MaWilly
Topic Starter
Thank you for your help in advance. You all fixed me up once years ago and I am hoping for success with this new computer.
I was up and running fine and then all kinds of strange things would not work and they had been working before. Pop-up, wrong pages showing up, programs running wrong and tech support can't figure issues out….. I am posting all the logs below.
OTL logfile created on: 9/26/2013 5:28:00 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Susan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.86 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 57.44% Memory free
7.71 Gb Paging File | 5.74 Gb Available in Paging File | 74.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 447.66 Gb Total Space | 387.30 Gb Free Space | 86.52% Space Free | Partition Type: NTFS
Computer Name: SUSAN-LAPTOP | User Name: Susan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Susan\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Jawbone\JawboneUpdater.exe ()
PRC - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE (Microsoft Corporation.)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\ProgramData\Search Protection\SearchProtection.exe (Lavasoft)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
PRC - C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll ()
MOD - C:\Program Files (x86)\Jawbone\JawboneUpdater.exe ()
MOD - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
MOD - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll ()
MOD - C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\zlib1.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\dblite.dll ()
MOD - C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll ()
MOD - C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe ()
========== Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (ASCAntivirusSrv) – C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe (IOBit)
SRV - (BackupStack) – C:\Program Files (x86)\MyPC Backup\BackupStack.exe (Just Develop It)
SRV - (Ad-Aware Service) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (CSObjectsSrv) – C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (AdvancedSystemCareService6) – C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCSvc.exe (IObit)
SRV - (SBAMSvc) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (AKeyPCSyncService) – C:\Supra\AKeyPCSyncClient\AKeyPCSyncService.exe (GE Security Inc)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV:64bit: - (gfibto) – C:\Windows\SysNative\drivers\gfibto.sys (GFI Software)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kneps) – C:\Windows\SysNative\drivers\kneps.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kltdi) – C:\Windows\SysNative\drivers\kltdi.sys (Kaspersky Lab ZAO)
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (ThreatTrack Security)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (libusb0) – C:\Windows\SysNative\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV:64bit: - (sbapifs) – C:\Windows\SysNative\drivers\sbapifs.sys (GFI Software)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (klkbdflt) – C:\Windows\SysNative\drivers\klkbdflt.sys (Kaspersky Lab)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (bcbtums) – C:\Windows\SysNative\drivers\bcbtums.sys (Broadcom Corporation.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NTI Corporation)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NTI Corporation)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (btath_avdt) – C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (CSCrySec) – C:\Windows\SysNative\drivers\CSCrySec.sys (Infowatch)
DRV:64bit: - (CSVirtualDiskDrv) – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV:64bit: - (bScsiMSa) – C:\Windows\SysNative\drivers\bScsiMSa.sys (Broadcom Corporation)
DRV:64bit: - (k57nd60a) – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (bScsiSDa) – C:\Windows\SysNative\drivers\bScsiSDa.sys (Broadcom Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ETD) – C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (b57xdmp) – C:\Windows\SysNative\drivers\b57xdmp.sys (Broadcom Corporation)
DRV:64bit: - (b57xdbd) – C:\Windows\SysNative\drivers\b57xdbd.sys (Broadcom Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (PhSerUsb) – C:\Windows\SysNative\drivers\PhSerUsb.sys (PHILOG)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (BTKRNL) – C:\Windows\SysNative\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a;=d…9021852&ir;=
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{198B59FC-240E-9B00-5ADB-543F6EFA549C}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://start.mysearchdial.com/results.php?…9021852&ir;=
IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…_oid=26-12-2012
&tb;_mrud=26-12-2012
IE - HKLM\..\SearchScopes\{4C945085-5934-CFE5-38A0-4DF9A373F38F}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://start.mysearchdial.com/results.php?…9021852&ir;=
