61E0BCFEFF2}F:\program files\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=f:\program files\java\jre7\bin\java.exe |
"TCP Query User{67D10372-73D2-42AC-A2B0-BE3BE9DD7A15}C:\program files\starcraft ii\versions\base24944\sc2.exe" = protocol=6 | dir=in | app=c:\program files\starcraft ii\versions\base24944\sc2.exe |
"TCP Query User{6A622D81-9358-4F99-B740-6058E215EDB7}C:\program files\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=c:\program files\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"TCP Query User{6D357F56-E2EA-496F-AC85-F2874B232BCE}C:\program files\electronic arts\red alert 3\data\ra3_1.12.game" = protocol=6 | dir=in | app=c:\program files\electronic arts\red alert 3\data\ra3_1.12.game |
"TCP Query User{85E57CEC-8847-43BC-8B28-DC9C0C97E974}F:\program files\westwood\c&c95\c&c95.exe" = protocol=6 | dir=in | app=f:\program files\westwood\c&c95\c&c95.exe |
"TCP Query User{8612394D-1C53-4986-B35A-45912C4AA457}F:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=f:\program files\mirc\mirc.exe |
"TCP Query User{8D9917AD-F39D-4960-A17B-B25B1B52AAB1}F:\program files\ea games\command & conquer the first decade\command & conquer™ generals zero hour\generals.exe" = protocol=6 | dir=in | app=f:\program files\ea games\command & conquer the first decade\command & conquer™ generals zero hour\generals.exe |
"TCP Query User{92ABA103-58EA-4031-9E8B-AB7EB82E7F82}C:\program files\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe |
"TCP Query User{95EC9648-CB19-49F8-9D1E-FFFFFE68161A}F:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=f:\program files\mirc\mirc.exe |
"TCP Query User{A19AEA16-C2FA-4269-A96A-C90FDA213B8F}D:\doom\ide\ide.exe" = protocol=6 | dir=in | app=d:\doom\ide\ide.exe |
"TCP Query User{B00424D2-1085-47F7-A08F-C2EE73137DF2}D:\doom\zandronum alpha\zandronum.exe" = protocol=6 | dir=in | app=d:\doom\zandronum alpha\zandronum.exe |
"TCP Query User{B05F73DE-259E-4534-9164-02FBDAD4E82D}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{B0AE97F0-7385-4382-A38E-10EE8215083A}F:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe" = protocol=6 | dir=in | app=f:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe |
"TCP Query User{B5E0009F-323E-4A60-B182-9ACD889818D8}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{C1456772-ECE1-4811-AFC4-621425EB27CE}D:\doom\skulltag\skulltag.exe" = protocol=6 | dir=in | app=d:\doom\skulltag\skulltag.exe |
"TCP Query User{C2C180FF-9343-4A7C-BF33-9740D01F2350}C:\program files\steam\steamapps\common\krater\krater.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\krater\krater.exe |
"TCP Query User{C2C30AE8-3F40-4C37-ACA5-A8A97ACD30CE}D:\doom\skulltag\rcon_utility.exe" = protocol=6 | dir=in | app=d:\doom\skulltag\rcon_utility.exe |
"TCP Query User{E6DC9758-DE8F-4A49-9C2F-81611E4CD919}C:\program files\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire\xfire.exe |
"UDP Query User{0EC75D19-8E03-4187-9604-99D575C396A5}C:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe" = protocol=17 | dir=in | app=c:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe |
"UDP Query User{177F74A5-8B43-4FE4-9D01-BA1E155FC377}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{181B9B70-523F-4201-B42C-A922233477D0}D:\doom\skulltag\skulltag.exe" = protocol=17 | dir=in | app=d:\doom\skulltag\skulltag.exe |
"UDP Query User{248421BF-1037-42D1-9361-5454212F1114}F:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=f:\program files\mirc\mirc.exe |
"UDP Query User{2621C35A-66AA-4418-BCB8-D487FBE4E1CE}C:\program files\electronic arts\red alert 3\data\ra3_1.12.game" = protocol=17 | dir=in | app=c:\program files\electronic arts\red alert 3\data\ra3_1.12.game |
"UDP Query User{2E77B2E1-0B2D-4D63-8552-52864B9569A2}F:\program files\westwood\c&c95\c&c95.exe" = protocol=17 | dir=in | app=f:\program files\westwood\c&c95\c&c95.exe |
"UDP Query User{3DCA2543-AE3B-4CD1-A48B-27A1D4FEF796}C:\program files\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe |
"UDP Query User{3FFD1C02-FC65-4478-8484-77058C719B17}C:\program files\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire\xfire.exe |
"UDP Query User{4D21ADC4-7210-445D-A44A-35E05586C70F}C:\program files\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=c:\program files\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"UDP Query User{59898C36-2E43-4D23-895B-FA3DF3DADB94}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{5A3CAA52-616A-455D-A27A-A4534F9CFDB9}F:\users\tyler\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=f:\users\tyler\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{65C5D02E-32B5-49D6-85B4-35BFD60E8A0E}F:\program files\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=f:\program files\java\jre7\bin\java.exe |
"UDP Query User{65D24161-390A-46A0-A4F4-BF594E77C29A}D:\doom\zandronum alpha\zandronum.exe" = protocol=17 | dir=in | app=d:\doom\zandronum alpha\zandronum.exe |
"UDP Query User{6E1619AE-C02F-4325-8EDB-DA8F3039A8DD}F:\program files\ea games\command & conquer the first decade\command & conquer™ generals zero hour\generals.exe" = protocol=17 | dir=in | app=f:\program files\ea games\command & conquer the first decade\command & conquer™ generals zero hour\generals.exe |
"UDP Query User{760BB6FC-0566-46C2-B276-39D945C8B577}F:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=f:\program files\mirc\mirc.exe |
"UDP Query User{94EA4D0A-C388-48EB-A222-E057B0AB1DB2}D:\doom\ide\ide.exe" = protocol=17 | dir=in | app=d:\doom\ide\ide.exe |
"UDP Query User{96426983-7313-4B23-A50C-F18E3CE9FF6F}D:\doom\skulltag\idese.exe" = protocol=17 | dir=in | app=d:\doom\skulltag\idese.exe |
"UDP Query User{96A147E3-EB34-42B3-BBEA-13D13100605E}D:\doom\skulltag\rcon_utility.exe" = protocol=17 | dir=in | app=d:\doom\skulltag\rcon_utility.exe |
"UDP Query User{A342C8B2-3AA4-4A28-9D44-93052A26BDD7}C:\program files\electronic arts\red alert 3\data\ra3_1.12.game" = protocol=17 | dir=in | app=c:\program files\electronic arts\red alert 3\data\ra3_1.12.game |
"UDP Query User{ADB4C2BE-0228-4AFE-8AE8-F6FB34B5F6E8}F:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe" = protocol=17 | dir=in | app=f:\program files\ea games\command & conquer the first decade\command & conquer red alert™ ii\ra2\game.exe |
"UDP Query User{D65FE3EC-92AA-452B-A2BB-EBF8B3392114}C:\program files\steam\steamapps\common\krater\krater.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\krater\krater.exe |
"UDP Query User{DDD849FA-C112-4978-AC83-304519DC6694}C:\program files\starcraft ii\versions\base24944\sc2.exe" = protocol=17 | dir=in | app=c:\program files\starcraft ii\versions\base24944\sc2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00EC8ABC-3C5A-40F8-A8CB-E7DCD5ABFA05}" = Microsoft NuGet - Visual Studio 2012
"{04587046-E062-A70D-10C0-108318D5AD2C}" = ccc-utility
"{046806D1-0A38-3FCA-AF84-F71C50A0C363}" = Microsoft Visual Studio Premium 2012
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07070EAB-9349-4F6C-AC13-AEFE436F9775}" = D-link AirPlus G DWL-G120 Wireless USB Adapter
"{079A4EB2-9A74-7B86-12C2-00B52E395801}" = CCC Help Danish
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{097CDB1E-07C9-40F1-9972-F0F9F3A287E4}" = Network
"{0A1A1D48-DB23-443A-BC7B-49255D138020}" = Entity Framework Designer for Visual Studio 2012 - enu
"{0A5B39D2-7ED6-4779-BCC9-37F381139DB3}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0BCC836F-0B28-4090-B58A-64883BAA3B2F}" = WCF Data Services 5.0 (for OData v3) Primary Components
"{100C8F3B-82D6-4B14-BB7A-5E8C3FF810C8}_is1" = Driver Fusion
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{112DDD07-E419-2498-1E9E-2157F82AF5AA}" = CCC Help Turkish
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{12A00DC2-1226-D9F2-13DA-F974111D439E}" = Catalyst Control Center
"{148878BD-A2A5-4CF1-A103-2BA632F41953}" = WCF Data Services Tools for Microsoft Visual Studio 2012
"{1690CE56-2231-4E59-9006-A0876D949EA8}" = Tools for .Net 3.5
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}" = Microsoft Silverlight 4 SDK
"{1948E039-EC79-4591-951D-9867A8C14C90}" = Microsoft .NET Framework 4.5 SDK