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes\{04522A6B-F138-430A-8DF6-65D88AB383B3}: "URL" = http://start.mysearchdial.com/results.php?…9021852&ir;=
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www2.delta-search.com/?q={searchTer…39&tsp;=5004
IE - HKCU\..\SearchScopes\{198B59FC-240E-9B00-5ADB-543F6EFA549C}: "URL" = http://websearch.shopathome.com?user_id={8…q={searchTerms}
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://securedsearch2.lavasoft.com/results…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "SecureSearch"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://securedsearch2.lavasoft.com/index.php?pr=vmn&id;=adawaretb&v;=3_4&ent;=hp&u;=3B401CF1803A95D10E932752389BB7A3"
FF - prefs.js..extensions.enabledAddons: %7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%7D:7.0
FF - prefs.js..extensions.enabledAddons: ascsurfingprotection%40iobit.com:1.0
FF - prefs.js..extensions.enabledAddons: 7go%407go.com:1.0.0.0
FF - prefs.js..extensions.enabledAddons: %7B87934c42-161d-45bc-8cef-ef18abe2a30c%7D:3.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - prefs.js..keyword.URL: "http://securedsearch2.lavasoft.com/results.php?pr=vmn&id;=adawaretb&v;=3_4&hsimp;=yhs-lavasoft&ent;=bs&q;="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mozilla.zeniko.ch/PDFlite_Browser_Plugin: C:\Program Files (x86)\PDFlite\npPdfViewer.dll (Simon Bünzli)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@mozilla.zeniko.ch/PDFlite_Browser_Plugin: C:\Program Files (x86)\PDFlite\npPdfViewer.dll (Simon Bünzli)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/12/19 14:32:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/09/23 22:33:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/12/31 20:50:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Extensions
[2013/09/25 20:01:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions
[2013/09/16 23:01:16 | 000,000,000 | —D | M] (appbario12) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
[2013/09/25 20:01:57 | 000,000,000 | —D | M] (SweetPacks) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}
[2013/09/17 14:13:32 | 000,000,000 | —D | M] (Ad-Aware Security Add-on) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2013/09/09 21:59:17 | 000,000,000 | —D | M] ("MySearchDial" />) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
[2013/09/13 16:05:36 | 000,000,000 | —D | M] (7Go Games) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\[removed]
[2013/09/12 10:54:12 | 000,000,000 | —D | M] (Advanced SystemCare Surfing Protection) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\[removed]
[2013/09/25 20:01:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\staged
[2013/08/29 21:57:08 | 000,007,979 | —- | M] () (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\[removed]
[2013/09/13 15:50:32 | 000,000,997 | —- | M] () – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\searchplugins\conduit.xml
[2013/09/09 21:59:22 | 000,002,393 | —- | M] () – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\searchplugins\Mysearchdial.xml
[2013/09/13 15:39:05 | 000,002,144 | —- | M] () – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\searchplugins\MyStart Search.xml
[2013/05/07 21:26:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/09/23 22:33:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/09/23 22:33:05 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/08/08 13:47:04 | 000,000,644 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
========== Chrome ==========
CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…279411&UM;=2
CHR - default_search_provider: suggest_url = http://suggest.search.conduit.com/CSuggest…140117&UM;=2
CHR - homepage: http://securedsearch2.lavasoft.com/index.p…E932752389BB7A3
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: SumatraPDF Browser Plugin (Enabled) = C:\Program Files (x86)\PDFlite\npPdfViewer.dll
CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_1\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_2\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_3\
CHR - Extension: Safe Money = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_0\
CHR - Extension: Safe Money = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_1\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4292_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\
CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.9_0\
CHR - Extension: Lavasoft NewTab = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole\0.12_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0\
CHR - Extension: Anti-Banner = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_1\
O1 HOSTS File: ([2013/09/12 15:43:58 | 000,449,438 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15429 more lines…
O2:64bit: - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Kaspersky Passsword Manager Toolbar) - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O2 - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {6C8DB2EC-499B-4897-A784-0E3186C97E9D} - No CLSID value found.