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1B9BBB23-65CB-3AEE-BFC6-633E7CA299FD}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - ENU
"{1C163D33-33B3-33EB-A617-0D4D852BE8E1}" = Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727
"{1DB43E5A-2F24-4F51-92B0-A2C0EBF5C742}" = Microsoft Report Viewer Add-On for Visual Studio 2012
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F4DF099-EA5C-482D-9901-C0A8B539B417}" = Microsoft Web Platform Installer 4.0
"{1F8E06E2-BA93-40DC-B183-E024CBD853A8}" = Microsoft Visual C++ 2012 Compilers
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{203E564A-51E6-44E5-9DF9-8D0AD66E401D}" = DJ_SF_05_D2600_Software_Min
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{224828D6-DCA7-FDF3-3B85-085298AEC919}" = Catalyst Control Center InstallProxy
"{23176E97-26CB-C72A-19EB-BFB21AC1D15A}" = Windows Software Development Kit DirectX x86 Remote
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2993B157-97AE-7981-F29A-E6575F991CDB}" = CCC Help Swedish
"{29F259D7-C517-3EED-84B4-237573CFD39C}" = Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries
"{2A01368B-231F-3FF9-9CCB-03A99223E1CC}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2B8D2B28-5F76-4455-B97C-2BD82C2C2B9C}" = Visual Studio Extensions for Windows Library for JavaScript
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2C0CC01A-DDBC-3AED-AF18-E741242FD727}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer enu Resources
"{2C76E3DA-BA76-4FAD-B1B1-72B46D639028}" = PreEmptive Analytics Visual Studio Components
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2F6CE32A-018D-4656-895B-9E5E20D7740A}" = Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{330E5D98-20D2-4CA4-AE51-FCB8AA80F634}" = Microsoft Visual Studio 2012 Devenv
"{347966F8-E71A-E1A5-95E4-3A1C215383F6}" = CCC Help Chinese Traditional
"{372D17F6-A54E-4A01-B264-1314890FFE61}" = Dotfuscator and Analytics Community Edition
"{38A1E3ED-D913-41D2-9953-A93D5ACE3ADF}" = TL-WN721N/TL-WN722N Driver
"{38FC6E9A-F719-431A-A83D-4C86D5FD6555}" = Microsoft Visual Studio 2012 Shell (Minimum) Resources
"{3A523AF9-D32F-4C85-8388-0335731F3405}" = WCF RIA Services V1.0 SP2
"{3B3D81AB-51E2-695F-7E57-1CC30049F2A3}" = CCC Help French
"{3DC873BB-FFE3-46BF-9701-26B9AE371F9F}" = RealDownloader
"{3DFE302B-20AE-324B-8E92-BC7F0F036191}" = Microsoft Visual Studio Team Foundation Server 2012 Storyboarding
"{42F61556-29ED-8122-F39E-6F04EA5FF279}" = Windows Software Development Kit for Windows Store Apps DirectX x86 Remote
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45A8F8FF-ED9B-40B2-B923-94F46FCF6135}" = Microsoft SQL Server 2012 Command Line Utilities
"{462C2036-3055-4369-D30B-8DA032331EAB}" = CCC Help Greek
"{46561F4C-8C4B-3B79-81FA-074CD2E14584}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU
"{4A5667B2-5D13-46C2-85B5-9D46A6096F61}" = Secure Download Manager
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6
"{51054867-140B-8FBF-73A8-75386276BD98}" = CCC Help Spanish
"{532DBCC8-9468-435C-AEF6-30B7F50735A2}" = Blend for Visual Studio 2012 ENU resources
"{55BD05F4-6AF3-378F-9BC4-73F16FA5F823}" = Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - ENU
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{57D782D7-49FD-48DE-AB47-A690A1519A2D}" = Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools
"{57F20F04-014D-453F-B6A3-AE9485C4DFAB}" = Blend for Visual Studio 2012
"{586A5957-F21B-C8AD-F5C2-11D4D7DA5340}" = CCC Help German
"{59D87F40-6C4B-4F80-A42B-FAA0E6EAFAB6}" = Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools
"{59E4543A-D49D-4489-B445-473D763C79AF}" = Microsoft Games for Windows - LIVE Redistributable
"{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}" = Microsoft .NET Framework 4.5 Multi-Targeting Pack
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{60D5EF2A-4E0C-2C30-38F6-59C26E134F4A}" = Windows Software Development Kit
"{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}" = Microsoft ASP.NET Web Pages
"{633414E3-AA2A-CD04-5976-E91F5F871396}" = CCC Help Japanese
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{66D6F3BD-CA23-41A4-9FA3-96B26B32528C}" = Command & Conquer The First Decade
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{689425C0-2E3B-47C3-84BA-FA06732F2EB3}" = Microsoft Visual Studio 2012 Performance Collection Tools
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6D6D43E5-218C-4B05-92D3-2240810F4760}" = Microsoft SQL Server 2012 T-SQL Language Service
"{6DAB46E3-D017-3E2B-85D8-F57A230384C0}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer
"{6F066545-40A2-4C38-A8F7-78581CC5C442}" = Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools
"{6FC3B79F-47C6-38AF-B9A9-67DE3C639598}" = Microsoft Visual Studio Premium 2012 - ENU
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{731C183B-86A0-3442-BE55-68A7C92581E9}" = Microsoft Visual C++ 2012 Extended Libraries
"{7437A4B9-314F-3B8F-827B-22909146E471}" = Microsoft LightSwitch for Visual Studio 2012 Core
"{773AC1E4-5F27-4DF6-A932-7FDDE35C069D}" = Microsoft SQL Server Compact 4.0 SP1 ENU
"{775290AD-C54E-418C-9564-A10836F42C1C}" = D2600
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{790E9425-8570-493F-9AE7-81AFC9E46930}" = Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00)
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79B49428-E9B0-4479-A0FA-3EFF8AFA9F07}" = Microsoft SQL Server 2012 Transact-SQL Compiler Service
"{7D5CE450-30A2-35F6-A5B4-53847D2E3175}" = Microsoft Visual Studio 2010 Office Developer Tools (x86)
"{7de84939-616c-4ce3-ab2a-d704b8d2dd20}" = Visual Studio Extensions for Windows Library for JavaScript 1.0.9200.20512
"{7DECB2A6-C226-6042-9C2B-83316950D30E}" = Pandora
"{800F484E-9D69-492D-B656-7BAA32586142}" = Microsoft Visual Studio 2012 Shell (Minimum)
"{80D3CFFD-4CB5-47A1-8779-11A720A9ADB2}" = HP Deskjet D2600 Printer Driver Software 13.0 Rel .5
"{812FF572-F216-EBA0-123E-636C1B6EBC5B}" = CCC Help Korean
"{820C677A-41B2-48C3-8136-FEE35A052E73}" = Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C7F964-AC58-4104-B613-B4D0F61DA8CD}" = Microsoft SQL Server 2012 Native Client
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{85BB7CA7-6B0D-0B27-F4FF-B3D04282B3D1}" = CCC Help Russian
"{883CCFC7-CA6B-5531-704B-F9A64546B309}" = CCC Help Thai
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
"{8BDD3EC9-27E9-E490-7607-AF97FA678046}" = CCC Help Italian
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{9169C939-ED01-446A-BD0C-29873BAF4E48}" = Prerequisites for SSDT
"{925F1DB6-E86E-4378-9091-D1F68B0583C9}" = iCloud
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{93489CA8-6656-33A0-A5AC-E0EDEDB17C3E}" = Microsoft Visual Studio Professional 2012
"{93A92E3A-46D2-443A-9451-3201F936F246}" = Microsoft Visual Studio 2012 Performance Collection Tools - ENU
"{942CC691-5B98-42A3-8BC5-A246BA69D983}" = Microsoft ASP.NET MVC 4 Runtime
"{949A8BA8-D75A-4D42-AEBD-EEDCAC408FA7}" = PS_AIO_07_C510_SW_Min
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B486871-27EB-49A5-8832-77176E63333C}" = iTunes
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DA5221E-15DE-5B0F-D7BE-CCC7305575DD}" = CCC Help Dutch
"{9F612429-4A00-3D44-88CF-146DA2EE1F92}" = Microsoft .NET Framework 4.5
"{A0FE0292-D3BE-3447-80F2-72E032A54875}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"{A1400F57-65CC-0C22-6461-948EA2837670}" = CCC Help Hungarian
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A3A6D5EA-B6B5-3C05-BDA8-EAB99C09CDDC}" = Microsoft Visual Studio 2012 SharePoint Developer Tools
"{A4366F69-CE22-4DB7-9C8C-46A5845AF997}" = Microsoft Visual C++ 2012 Compilers - ENU Resources
"{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}" = Microsoft SQL Server System CLR Types
"{A561BB5F-5A85-5D88-E520-0A4512D5E6C0}" = CCC Help Norwegian
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A8B72907-B3F5-4C18-2D2B-F5E786A520DF}" = CCC Help Polish
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AB661879-AB21-41C1-AC94-CB6AD30B8DFC}" = Multiplayer Monopoly Online Game
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AD17194D-3829-E59E-99A4-EC47097722CA}" = Windows App Certification Kit Native Components
"{AD1AEE2A-D9C0-3FAC-8D6B-B5E07B47257B}" = Microsoft Visual C++ 2012 Core Libraries
"{AD219F94-16F2-937F-076A-F22DAA8D0A0B}" = CCC Help Finnish
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B1465D1D-6427-4CA1-AE29-8B699209E663}" = Microsoft Visual Studio 2012 Devenv Resources
"{B2B5B39B-4E8C-AC78-7FF1-7055C338D243}" = Catalyst Control Center Graphics Previews Common
"{B3533B84-A8DF-4A7A-8E95-B15F08B26E96}" = Microsoft Visual Studio 2012 IntelliTrace Core x86
"{B5DA9D49-9BD8-0F2F-52FC-C7E66BC8D944}" = LocalESPCui for en-us
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7C6F142-1136-EDB0-C1C4-1F28A6639768}" = AMD Drag and Drop Transcoding
"{B8FFB7D6-6ABD-47C3-8BAD-86FF5D8F3EDC}" = IIS 8.0 Express
"{B96FCD4F-6EDD-4258-8A6D-0FCEA8445E3E}" = Microsoft Web Developer Tools - Visual Studio 2012
"{B9F35D86-242E-3FA4-B9F8-A982E0DF918D}" = Microsoft Visual Studio 2012 SharePoint Developer Tools ENU Language Pack
"{BAD0254F-9BDB-3D14-A5AC-9C0EF51F3D09}" = Microsoft Portable Library Multi-Targeting Pack Language Pack - enu
"{BB3A1518-D930-46AD-9306-CFBB1BAC03B7}" = Visual Studio Extensions for Windows Library for JavaScript
"{BDBE5D2A-AAB7-77BD-7A0E-5006665CE7C6}" = LocalESPC
"{C1363D80-05CF-454F-A5A1-E37AE7BD9621}" = Microsoft Visual Studio 2012 Preparation
"{C1BE4600-7D15-3D1E-8AA2-B3241DB1D063}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C4CAD994-6EA2-3121-8352-DA593150B322}" = Microsoft Portable Library Multi-Targeting Pack
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C81452EB-CBCF-B8EB-3124-48C5B3D506B0}" = Windows Runtime Intellisense Content - en-us
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CD920828-2B95-49A4-8BFD-1D34BCBF5A27}" = Microsoft SQL Server 2012 Transact-SQL ScriptDom
"{CDFBE82A-62CF-ACD5-5BDC-A776229D694A}" = AMD Media Foundation Decoders
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CE9B60E1-BC90-DADA-0935-02F51FB9228C}" = AMD Catalyst Install Manager
"{CEE1F4AA-FAAE-6574-8AE6-93727FD6C246}" = Windows App Certification Kit x86
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{CFFDC0EC-6924-3347-B047-13339EDBEC28}" = Microsoft Visual Studio Professional 2012 - ENU
"{D11F66FF-82B3-DDB8-1146-525370552BE1}" = Windows Software Development Kit for Windows Store Apps
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D69B5522-2170-962F-58E8-DDEFA6636DA9}" = AMD Accelerated Video Transcoding
"{D9DA2981-3298-4F1A-9192-F2CF5BD91145}" = Microsoft SQL Server 2012 Express LocalDB
"{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}" = Microsoft SQL Server 2012 Management Objects
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}" = Microsoft ASP.NET MVC 3
"{DD8ACFF8-098E-130C-2799-BCA4D41EBAB2}" = CCC Help Chinese Standard
"{ddf0bb95-e254-447e-8472-3470057d9c7e}" = Microsoft Visual Studio Premium 2012
"{DE123FE9-B7F6-A75A-920D-3937FB9F06E4}" = CCC Help Portuguese
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E1FBB3D4-ADB0-4949-B101-855DA061C735}" = Microsoft Silverlight 5 SDK
"{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}" = Microsoft System CLR Types for SQL Server 2012
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E43AC95E-66B0-4CEC-AADD-C9BFEF5A4C0A}" = Microsoft Web Deploy 3.0
"{E4ADE757-7FE9-322D-9CAE-C77D77A2D2BF}" = Microsoft LightSwitch for Visual Studio 2012 CoreRes - ENU
"{E4C33F5B-1B2F-466E-957E-B274F08151A0}" = Microsoft Web Deploy dbSqlPackage Provider - enu
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E78C63C9-9849-45FA-8315-2AE38A293E2E}_is1" = DoomRL version 0.9.9.7
"{E818AE7C-244B-4A50-9C86-C0E4A8B69159}" = Microsoft Visual Studio 2012 Tools for SQL Server Compact 4.0 SP1 ENU
"{EE253E80-C298-4A31-BB22-7280DC8C7177}" = CCC Help Czech
"{EEEA9020-FCB0-4E35-82B9-D0994EF267B0}" = HP Photosmart eStn C510 All-In-One Driver 14.0 Rel. 7
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F648F088-B270-CF18-6486-AF8B1FE6BC09}" = CCC Help English
"{FA804794-2CCB-4301-954F-2C2894698876}" = Microsoft SQL Server Data Tools - enu (11.1.20627.00)
"{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}" = Microsoft SQL Server 2012 Data-Tier App Framework
"{FBBC8076-BB21-4E06-9FA0-309AEF6E35EE}" = Microsoft ASP.NET Web Pages 2 Runtime
"{FD85D9C0-783A-77B7-8EF8-326EC6C154D1}" = Catalyst Control Center Localization All
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb" = IIS Express Application Compatibility Database for x86
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}" = Microsoft Help Viewer 2.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"com.pandora.desktop.E7C14276FFE9EEF0BC7DCE654C467D9A299EFD21.1" = Pandora
"FileZilla Client" = FileZilla Client 3.7.3
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"LibUSB-Win32_is1" = LibUSB-Win32-0.1.10.1
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Messenger Plus!" = Messenger Plus!
"Messenger Plus! for Skype" = Messenger Plus! for Skype
"Microsoft Help Viewer 2.0" = Microsoft Help Viewer 2.0
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"Mini Golf Master" = Mini Golf Master
"mIRC" = mIRC
"Mozilla Firefox 23.0.1 (x86 en-US)" = Mozilla Firefox 23.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"nGlide" = nGlide 1.01
"OpenAL" = OpenAL
"Pidgin" = Pidgin
"PuTTY_is1" = PuTTY version 0.63
"RealPlayer 16.0" = RealPlayer
"Secunia PSI" = Secunia PSI (3.0.0.7011)
"Shop for HP Supplies" = Shop for HP Supplies
"StarCraft II" = StarCraft II
"Steam App 107100" = Bastion
"Steam App 108500" = Vessel
"Steam App 109400" = MicroVolts
"Steam App 112100" = Avadon: The Black Fortress
"Steam App 1250" = Killing Floor
"Steam App 1260" = Killing Floor SDK
"Steam App 17410" = Mirror's Edge
"Steam App 17470" = Dead Space
"Steam App 1840" = Source Filmmaker
"Steam App 203730" = Q.U.B.E.
"Steam App 205790" = Dota 2 Test
"Steam App 212180" = Combat Arms
"Steam App 212680" = FTL: Faster Than Light
"Steam App 214850" = GameMaker: Studio
"Steam App 218210" = Vanguard: Saga of Heroes F2P
"Steam App 22350" = BRINK
"Steam App 22380" = Fallout: New Vegas
"Steam App 22450" = Hunted: The Demon's Forge
"Steam App 224960" = Tomb Raider I
"Steam App 224980" = Tomb Raider: The Last Revelation
"Steam App 225000" = Tomb Raider: Chronicles
"Steam App 225020" = Tomb Raider (VI): The Angel of Darkness
"Steam App 225300" = Tomb Raider II
"Steam App 225320" = Tomb Raider III: Adventures of Lara Croft
"Steam App 2280" = The Ultimate DOOM
"Steam App 2290" = Final DOOM
"Steam App 2300" = DOOM II: Hell on Earth
"Steam App 233720" = Surgeon Simulator 2013
"Steam App 2360" = HeXen: Beyond Heretic
"Steam App 2370" = HeXen: Deathkings of the Dark Citadel
"Steam App 2390" = Heretic: Shadow of the Serpent Riders
"Steam App 31410" = Zombie Driver
"Steam App 35110" = Just Cause 2 Demo
"Steam App 40800" = Super Meat Boy
"Steam App 42170" = Krater
"Steam App 42910" = Magicka
"Steam App 43110" = Metro 2033
"Steam App 570" = Dota 2
"Steam App 7000" = Tomb Raider: Legend
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8000" = Tomb Raider: Anniversary
"Steam App 8140" = Tomb Raider: Underworld
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 9050" = DOOM 3
"Steam App 9060" = HeXen II
"Steam App 9070" = DOOM 3: Resurrection of Evil
"Steam App 9160" = Master Levels for DOOM II
"Steam App 98800" = Dungeons of Dredmor
"SumatraPDF" = SumatraPDF
"TeamViewer 8" = TeamViewer 8
"The Weather Channel App" = The Weather Channel App
"UDK-5ef054a9-d9a8-4e9b-9442-dfb78619deb5" = My Game Long Name
"UDK-ee7b5574-2bf5-4145-9388-fe71badd7de5" = Unreal Development Kit: 2012-10
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.8
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"Wireshark" = Wireshark 1.8.10 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Juniper_Setup_Client" = Juniper Networks Setup Client
"Juniper_Term_Services" = Juniper Terminal Services Client
"ROTR ECA Beta 1.8" = ROTR ECA Beta 1.8
"ROTR Map Pack" = ROTR Map Pack