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Advanced SystemCare Browser Protection) - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\BrowerProtect\ASCPlugin_Protection.dll (IObit)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
O3:64bit: - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Kaspersky Passsword Manager Toolbar) - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe (Lavasoft)
O4 - HKCU..\Run: [ABBYY Screenshot Reader Retail] File not found
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - Startup: C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch Jawbone Updater.lnk = C:\Program Files (x86)\Jawbone\LaunchJU.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} https://www.icloud.com/system/iCloud.cab (iCloud Web App Plugin)
O16 - DPF: {9C65AB3E-C9A8-4789-AE24-B365A1C4A6F9} http://acer.custhelp.com/euf/assets/activex/snret.cab (SNRet Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F5F8F2C6-F64E-450C-B3D8-EE32F9DF7453}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2013/09/03 11:55:06 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{cd147cfc-8616-11e1-8453-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{cd147cfc-8616-11e1-8453-806e6f6e6963}\Shell\AutoRun\command - "" = D:\disk1\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\SysWow64\SL_ANET.ACM (Sipro Lab Telecom Inc.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.MP42 - C:\Windows\SysWow64\MPG4C32.DLL (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\Windows\SysWow64\MPG4C32.DLL (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/09/26 11:31:10 | 000,000,000 | —D | C] – C:\Users\Susan\Desktop\Adobe Application Manager 7.0
[2013/09/25 20:24:04 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jawbone
[2013/09/25 20:23:12 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\JawboneUpdater
[2013/09/25 20:23:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Jawbone
[2013/09/21 12:46:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/09/17 14:26:18 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\LavasoftStatistics
[2013/09/17 14:26:18 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2013/09/17 14:14:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2013/09/17 14:14:46 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2013/09/17 14:14:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2013/09/17 14:13:54 | 000,000,000 | —D | C] – C:\ProgramData\Search Protection
[2013/09/17 14:13:50 | 000,000,000 | —D | C] – C:\ProgramData\blekko toolbars
[2013/09/17 14:13:49 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\adawarebp
[2013/09/17 14:13:47 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2013/09/17 14:13:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2013/09/17 14:13:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2013/09/17 14:08:06 | 000,047,496 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2013/09/17 14:08:04 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Ad-Aware Antivirus
[2013/09/17 13:57:14 | 000,000,000 | —D | C] – C:\Users\Susan\Documents\ProcAlyzer Dumps
[2013/09/16 20:46:14 | 000,000,000 | —D | C] – C:\A-Scans
[2013/09/16 16:02:18 | 000,741,480 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\HPDiscoPM5912.dll
[2013/09/16 16:01:50 | 000,000,000 | —D | C] – C:\Program Files\HP
[2013/09/15 22:20:56 | 000,000,000 | —D | C] – C:\A-TT
[2013/09/13 15:49:35 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\PerformerSoft
[2013/09/13 15:49:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\7Go Games
[2013/09/13 15:49:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2013/09/13 15:49:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Performer
[2013/09/13 15:49:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\ffdshow
[2013/09/13 15:49:12 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/09/13 15:40:22 | 000,000,000 | —D | C] – C:\ProgramData\Conduit
[2013/09/13 15:40:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetPacks
[2013/09/13 15:40:01 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\CRE
[2013/09/13 15:39:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\SearchProtect
[2013/09/13 15:39:37 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\SearchProtect
[2013/09/13 15:38:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\BrowseFox
[2013/09/13 00:57:09 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
[2013/09/13 00:57:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyPC Backup
[2013/09/13 00:56:02 | 000,000,000 | —D | C] – C:\ProgramData\DSearchLink
[2013/09/13 00:55:44 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/09/13 00:54:57 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\SimpleFiles
[2013/09/12 23:43:55 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Intel Corporation
[2013/09/12 23:12:39 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
[2013/09/12 23:11:48 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\DSite
[2013/09/12 23:11:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Image Converter
[2013/09/12 13:58:21 | 000,000,000 | —D | C] – C:\Users\Susan\Desktop\Computer Care