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/13/2013 3:25:19 AM | Computer Name = Tyler-PC | Source = Windows Search Service | ID = 3029
Description =

Error - 9/13/2013 3:25:19 AM | Computer Name = Tyler-PC | Source = Windows Search Service | ID = 3028
Description =

Error - 9/13/2013 3:25:19 AM | Computer Name = Tyler-PC | Source = Windows Search Service | ID = 3058
Description =

Error - 9/13/2013 3:25:19 AM | Computer Name = Tyler-PC | Source = Windows Search Service | ID = 7010
Description =

Error - 9/13/2013 3:25:58 AM | Computer Name = Tyler-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/13/2013 9:31:43 AM | Computer Name = Tyler-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/13/2013 9:34:29 AM | Computer Name = Tyler-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/13/2013 9:47:11 AM | Computer Name = Tyler-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/14/2013 3:13:27 PM | Computer Name = Tyler-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/14/2013 3:20:27 PM | Computer Name = Tyler-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2/15/2013 3:45:18 PM | Computer Name = Tyler-PC | Source = NetBT | ID = 4321
Description = The name "TYLER-PC :0" could not be registered on the interface
with IP address 192.168.1.79. The computer with the IP address 192.168.1.136 did
not allow the name to be claimed by this computer.

Error - 2/15/2013 3:45:18 PM | Computer Name = Tyler-PC | Source = NetBT | ID = 4321
Description = The name "TYLER-PC :20" could not be registered on the interface
with IP address 192.168.1.79. The computer with the IP address 192.168.1.136 did
not allow the name to be claimed by this computer.

Error - 2/17/2013 11:13:07 AM | Computer Name = Tyler-PC | Source = bowser | ID = 8003
Description =

Error - 2/17/2013 6:54:30 PM | Computer Name = Tyler-PC | Source = bowser | ID = 8003
Description =

Error - 2/21/2013 9:51:20 AM | Computer Name = Tyler-PC | Source = bowser | ID = 8003
Description =

Error - 2/28/2013 4:20:44 AM | Computer Name = Tyler-PC | Source = DCOM | ID = 10016
Description =

Error - 3/2/2013 1:32:25 PM | Computer Name = Tyler-PC | Source = bowser | ID = 8003
Description =

Error - 3/2/2013 2:30:51 PM | Computer Name = Tyler-PC | Source = bowser | ID = 8003
Description =

Error - 3/3/2013 5:34:13 PM | Computer Name = Tyler-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 3:20:23 PM on ?3/?3/?2013 was unexpected.

Error - 3/3/2013 5:35:17 PM | Computer Name = Tyler-PC | Source = DCOM | ID = 10016
Description =


< End of report >



hijackthis.txt

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:41:58 PM, on 9/14/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Safe mode

Running processes:
F:\Windows\Explorer.EXE
F:\Windows\system32\ctfmon.exe
F:\Windows\system32\DllHost.exe
F:\Users\Tyler\Desktop\OTL.exe
F:\Windows\notepad.exe
F:\Windows\system32\NOTEPAD.EXE
F:\Users\Tyler\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securedsearch2.lavasoft.com/index.p…420DC5223B69336
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - F:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - F:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [avgnt] "F:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [MessengerPlusForSkypeService] "F:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] F:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = F:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - F:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: f:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - F:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - F:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - F:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - F:\Windows\system32\atiesrxx.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - F:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - F:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - F:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - F:\Windows\system32\libusbd-nt.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - F:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - F:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - F:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - F:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Messenger Plus! Service (MsgPlusService) - Yuna Software - F:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - F:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Secunia PSI Agent - Secunia - F:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - F:\Program Files\Secunia\PSI\sua.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - F:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - F:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - F:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - F:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe

–
End of file - 6800 bytes




DDS.txt

.
DDS (Ver_11-03-05.01) - NTFSx86 MINIMAL
Run by [removed] at 17:43:28.82 on Sat 09/14/2013
Internet Explorer: 9.10.9200.16686 BrowserJavaVersion: 10.25.2
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3070.2404 [GMT -4:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
F:\Windows\system32\wininit.exe
F:\Windows\system32\lsm.exe
F:\Windows\system32\svchost.exe -k DcomLaunch
F:\Windows\system32\svchost.exe -k RPCSS
F:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
F:\Windows\system32\svchost.exe -k netsvcs
F:\Windows\system32\svchost.exe -k NetworkService
F:\Windows\Explorer.EXE
F:\Windows\system32\ctfmon.exe
F:\Windows\system32\DllHost.exe
F:\Users\Tyler\Desktop\OTL.exe
F:\Windows\System32\svchost.exe -k secsvcs
F:\Windows\notepad.exe
F:\Windows\system32\NOTEPAD.EXE
F:\Windows\system32\NOTEPAD.EXE
F:\Users\Tyler\Desktop\dds.scr
F:\Windows\system32\conhost.exe
F:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=F99C22CBFA0C1F08C420DC5223B69336
uInternet Settings,ProxyOverride = *.local
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - f:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - f:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - f:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - f:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - f:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - f:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
mRun: [Computer Alarm Clock]
mRun: []
mRun: [avgnt] "f:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [MessengerPlusForSkypeService] "f:\program files\yuna software\messenger plus! for skype\MsgPlusForSkypeService.exe"
StartupFolder: f:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - f:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: f:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - f:\program files\mcafee security scan\3.0.207\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - f:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - f:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - f:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - f:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - f:\users\tyler\appdata\roaming\mozilla\firefox\profiles\btgsoxuh.default\
FF - plugin: f:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: f:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: f:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: f:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: f:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll
FF - plugin: f:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll
FF - plugin: f:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll
FF - plugin: f:\programdata\realnetworks\realdownloader\browserplugins\npdlplugin.dll
FF - plugin: f:\windows\system32\macromed\flash\NPSWF32_11_8_800_168.dll
FF - plugin: f:\windows\system32\npDeployJava1.dll
FF - plugin: f:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 gfibto;gfibto;f:\windows\system32\drivers\gfibto.sys [2013-9-1 13560]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;f:\windows\system32\drivers\libusb0.sys [2012-12-25 33792]
S1 avkmgr;avkmgr;f:\windows\system32\drivers\avkmgr.sys [2013-7-29 37352]
S1 vwififlt;Virtual WiFi Filter Driver;f:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
S2 AdobeARMservice;Adobe Acrobat Update Service;f:\program files\common files\adobe\arm\1.0\armsvc.exe [2013-5-11 65640]
S2 AMD External Events Utility;AMD External Events Utility;f:\windows\system32\atiesrxx.exe [2012-6-11 217600]
S2 AntiVirSchedulerService;Avira Scheduler;f:\program files\avira\antivir desktop\sched.exe [2013-7-29 84024]
S2 AntiVirService;Avira Real-Time Protection;f:\program files\avira\antivir desktop\avguard.exe [2013-7-29 108088]
S2 avgntflt;avgntflt;f:\windows\system32\drivers\avgntflt.sys [2013-7-29 88840]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;f:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2012-7-9 104912]
S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?]
S2 MBAMScheduler;MBAMScheduler;f:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-9-7 418376]
S2 MBAMService;MBAMService;f:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-9-7 701512]
S2 MsgPlusService;Messenger Plus! Service;f:\program files\yuna software\messenger plus! for skype\MsgPlusForSkypeService.exe [2013-1-26 128000]
S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;f:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2013-4-16 39056]
S2 Secunia PSI Agent;Secunia PSI Agent;f:\program files\secunia\psi\psia.exe [2013-7-3 1228504]
S2 Secunia Update Agent;Secunia Update Agent;f:\program files\secunia\psi\sua.exe [2013-7-3 660184]
S2 Skype C2C Service;Skype C2C Service;f:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2013-8-14 3291008]
S2 SkypeUpdate;Skype Updater;f:\program files\skype\updater\Updater.exe [2013-6-21 162408]
S2 TeamViewer7;TeamViewer 7;c:\program files\teamviewer\version7\TeamViewer_Service.exe [2012-7-16 2673064]
S2 TeamViewer8;TeamViewer 8;f:\program files\teamviewer\version8\TeamViewer_Service.exe [2012-12-10 5071712]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;f:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-7-20 257416]
S3 amdkmdag;amdkmdag;f:\windows\system32\drivers\atikmdag.sys [2012-6-11 8733696]
S3 amdkmdap;amdkmdap;f:\windows\system32\drivers\atikmpag.sys [2012-6-11 295936]
S3 athur;Wireless Network Adapter Service;f:\windows\system32\drivers\athur.sys [2012-12-22 1445888]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;f:\windows\system32\drivers\AtihdW73.sys [2012-2-23 86544]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;f:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;f:\windows\system32\drivers\dmvsc.sys [2011-4-11 62464]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service;f:\program files\windows kits\8.0\app certification kit\fussvc.exe [2012-7-25 133632]
S3 mbamchameleon;mbamchameleon;f:\windows\system32\drivers\mbamchameleon.sys [2013-9-13 31560]
S3 MBAMProtector;MBAMProtector;f:\windows\system32\drivers\mbam.sys [2013-9-7 22856]
S3 McComponentHostService;McAfee Security Scan Component Host Service;f:\program files\mcafee security scan\3.0.207\McCHSvc.exe [2011-6-17 237008]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;f:\windows\system32\drivers\MijXfilt.sys [2012-12-25 95304]
S3 MozillaMaintenance;Mozilla Maintenance Service;f:\program files\mozilla maintenance service\maintenanceservice.exe [2013-9-14 117656]
S3 PSI;PSI;f:\windows\system32\drivers\psi_mf_x86.sys [2013-7-3 16024]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;f:\windows\system32\drivers\rdpvideominiport.sys [2013-5-24 14848]
S3 RTL8167;Realtek 8167 NT Driver;f:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S3 StorSvc;Storage Service;f:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 Te.Service;Te.Service;f:\program files\windows kits\8.0\testing\runtimes\taef\Wex.Services.exe [2012-7-25 94208]
S3 TsUsbFlt;TsUsbFlt;f:\windows\system32\drivers\TsUsbFlt.sys [2013-5-24 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device;f:\windows\system32\drivers\TsUsbGD.sys [2013-5-24 27136]
S3 VSPerfDrv110;Performance Tools Driver 11.0;f:\program files\microsoft visual studio 11.0\team tools\performance tools\VSPerfDrv110.sys [2012-7-13 55416]
S3 WatAdminSvc;Windows Activation Technologies Service;f:\windows\system32\wat\WatAdminSvc.exe [2012-7-21 1343400]
S3 WinRing0_1_2_0;WinRing0_1_2_0;f:\program files\realtemp\WinRing0.sys [2008-7-26 14416]
S3 WSDPrintDevice;WSD Print Support via UMB;f:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920]
S4 AntiVirWebService;Avira Web Protection;f:\program files\avira\antivir desktop\avwebgrd.exe [2013-7-29 815160]
.
=============== Created Last 30 ================
.
2013-09-14 18:50:54 ——– d—–w- f:\users\tyler\appdata\local\Mozilla
2013-09-14 18:50:42 ——– d—–w- f:\program files\Mozilla Maintenance Service
2013-09-14 17:11:20 ——– d—–w- f:\users\tyler\appdata\roaming\com.pandora.desktop
2013-09-14 17:11:19 ——– d—–w- f:\users\tyler\appdata\roaming\com.pandora.desktop.E7C14276FFE9EEF0BC7DCE654C467D9A299EFD21.1
2013-09-14 17:11:15 ——– d—–w- f:\program files\Pandora
2013-09-13 12:34:07 105176 —-a-w- f:\windows\system32\drivers\48230029.sys
2013-09-13 12:26:43 31560 —-a-w- f:\windows\system32\drivers\mbamchameleon.sys
2013-09-13 12:14:12 ——– d—–w- f:\progra~2\Malwarebytes' Anti-Malware (portable)
2013-09-13 07:56:19 7166848 —-a-w- f:\progra~2\microsoft\windows defender\definition updates\{8619fd27-a27e-4d50-b7ed-e1f2e5375b0c}\mpengine.dll
2013-09-13 07:11:53 ——– d—–w- f:\program files\Wireshark
2013-09-13 01:15:47 ——– d—–w- f:\windows\pss
2013-09-07 23:23:03 22856 —-a-w- f:\windows\system32\drivers\mbam.sys
2013-09-07 23:23:03 ——– d—–w- f:\program files\Malwarebytes' Anti-Malware
2013-09-07 08:54:50 7166848 —-a-w- f:\progra~2\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-09-05 17:35:41 ——– d—–w- f:\program files\CCleaner
2013-09-05 17:26:12 ——– d—–w- F:\AdwCleaner
2013-09-05 17:21:37 12872 —-a-w- f:\windows\system32\bootdelete.exe
2013-09-05 17:14:56 ——– d—–w- f:\progra~2\HitmanPro
2013-09-03 12:12:34 ——– d—–w- F:\TDSSKiller_Quarantine
2013-09-01 21:53:12 ——– d—–w- f:\users\tyler\appdata\roaming\LavasoftStatistics
2013-09-01 21:50:18 ——– d—–w- f:\progra~2\Downloaded Installations
2013-09-01 21:50:13 ——– d—–w- f:\users\tyler\appdata\local\adawarebp
2013-09-01 21:50:11 ——– d—–w- f:\progra~2\Ad-Aware Browsing Protection
2013-09-01 21:50:07 ——– d—–w- f:\program files\Toolbar Cleaner
2013-09-01 21:49:50 ——– d—–w- f:\program files\Lavasoft
2013-09-01 21:48:35 44424 —-a-w- f:\windows\system32\sbbd.exe
2013-09-01 21:48:35 13560 —-a-w- f:\windows\system32\drivers\gfibto.sys
2013-09-01 21:32:40 ——– d—–w- f:\progra~2\Spybot - Search & Destroy
2013-09-01 20:26:32 ——– d—–w- f:\users\tyler\appdata\roaming\Malwarebytes
2013-09-01 20:26:22 ——– d—–w- f:\progra~2\Malwarebytes
2013-08-23 12:10:37 94632 —-a-w- f:\windows\system32\WindowsAccessBridge.dll
2013-08-23 11:59:17 ——– d—–w- f:\program files\SumatraPDF
2013-08-23 11:52:59 ——– d—–w- f:\program files\Pidgin
2013-08-23 11:51:51 ——– d—–w- f:\program files\common files\PX Storage Engine
2013-08-23 11:50:25 ——– d—–w- f:\program files\VideoLAN
2013-08-23 11:39:55 ——– d—–w- f:\users\tyler\appdata\local\Secunia PSI
2013-08-23 11:39:42 ——– d—–w- f:\program files\Secunia
2013-08-20 22:11:24 ——– d—–w- f:\program files\iPod
2013-08-20 22:11:23 ——– d—–w- f:\program files\iTunes
2013-08-20 22:11:23 ——– d—–w- f:\progra~2\188F1432-103A-4ffb-80F1-36B633C5C9E1
.
==================== Find3M ====================
.
2013-09-14 05:39:06 71048 —-a-w- f:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-14 05:39:06 692616 —-a-w- f:\windows\system32\FlashPlayerApp.exe
2013-08-23 12:10:33 867240 —-a-w- f:\windows\system32\npDeployJava1.dll
2013-08-23 12:10:33 789416 —-a-w- f:\windows\system32\deployJava1.dll
2013-08-10 03:59:10 1767936 —-a-w- f:\windows\system32\wininet.dll
2013-08-10 03:58:09 2876928 —-a-w- f:\windows\system32\jscript9.dll
2013-08-10 03:58:06 61440 —-a-w- f:\windows\system32\iesetup.dll
2013-08-10 03:58:06 109056 —-a-w- f:\windows\system32\iesysprep.dll
2013-08-10 03:07:50 2706432 —-a-w- f:\windows\system32\mshtml.tlb
2013-08-10 02:17:19 71680 —-a-w- f:\windows\system32\RegisterIEPKEYs.exe
2013-08-08 01:03:07 2348544 —-a-w- f:\windows\system32\win32k.sys
2013-08-07 08:22:04 238872 ——w- f:\windows\system32\MpSigStub.exe
2013-08-02 01:50:36 169984 —-a-w- f:\windows\system32\winsrv.dll
2013-08-02 01:49:19 293376 —-a-w- f:\windows\system32\KernelBase.dll
2013-08-02 00:52:57 271360 —-a-w- f:\windows\system32\conhost.exe
2013-08-02 00:43:05 6144 —ha-w- f:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 —ha-w- f:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 —ha-w- f:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 —ha-w- f:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-07-25 08:57:27 1620992 —-a-w- f:\windows\system32\WMVDECOD.DLL
2013-07-19 01:41:01 2048 —-a-w- f:\windows\system32\tzres.dll
2013-07-09 05:03:34 3968960 —-a-w- f:\windows\system32\ntkrnlpa.exe
2013-07-09 05:03:34 3913664 —-a-w- f:\windows\system32\ntoskrnl.exe
2013-07-09 04:53:46 1289096 —-a-w- f:\windows\system32\ntdll.dll
2013-07-09 04:52:10 175104 —-a-w- f:\windows\system32\wintrust.dll
2013-07-09 04:50:42 652800 —-a-w- f:\windows\system32\rpcrt4.dll
2013-07-09 04:46:31 140288 —-a-w- f:\windows\system32\cryptsvc.dll
2013-07-09 04:46:31 1166848 —-a-w- f:\windows\system32\crypt32.dll
2013-07-09 04:46:31 103936 —-a-w- f:\windows\system32\cryptnet.dll
2013-07-04 16:39:19 70025 —-a-w- f:\windows\system32\nglide_uninst.exe
2013-06-20 11:41:09 499712 —-a-w- f:\windows\system32\msvcp71.dll
2013-06-20 11:41:09 348160 —-a-w- f:\windows\system32\msvcr71.dll
.
============= FINISH: 17:43:40.64 ===============
Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