[2013/09/12 10:54:30 | 000,000,000 | —D | C] – C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
[2013/09/12 10:54:26 | 000,000,000 | —D | C] – C:\IObit
[2013/09/12 10:54:25 | 000,000,000 | —D | C] – C:\ProgramData\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
[2013/09/12 10:54:22 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2013/09/12 10:54:21 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\IObit
[2013/09/12 10:54:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare Ultimate
[2013/09/12 10:54:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2013/09/12 09:52:16 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\BMExplorer
[2013/09/12 07:33:02 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/09/12 07:33:02 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/09/12 07:33:01 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/12 07:33:01 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/12 07:33:01 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/09/12 07:33:01 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/09/12 07:33:01 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/12 07:33:01 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/12 07:33:01 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/12 07:33:01 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/12 07:33:01 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/12 07:32:59 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/12 07:32:59 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/12 07:32:59 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/12 07:32:58 | 003,959,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/11 21:15:10 | 000,000,000 | —D | C] – C:\Users\Susan\Documents\OneNote Notebooks
[2013/09/11 18:32:30 | 000,155,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ataport.sys
[2013/09/11 18:32:29 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/09/11 18:32:29 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/09/11 18:32:29 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/09/11 18:32:29 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/09/11 18:32:28 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/09/11 18:32:28 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/09/11 18:32:28 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/09/11 18:32:28 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/09/11 18:32:28 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/09/11 18:32:28 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/09/11 18:32:28 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/09/11 18:32:28 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/09/11 18:32:28 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/09/11 18:32:28 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/09/11 18:32:28 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/09/11 18:32:28 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/09/11 18:32:28 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/09/11 18:32:28 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/09/11 18:32:28 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/09/11 18:32:28 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/09/11 18:32:27 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/09/11 18:32:27 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/09/11 18:32:27 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013/09/11 18:32:27 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apisetschema.dll
[2013/09/11 18:32:27 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/09/11 18:32:24 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/09/09 20:29:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A-PDF Restrictions Remover
[2013/09/09 18:36:56 | 000,000,000 | —D | C] – C:\ProgramData\A-PDF
[2013/09/09 18:25:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\A-PDF Restrictions Remover
[2013/09/09 18:06:08 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\Wondershare
[2013/09/09 18:06:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wondershare
[2013/09/09 18:05:42 | 000,000,000 | —D | C] – C:\ProgramData\PDFEditor
[2013/09/09 18:05:41 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Wondershare
[2013/09/08 11:22:26 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\SparkTrust
[2013/09/08 11:22:26 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\DriverCure
[2013/09/08 11:22:14 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SparkTrust
[2013/09/08 11:22:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\SparkTrust
[2013/09/08 11:22:01 | 000,000,000 | —D | C] – C:\ProgramData\SparkTrust
[2013/09/08 11:22:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\SparkTrust
[2013/09/07 08:55:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/09/07 08:54:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/09/04 22:46:29 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013/09/04 22:28:28 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\C8A13589-5A4C-46D8-9394-743EDDBDAB2B.aplzod
[2013/09/04 22:24:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013/09/04 22:24:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/09/04 22:24:13 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\Apple