[external image: Posted Image] AdwCleaner

Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
———-
Hello,

Okay. So, the only thing that has happened on my PC recently is that I have found out what caused firefox to crash all the time.

It had to do with my student e-mail using Office 365. The script crashes (a java script) and it does it constantly. And only when I'm logged in. So, I cannot even view my e-mail at all, which might not be malware related since I have tried it on my laptop as well as a random computer in the CS lab [each using firefox].

No symptoms of any adware on my computer since I posted this thread as well, which might seem as if it's clean, right? Well, we can only hope!

Anyway, here are the results:



# AdwCleaner v3.004 - Report created 18/09/2013 at 11:21:04
# Updated 15/09/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : Tyler - TYLER-PC
# Running from : F:\Users\Tyler\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16686


-\\ Mozilla Firefox v23.0.1 (en-US)

[ File : F:\Users\Tyler\AppData\Roaming\Mozilla\Firefox\Profiles\btgsoxuh.default\prefs.js ]


[ File : F:\Users\Work Station\AppData\Roaming\Mozilla\Firefox\Profiles\adfupymm.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [2428 octets] - [05/09/2013 13:26:15]
AdwCleaner[R1].txt - [800 octets] - [18/09/2013 11:21:04]
AdwCleaner[S0].txt - [2529 octets] - [05/09/2013 13:27:55]

########## EOF - F:\AdwCleaner\AdwCleaner[R1].txt - [919 octets] ##########



It appears that there's nothing from these results which suggest that anything is remotely wrong with my machine. But, for AdwCleaner, I found some quarantined files from a previous AdwCleaner run from 9 days ago. Do you think this could have been it?

The very fact that AdwCleaner found almost zero files for review reminded me that I actually ran CCleaner several times last week. It could be possible that I [albeit unintentionally] removed the malware already, and then removed all of the extraneous scripts that may have been left behind somehow. But that is just a theory.

ALSO: So, I booted my computer back up (to get out of safe mode) to post this in the thread here, but that RealPlayer update box appeared again. I'm pretty sure it's legit, but I was completely paranoid before. I mean, seriously - I thought it was a really strange window. Of course, I did check RealPlayer and it does need to be updated, but yeah.

📎Reaplayer_update_box.png

📎Reaplayer_update_box_2.png

📎Reaplayer_update_box_3.png

📎TDSSKiller.2.8.16.0_18.09.2013_11.17.13_log.txt
Hi,

Yeah RealPlayer update is more than likely legit. :)

Let's do the following and see if anything else might pop up…

ComboFix

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
I am in safe mode now, writing this message in a text file. Well, it said Avira was running, but it was not - I checked twice and it said that Real-time Protection was not running and it asked me to enable it (to which I hit cancel), and, for the third time, I checked Windows Task Manager and no Avira processes showed up. Yet it still thought they were on. The icon for it was not on the system tray either, so yeah. I went on to running ComboFix, so let's see what happens. Okay, here is the log: ComboFix 13-09-17.01 - Tyler 09/18/2013 15:21:07.1.2 - x86 MINIMAL Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3070.2581 [GMT -4:00] Running from: f:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . f:\program files\Pandora\Pandora.exe f:\users\Tyler\AppData\Roaming\mIRC\logs\status.log f:\windows\wininit.ini . . ((((((((((((((((((((((((( Files Created from 2013-08-18 to 2013-09-18 ))))))))))))))))))))))))))))))) . . 2013-09-18 19:26 . 2013-09-18 19:26 ——– d—–w- f:\users\Tyler\AppData\Local\temp 2013-09-17 11:48 . 2013-09-05 05:02 7328304 —-a-w- f:\programdata\Microsoft\Windows Defender\Definition Updates\{47EF911E-3523-41D3-BE4E-C03C3D54E5DD}\mpengine.dll 2013-09-14 18:50 . 2013-09-14 18:50 ——– d—–w- f:\users\Tyler\AppData\Local\Mozilla 2013-09-14 18:50 . 2013-09-14 18:50 ——– d—–w- f:\program files\Mozilla Maintenance Service 2013-09-14 17:11 . 2013-09-14 17:11 ——– d—–w- f:\users\Tyler\AppData\Roaming\com.pandora.desktop 2013-09-14 17:11 . 2013-09-18 19:26 ——– d—–w- f:\program files\Pandora 2013-09-14 17:10 . 2013-09-14 17:10 ——– d—–w- f:\program files\Common Files\Adobe AIR 2013-09-13 12:34 . 2013-09-13 13:44 105176 —-a-w- f:\windows\system32\drivers\48230029.sys 2013-09-13 12:26 . 2013-09-13 12:26 31560 —-a-w- f:\windows\system32\drivers\mbamchameleon.sys 2013-09-13 12:14 . 2013-09-13 13:56 ——– d—–w- f:\programdata\Malwarebytes' Anti-Malware (portable) 2013-09-13 07:11 . 2013-09-13 07:12 ——– d—–w- f:\program files\Wireshark 2013-09-13 00:30 . 2013-09-13 00:30 ——– d—–w- f:\program files\FileZilla FTP Client 2013-09-07 23:23 . 2013-09-07 23:23 ——– d—–w- f:\program files\Malwarebytes' Anti-Malware 2013-09-07 23:23 . 2013-04-04 18:50 22856 —-a-w- f:\windows\system32\drivers\mbam.sys 2013-09-05 17:35 . 2013-09-05 17:35 ——– d—–w- f:\program files\CCleaner 2013-09-05 17:26 . 2013-09-18 15:21 ——– d—–w- F:\AdwCleaner 2013-09-05 17:21 . 2013-09-05 17:21 12872 —-a-w- f:\windows\system32\bootdelete.exe 2013-09-05 17:14 . 2013-09-05 17:22 ——– d—–w- f:\programdata\HitmanPro 2013-09-03 12:12 . 2013-09-03 12:12 ——– d—–w- F:\TDSSKiller_Quarantine 2013-09-01 21:53 . 2013-09-01 21:53 ——– d—–w- f:\users\Tyler\AppData\Roaming\LavasoftStatistics 2013-09-01 21:50 . 2013-09-01 21:50 ——– d—–w- f:\programdata\Downloaded Installations 2013-09-01 21:50 . 2013-09-01 21:50 ——– d—–w- f:\users\Tyler\AppData\Local\adawarebp 2013-09-01 21:50 . 2013-09-01 21:50 ——– d—–w- f:\programdata\Ad-Aware Browsing Protection 2013-09-01 21:50 . 2013-09-01 21:50 ——– d—–w- f:\program files\Toolbar Cleaner 2013-09-01 21:49 . 2013-09-01 21:49 ——– d—–w- f:\program files\Lavasoft 2013-09-01 21:48 . 2013-09-01 21:48 44424 —-a-w- f:\windows\system32\sbbd.exe 2013-09-01 21:48 . 2013-09-01 21:48 13560 —-a-w- f:\windows\system32\drivers\gfibto.sys 2013-09-01 21:32 . 2013-09-04 10:46 ——– d—–w- f:\programdata\Spybot - Search & Destroy 2013-09-01 20:26 . 2013-09-01 20:26 ——– d—–w- f:\users\Tyler\AppData\Roaming\Malwarebytes 2013-09-01 20:26 . 2013-09-01 20:26 ——– d—–w- f:\programdata\Malwarebytes 2013-08-23 12:10 . 2013-08-23 12:10 94632 —-a-w- f:\windows\system32\WindowsAccessBridge.dll 2013-08-23 11:59 . 2013-08-23 11:59 ——– d—–w- f:\program files\SumatraPDF 2013-08-23 11:55 . 2013-08-23 11:55 ——– d—–w- f:\program files\Common Files\Adobe 2013-08-23 11:52 . 2013-08-23 11:53 ——– d—–w- f:\program files\Pidgin 2013-08-23 11:51 . 2013-08-23 11:51 ——– d—–w- f:\program files\Common Files\PX Storage Engine 2013-08-23 11:51 . 2013-09-05 17:38 ——– d—–w- f:\users\Tyler\AppData\Roaming\Winamp 2013-08-23 11:51 . 2013-08-23 11:52 ——– d—–w- f:\program files\Winamp 2013-08-23 11:50 . 2013-08-23 11:50 ——– d—–w- f:\program files\VideoLAN 2013-08-23 11:39 . 2013-08-23 11:39 ——– d—–w- f:\users\Tyler\AppData\Local\Secunia PSI 2013-08-23 11:39 . 2013-08-23 11:39 ——– d—–w- f:\program files\Secunia 2013-08-20 22:11 . 2013-08-20 22:11 ——– d—–w- f:\program files\iPod 2013-08-20 22:11 . 2013-08-20 22:12 ——– d—–w- f:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-08-20 22:11 . 2013-08-20 22:12 ——– d—–w- f:\program files\iTunes . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-14 05:39 . 2012-07-21 01:06 71048 —-a-w- f:\windows\system32\FlashPlayerCPLApp.cpl 2013-09-14 05:39 . 2012-07-21 01:06 692616 —-a-w- f:\windows\system32\FlashPlayerApp.exe 2013-09-04 11:15 . 2013-07-29 23:02 88840 —-a-w- f:\windows\system32\drivers\avgntflt.sys 2013-08-29 11:10 . 2013-07-29 23:05 66144 —-a-w- f:\windows\system32\drivers\avnetflt.sys 2013-08-29 11:10 . 2013-07-29 23:02 136672 —-a-w- f:\windows\system32\drivers\avipbb.sys 2013-08-23 12:10 . 2012-08-15 15:48 867240 —-a-w- f:\windows\system32\npDeployJava1.dll 2013-08-23 12:10 . 2012-08-15 15:48 789416 —-a-w- f:\windows\system32\deployJava1.dll 2013-08-07 08:22 . 2012-07-21 01:21 238872 ——w- f:\windows\system32\MpSigStub.exe 2013-07-29 22:54 . 2013-07-29 23:02 37352 —-a-w- f:\windows\system32\drivers\avkmgr.sys 2013-07-25 08:57 . 2013-08-15 01:18 1620992 —-a-w- f:\windows\system32\WMVDECOD.DLL 2013-07-19 01:41 . 2013-08-15 01:18 2048 —-a-w- f:\windows\system32\tzres.dll 2013-07-09 05:03 . 2013-08-15 01:18 3968960 —-a-w- f:\windows\system32\ntkrnlpa.exe 2013-07-09 05:03 . 2013-08-15 01:18 3913664 —-a-w- f:\windows\system32\ntoskrnl.exe 2013-07-09 04:53 . 2013-08-15 01:18 1289096 —-a-w- f:\windows\system32\ntdll.dll 2013-07-09 04:52 . 2013-08-15 01:18 175104 —-a-w- f:\windows\system32\wintrust.dll 2013-07-09 04:50 . 2013-08-15 01:18 652800 —-a-w- f:\windows\system32\rpcrt4.dll 2013-07-09 04:46 . 2013-08-15 01:18 140288 —-a-w- f:\windows\system32\cryptsvc.dll 2013-07-09 04:46 . 2013-08-15 01:18 1166848 —-a-w- f:\windows\system32\crypt32.dll 2013-07-09 04:46 . 2013-08-15 01:18 103936 —-a-w- f:\windows\system32\cryptnet.dll 2013-07-06 05:05 . 2013-08-15 01:18 1293760 —-a-w- f:\windows\system32\drivers\tcpip.sys 2013-07-04 16:39 . 2013-07-04 16:39 70025 —-a-w- f:\windows\system32\nglide_uninst.exe 2013-07-03 08:32 . 2013-07-03 08:32 16024 —-a-w- f:\windows\system32\drivers\psi_mf_x86.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-23 17:58 130736 —-a-w- f:\users\Tyler\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-23 17:58 130736 —-a-w- f:\users\Tyler\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-23 17:58 130736 —-a-w- f:\users\Tyler\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="f:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-29 347192] "MessengerPlusForSkypeService"="f:\program files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [2013-06-27 128000] . f:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - f:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] McAfee Security Scan Plus.lnk - f:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] @="" . [HKLM\~\startupfolder\F:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^D-link AirPlus G DWL-G120 Wireless USB.lnk] path=f:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\D-link AirPlus G DWL-G120 Wireless USB.lnk backup=f:\windows\pss\D-link AirPlus G DWL-G120 Wireless USB.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\F:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk] path=f:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk backup=f:\windows\pss\Secunia PSI Tray.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\F:^Users^Tyler^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk] path=f:\users\Tyler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk backup=f:\windows\pss\Dropbox.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\F:^Users^Tyler^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk] path=f:\users\Tyler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk backup=f:\windows\pss\MagicDisc.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\F:^Users^Tyler^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk] path=f:\users\Tyler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk backup=f:\windows\pss\OpenOffice.org 3.2.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT] start AMD Accelerated Video Transcoding device initialization [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection] 2013-07-15 21:09 554384 —-a-w- f:\programdata\Ad-Aware Browsing Protection\adawarebp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2013-05-11 10:37 958576 —-a-w- f:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2013-04-22 01:43 59720 —-a-w- f:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt] 2013-08-29 11:10 347192 —-a-w- f:\program files\Avira\AntiVir Desktop\avgnt.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2011-05-10 06:41 49208 —-a-w- f:\program files\HP\HP Software Update\hpwuschd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2013-08-16 13:07 152392 —-a-w- f:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlusForSkypeService] 2013-06-27 14:02 128000 —-a-w- f:\program files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlusService] 2013-01-23 21:02 802304 —-a-w- f:\program files\Yuna Software\Messenger Plus!\PlusService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2013-05-01 07:59 421888 —-a-w- f:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2012-06-11 22:00 641704 —-a-w- f:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2013-06-20 11:41 295512 —-a-w- f:\program files\Real\RealPlayer\Update\realsched.exe . R1 avkmgr;avkmgr;f:\windows\system32\DRIVERS\avkmgr.sys [2013-07-29 37352] R2 AMD External Events Utility;AMD External Events Utility;f:\windows\system32\atiesrxx.exe [2012-06-11 217600] R2 AntiVirSchedulerService;Avira Scheduler;f:\program files\Avira\AntiVir Desktop\sched.exe [2013-08-29 84024] R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;f:\windows\system32\libusbd-nt.exe [2005-03-10 18944] R2 MBAMScheduler;MBAMScheduler;f:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] R2 MBAMService;MBAMService;f:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] R2 MsgPlusService;Messenger Plus! Service;f:\program files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe [2013-06-27 128000] R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;f:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-04-16 39056] R2 Secunia PSI Agent;Secunia PSI Agent;f:\program files\Secunia\PSI\PSIA.exe [2013-07-03 1228504] R2 Secunia Update Agent;Secunia Update Agent;f:\program files\Secunia\PSI\sua.exe [2013-07-03 660184] R2 Skype C2C Service;Skype C2C Service;f:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-08-14 3291008] R2 SkypeUpdate;Skype Updater;f:\program files\Skype\Updater\Updater.exe [2013-06-21 162408] R2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [2012-07-16 2673064] R2 TeamViewer8;TeamViewer 8;f:\program files\TeamViewer\Version8\TeamViewer_Service.exe [2013-09-12 5071712] R3 athur;Wireless Network Adapter Service;f:\windows\system32\DRIVERS\athur.sys [2011-04-20 1445888] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;f:\windows\system32\drivers\AtihdW73.sys [2012-02-23 86544] R3 dmvsc;dmvsc;f:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 mbamchameleon;mbamchameleon;f:\windows\system32\drivers\mbamchameleon.sys [2013-09-13 31560] R3 MBAMProtector;MBAMProtector;f:\windows\system32\drivers\mbam.sys [2013-04-04 22856] R3 McComponentHostService;McAfee Security Scan Component Host Service;f:\program files\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008] R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;f:\windows\system32\DRIVERS\MijXfilt.sys [2011-11-10 95304] R3 PSI;PSI;f:\windows\system32\DRIVERS\psi_mf_x86.sys [2013-07-03 16024] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;f:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 RTL8167;Realtek 8167 NT Driver;f:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-02 139776] R3 Te.Service;Te.Service;f:\program files\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 94208] R3 TsUsbFlt;TsUsbFlt;f:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664] R3 TsUsbGD;Remote Desktop Generic USB Device;f:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136] R3 WatAdminSvc;Windows Activation Technologies Service;f:\windows\system32\Wat\WatAdminSvc.exe [2012-07-21 1343400] R3 WinRing0_1_2_0;WinRing0_1_2_0;f:\program files\RealTemp\WinRing0.sys [2013-06-30 14416] R4 AntiVirWebService;Avira Web Protection;f:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-08-29 815160] S0 gfibto;gfibto;f:\windows\system32\drivers\gfibto.sys [2013-09-01 13560] S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;f:\windows\system32\drivers\libusb0.sys [2005-03-10 33792] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HPService REG_MULTI_SZ HPSLPSVC . Contents of the 'Scheduled Tasks' folder . 2013-09-18 f:\windows\Tasks\Adobe Flash Player Updater.job - f:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-21 05:39] . 2013-09-18 f:\windows\Tasks\ReclaimerUpdateFiles_Tyler.job - f:\users\Tyler\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.60\agent\rnupgagent.exe [2013-09-10 17:07] . 2013-09-17 f:\windows\Tasks\ReclaimerUpdateXML_Tyler.job - f:\users\Tyler\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.60\agent\rnupgagent.exe [2013-09-10 17:07] . 2013-09-18 f:\windows\Tasks\RNUpgradeHelperLogonPrompt_Tyler.job - f:\users\Tyler\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.60\agent\rnupgagent.exe [2013-09-10 17:07] . . ——- Supplementary Scan ——- . uStart Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=F99C22CBFA0C1F08C420DC5223B69336 uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{D611A1D1-A025-4C8C-9453-6A9AE6A1BABB}: DhcpNameServer = [removed] [removed] FF - ProfilePath - f:\users\Tyler\AppData\Roaming\Mozilla\Firefox\Profiles\btgsoxuh.default\ FF - ExtSQL: 2013-09-15 09:23; {dc572301-7619-498c-a57d-39143191b318}; f:\users\Tyler\AppData\Roaming\Mozilla\Firefox\Profiles\btgsoxuh.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF - ExtSQL: !HIDDEN! 2012-09-03 18:54; [removed]; f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 . - - - - ORPHANS REMOVED - - - - . HKLM-Run-Computer Alarm Clock - (no file) f:\users\Tyler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pandora.lnk - f:\program files\Pandora\Pandora.exe ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - f:\program files\SUPERAntiSpyware\SASSEH.DLL SafeBoot-34196528.sys MSConfigStartUp-Search Protection - f:\programdata\Search Protection\SearchProtection.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-349171224-2937114174-661177079-1000\Software\SecuROM\License information*] "datasecu"=hex:cd,e6,81,b0,a1,c2,08,85,b1,a6,22,c7,17,f5,7c,87,56,c8,d5,ab,e1, 62,ef,a2,ad,12,7d,3a,aa,82,15,16,fa,dd,98,7d,b9,ea,03,09,d9,cb,41,45,73,c3,\ "rkeysecu"=hex:a1,91,17,31,d0,5e,e1,83,0b,54,48,b3,91,c7,21,d0 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-09-18 15:27:38 ComboFix-quarantined-files.txt 2013-09-18 19:27 . Pre-Run: 167,596,486,656 bytes free Post-Run: 167,469,563,904 bytes free . - - End Of File - - 48E649FE42F5B7544AF3B903381C00E3 A36C5E4F47E84449FF07ED3517B43A31
Hi, It seems that you have had several runs of malware removal programs and antiviruses on your system? Would that be accurate? Are you still using the LavaSoft/AdAware products and Vipre products?