[2013/09/04 22:24:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/09/04 22:24:00 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/09/04 22:24:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/09/04 22:23:47 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/09/04 22:23:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/09/04 22:15:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\JustCloud
[2013/09/03 11:54:25 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2013/09/03 11:53:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013/09/02 23:57:31 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2013/09/02 23:53:58 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Atheros
[2013/09/02 23:53:20 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
[2013/09/02 23:53:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bluetooth Suite
[2013/08/30 16:07:22 | 000,067,192 | —- | C] (http://libusb-win32.sourceforge.net) – C:\Windows\SysWow64\libusb0.dll
[2013/08/30 15:57:34 | 000,074,872 | —- | C] (http://libusb-win32.sourceforge.net) – C:\Windows\SysNative\libusb0.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/09/26 17:30:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/26 17:18:48 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 17:18:48 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 17:15:00 | 000,000,928 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-339540949-112371563-2919833766-1001UA.job
[2013/09/26 17:11:32 | 000,000,438 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.ics
[2013/09/26 17:11:00 | 000,000,286 | —- | M] () – C:\Windows\tasks\DSite.job
[2013/09/26 17:10:52 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/26 17:10:52 | 000,000,474 | —- | M] () – C:\Windows\tasks\SparkTrust Update Version3 Startup Task.job
[2013/09/26 17:10:49 | 000,000,414 | —- | M] () – C:\Windows\tasks\PC Optimizer Pro64 startups.job
[2013/09/26 17:10:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/26 17:10:41 | 3104,722,944 | -HS- | M] () – C:\hiberfil.sys
[2013/09/26 17:00:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/26 16:25:57 | 000,001,070 | —- | M] () – C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2013/09/25 20:51:14 | 000,730,384 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/25 20:51:14 | 000,627,082 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/25 20:51:14 | 000,107,366 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/25 20:24:04 | 000,000,992 | —- | M] () – C:\Users\Susan\Desktop\Jawbone Updater.lnk
[2013/09/25 20:23:12 | 000,000,824 | —- | M] () – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch Jawbone Updater.lnk
[2013/09/25 20:15:00 | 000,000,906 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-339540949-112371563-2919833766-1001Core.job
[2013/09/25 19:40:36 | 000,000,134 | —- | M] () – C:\Users\Susan\Desktop\Jawbone Support.url
[2013/09/25 19:33:45 | 000,000,464 | —- | M] () – C:\Windows\tasks\SparkTrust Registration3.job
[2013/09/25 12:59:43 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/25 12:59:42 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/22 12:08:32 | 000,000,522 | —- | M] () – C:\Windows\tasks\SparkTrust PC Cleaner Plus.job
[2013/09/21 12:52:25 | 000,000,017 | —- | M] () – C:\Users\Susan\AppData\Local\resmon.resmoncfg
[2013/09/21 12:46:44 | 000,001,747 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/17 14:08:05 | 000,014,456 | —- | M] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/09/16 16:02:17 | 000,002,204 | —- | M] () – C:\Users\Public\Desktop\HP Officejet Pro 8600.lnk
[2013/09/16 14:19:25 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/16 13:17:16 | 000,000,135 | —- | M] () – C:\Security_code.bat
[2013/09/15 22:31:36 | 000,000,679 | —- | M] () – C:\Users\Susan\Desktop\Therapeutic Touch.lnk
[2013/09/13 15:49:33 | 000,000,009 | —- | M] () – C:\END
[2013/09/13 00:57:09 | 000,001,051 | —- | M] () – C:\Users\Susan\Desktop\MyPC Backup.lnk
[2013/09/13 00:11:02 | 000,000,096 | —- | M] () – C:\Users\Susan\AppData\Roaming\WB.CFG
[2013/09/12 23:41:02 | 000,001,101 | —- | M] () – C:\Users\Susan\Desktop\Adobe Photoshop.lnk
[2013/09/12 22:28:21 | 000,001,063 | —- | M] () – C:\Users\Susan\Desktop\Adobe Bridge CS3.lnk
[2013/09/12 15:43:58 | 000,449,438 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/09/12 09:53:33 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2013/09/12 07:39:20 | 002,378,368 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/12 07:24:14 | 000,000,422 | —- | M] () – C:\Windows\tasks\SparkTrust Update Version3.job
[2013/09/09 22:36:17 | 000,000,200 | —- | M] () – C:\Users\Susan\Desktop\Facebook.url
[2013/09/09 21:05:09 | 000,001,097 | —- | M] () – C:\Users\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2013/09/03 11:55:06 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2013/09/02 23:58:44 | 000,000,952 | -HS- | M] () – C:\ProgramData\KGyGaAvL.sys
[2013/09/02 23:54:03 | 000,246,804 | —- | M] () – C:\Windows\SysNative\drivers\AtherosBt.bin
[2013/09/02 23:54:03 | 000,001,242 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2013/09/02 23:54:03 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2013/09/02 23:54:03 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40.dfu
[2013/09/02 23:54:03 | 000,001,198 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_26.dfu
[2013/08/31 19:24:48 | 000,449,438 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130912-154358.backup
[2013/08/31 19:23:46 | 000,012,473 | —- | M] () – C:\Windows\WinInit.Ini
[2013/08/31 17:45:01 | 000,449,438 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130831-192448.backup
[2013/08/31 14:25:30 | 000,000,301 | —- | M] () – C:\Users\Susan\Desktop\Home - Lumosity.url
[2013/08/30 16:07:22 | 000,067,192 | —- | M] (http://libusb-win32.sourceforge.net) – C:\Windows\SysWow64\libusb0.dll
[2013/08/30 15:57:34 | 000,074,872 | —- | M] (http://libusb-win32.sourceforge.net) – C:\Windows\SysNative\libusb0.dll
[2013/08/29 09:58:58 | 000,001,262 | —- | M] () – C:\Users\Susan\Desktop\Tri-City NYPS Home Page.url
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/09/26 16:25:57 | 000,001,082 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
[2013/09/26 16:25:57 | 000,001,070 | —- | C] () – C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2013/09/25 20:24:04 | 000,000,992 | —- | C] () – C:\Users\Susan\Desktop\Jawbone Updater.lnk
[2013/09/25 20:23:12 | 000,000,824 | —- | C] () – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch Jawbone Updater.lnk
[2013/09/25 19:40:22 | 000,000,134 | —- | C] () – C:\Users\Susan\Desktop\Jawbone Support.url
[2013/09/21 12:52:25 | 000,000,017 | —- | C] () – C:\Users\Susan\AppData\Local\resmon.resmoncfg
[2013/09/21 12:46:44 | 000,001,747 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/16 16:02:17 | 000,002,204 | —- | C] () – C:\Users\Public\Desktop\HP Officejet Pro 8600.lnk
[2013/09/16 15:36:34 | 000,000,962 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2013/09/16 14:24:00 | 000,000,135 | —- | C] () – C:\Security_code.bat
[2013/09/16 14:19:25 | 000,001,073 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/15 22:30:59 | 000,000,679 | —- | C] () – C:\Users\Susan\Desktop\Therapeutic Touch.lnk
[2013/09/13 15:39:06 | 000,000,009 | —- | C] () – C:\END
[2013/09/13 00:57:09 | 000,001,051 | —- | C] () – C:\Users\Susan\Desktop\MyPC Backup.lnk
[2013/09/13 00:11:02 | 000,000,096 | —- | C] () – C:\Users\Susan\AppData\Roaming\WB.CFG
[2013/09/12 23:41:53 | 000,001,063 | —- | C] () – C:\Users\Susan\Desktop\Adobe Bridge CS3.lnk
[2013/09/12 23:41:02 | 000,001,101 | —- | C] () – C:\Users\Susan\Desktop\Adobe Photoshop.lnk
[2013/09/12 23:11:49 | 000,000,286 | —- | C] () – C:\Windows\tasks\DSite.job
[2013/09/12 22:35:36 | 000,001,101 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS3.lnk
[2013/09/12 22:32:59 | 000,001,187 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Stock Photos CS3.lnk
[2013/09/12 22:31:10 | 000,001,367 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk
[2013/09/12 22:30:49 | 000,001,156 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS3.lnk
[2013/09/12 22:28:21 | 000,001,063 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS3.lnk
[2013/09/12 09:53:33 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2013/09/08 11:22:30 | 000,000,464 | —- | C] () – C:\Windows\tasks\SparkTrust Registration3.job
[2013/09/08 11:22:13 | 000,000,474 | —- | C] () – C:\Windows\tasks\SparkTrust Update Version3 Startup Task.job
[2013/09/08 11:22:13 | 000,000,422 | —- | C] () – C:\Windows\tasks\SparkTrust Update Version3.job
[2013/09/08 11:22:08 | 000,000,522 | —- | C] () – C:\Windows\tasks\SparkTrust PC Cleaner Plus.job
[2013/09/04 22:24:09 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/09/03 11:55:06 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2013/08/31 14:25:30 | 000,000,301 | —- | C] () – C:\Users\Susan\Desktop\Home - Lumosity.url
[2013/08/29 09:58:58 | 000,001,262 | —- | C] () – C:\Users\Susan\Desktop\Tri-City NYPS Home Page.url
[2013/08/23 11:44:30 | 000,000,088 | —- | C] () – C:\Users\Susan\.java.policy
[2013/03/28 19:54:14 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2013/03/14 21:57:11 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/02/24 21:22:18 | 000,743,534 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/02/19 21:27:36 | 000,000,028 | —- | C] () – C:\Windows\ICOA.INI
[2013/02/19 21:27:22 | 000,000,000 | —- | C] () – C:\Windows\QFNONL.ini
[2013/02/19 21:27:22 | 000,000,000 | —- | C] () – C:\Windows\QFN.ini
[2013/02/19 21:27:22 | 000,000,000 | —- | C] () – C:\Windows\QDQICK.ini
[2012/12/31 20:05:30 | 000,005,776 | —- | C] () – C:\Windows\Icoadb32.dat
[2012/12/31 20:05:30 | 000,000,064 | —- | C] () – C:\Windows\QBWCD.INI
[2012/12/29 21:32:18 | 000,012,473 | —- | C] () – C:\Windows\WinInit.Ini
[2012/12/20 23:30:39 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\LXEAsmr.dll
[2012/12/20 23:30:38 | 000,299,008 | —- | C] () – C:\Windows\SysWow64\LXEAsm.dll
[2012/12/20 23:06:01 | 000,001,080 | —- | C] () – C:\Windows\maxlink.ini
[2012/12/20 23:06:01 | 000,000,020 | —- | C] () – C:\Windows\calera.ini
[2012/12/20 23:05:58 | 000,269,312 | —- | C] () – C:\Windows\SysWow64\FPXIG.DLL
[2012/12/20 23:05:58 | 000,068,096 | —- | C] () – C:\Windows\SysWow64\IGFPX32P.DLL
[2012/12/20 23:05:58 | 000,065,024 | —- | C] () – C:\Windows\SysWow64\JPEGACC.DLL
[2012/12/20 23:05:51 | 000,101,376 | —- | C] () – C:\Windows\SysWow64\WELSOF32.DLL
[2012/12/20 21:28:10 | 000,000,952 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2012/12/20 00:16:09 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/12/14 02:42:30 | 000,963,452 | —- | C] () – C:\Windows\SysWow64\igcodeckrng600.bin
[2012/12/14 02:42:30 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/12/14 02:42:28 | 000,272,928 | —- | C] () – C:\Windows\SysWow64\igvpkrng600.bin
[2012/01/20 00:40:35 | 000,963,116 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/01/20 00:40:35 | 000,218,304 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2012/01/20 00:40:31 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
========== ZeroAccess Check ==========
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/07/25 22:24:57 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/07/25 21:55:59 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/09/12 23:12:39 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
[2013/09/17 15:12:17 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Ad-Aware Antivirus
[2013/09/26 16:45:10 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Classic Start Menu
[2013/09/03 17:10:55 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\DefaultTab
[2013/09/08 11:22:26 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\DriverCure
[2013/09/16 15:10:00 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Dropbox
[2013/09/12 23:11:48 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\DSite
[2013/09/13 09:34:04 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\IObit
[2013/04/20 09:51:17 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\IrfanView
[2013/09/25 20:24:11 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\JawboneUpdater
[2013/02/18 20:35:06 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\PDFlite
[2013/09/16 14:30:22 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\PerformerSoft
[2013/01/23 22:15:27 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\PowerCinema
[2013/03/09 22:34:35 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\S300-S400 Series
[2013/09/08 12:43:41 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Screensaver
[2013/09/13 15:50:40 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\SearchProtect
[2013/09/08 12:43:40 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\ShopAtHome
[2013/09/13 00:56:56 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\SimpleFiles
[2013/09/08 11:22:26 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\SparkTrust
[2012/12/31 20:50:06 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Thunderbird
[2012/12/29 19:57:02 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\WildTangent
[2013/02/22 20:00:46 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Windows Live Writer
[2013/09/09 18:06:29 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Wondershare
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2010/11/21 03:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2013/05/16 10:58:12 | 003,859,928 | —- | M] (Safer-Networking Ltd.) MD5=03250DB0886A23B1F6C077C5D9F152B0 – C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
[2011/07/14 01:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/07/14 01:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/07/14 01:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/07/14 01:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/07/14 01:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/07/14 01:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2013/01/08 21:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2013/07/26 02:23:39 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_16893df21e3dcd43\iexplore.exe
[2013/05/17 00:10:41 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=1423FF1BFD2ECD9CFC8C17EA4F98B20F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_0d07eadd80a334bf\iexplore.exe
[2013/08/10 02:31:28 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=1F3B062444AD6F667B5336E78D5A02B7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_ffb36d2837eafb72\iexplore.exe
[2013/02/22 03:04:50 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_0d238c71808d94e7\iexplore.exe
[2013/07/23 12:16:33 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_177836c3b4ee56e2\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_184d84e8cdd3303c\iexplore.exe
[2013/08/10 02:10:22 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D – C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/10 02:10:22 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_168ab5d61e3c99b7\iexplore.exe
[2013/08/10 00:18:11 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/08/10 00:18:11 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_20df6028529d5bb2\iexplore.exe
[2013/04/04 18:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_176a65f9b4f926ce\iexplore.exe
[2013/02/22 00:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_17f703a2ce14129d\iexplore.exe
[2013/08/10 01:13:42 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=48A1306191