Hi,

It seems that you have had several runs of malware removal programs and antiviruses on your system? Would that be accurate? Are you still using the LavaSoft/AdAware products and Vipre products?


Yes, I ran them multiple times before. They're uninstalled now, though - it is possible that there are still some leftover files or entries in the registry…

To be accurate, I ran them until I noticed that the symptoms (the vube.com / toplugs.com tabs popping up randomly in Firefox) were gone, but that never happened. So, then I uninstalled them all. Called university tech support, and they said to try MalwareBytes one more time (as a licensed user), so I used all of its features (Anti-Rootkit, Chameleon, etc) and then I ran CCleaner several times.

Honestly, if MalwareBytes got rid of it and CCleaner finished the job, then that wouldn't surprise me. There were never any hidden objects detected and, furthermore, I ran TDSSKiller twice (first time from Malware Removal Guide for Windows, second time from here) and there were threats detected & quarantined from the first time but not the second time. So, whatever it was, it would seem that my computer is clean. But, of course, I don't know that for sure - I am only reporting what I saw.

The only actual problem I have been dealing with now for the past few days is with the Office 365 Outlook Web App, which has been constantly crashing when I log in - everything turns black below the address bar, and nothing gets rendered properly on any of my tabs until I restart the browser. I recall having this happen not just on my desktop computer, but pretty much everywhere I go to use the Outlook Web App, no matter what computer I connect to it from. So, it seems that this is not a problem to do with my computer, but a nasty software issue, perhaps due to a recent update to firefox / flash / java. I might as well try to see if it does the same thing in IE and Chrome.

So, does everything look good on my end, do you think? Or shall we try running more tests first?
Hi,

Ok so you uninstalled those security programs? I ask because, yes, I did find several entries remaining. Check in Programs and Features to be sure that there are no Lavasoft/AdAware products listed in there. If they are, please uninstall them…if there are not any listed please let me know.

Called university tech support

Is this a university computer?

Check in Programs and Features to be sure that there are no Lavasoft/AdAware products listed in there. If they are, please uninstall them…if there are not any listed please let me know.


Ok, let's see….

Hmm, I don't see anything in Programs and Features for AdAware or Lavasoft… perhaps CCleaner doesn't pick that up, but some registry cleaner might get rid of it (and maybe more that we haven't spotted.)

Called university tech support

Is this a university computer?


Nah; this is my own personal computer - they just offer free support for students.
Hi,

Thank for letting me know about the computer (if it is a university computer or not).

Hmm, I don't see anything in Programs and Features for AdAware or Lavasoft… perhaps CCleaner doesn't pick that up, but some registry cleaner might get rid of it (and maybe more that we haven't spotted.)

Ok good. These are just remnants that I am seeing. No don't use a registry cleaner….they usually do more harm than good unfortunately.

Please run a Quick Scan with OTL and we will go from there. Post the new OTL.txt please.
Ok, I will run OTL when I get back to my dorm room sometime tonight, most likely. In the meantime, I do have a question about whether or not I should run OTL Quick Scan in Safe Mode or not, or if it does not matter? I only say this because I personally preferred running it in Safe Mode the first time [as well as everything else from this thread].

I will run OTL when I get back to my dorm room sometime tonight, most likely.

Sounds good!


whether or not I should run OTL Quick Scan in Safe Mode or not

Please run the Quick Scan in Normal Mode unless unable to do so. :)
Hi,

[external image: Posted Image] Tweaking.com Registry Backup
  • Download the tool found here to your Desktop so it is easy to find.
  • Double click on the file you just downloaded to install it to your system.
  • Once the tool is installed, double-click on the Tweaking.com Registry Backup icon
    **Note** The tool should automatically open to the Backup Registry tab.

    [external image: Posted Image]
  • Press Backup Now
  • When the back up is complete, the tool will tell you that Successful */* Files Backed Up
  • You have now successfully backed up your Registry.
———-

[external image: Posted Image]

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services

    :OTL
    SRV - (McComponentHostService) – F:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe (McAfee, Inc.)
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKU\S-1-5-21-349171224-2937114174-661177079-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securedsearch2.lavasoft.com/index.p…420DC5223B69336
    IE - HKU\S-1-5-21-349171224-2937114174-661177079-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 99 DE 1A F3 15 F3 CD 01 [binary data]
    IE - HKU\S-1-5-21-349171224-2937114174-661177079-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-349171224-2937114174-661177079-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
    [2013/09/01 17:53:12 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Roaming\LavasoftStatistics
    [2013/09/01 17:50:13 | 000,000,000 | —D | C] – F:\Users\Tyler\AppData\Local\adawarebp
    [2013/09/01 17:50:11 | 000,000,000 | —D | C] – F:\ProgramData\Ad-Aware Browsing Protection
    [2013/09/01 17:50:07 | 000,000,000 | —D | C] – F:\Program Files\Toolbar Cleaner
    [2013/09/01 17:49:50 | 000,000,000 | —D | C] – F:\Program Files\Lavasoft
    [1 F:\Windows\*.tmp files -> F:\Windows\*.tmp -> ]
    [2013/09/19 08:49:42 | 000,000,600 | —- | M] () – F:\Users\Tyler\AppData\Local\PUTTY.RND

    :Files
    ipconfig /flushdns /c

    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Post the new OTL.txt log and let me know how your system is running. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI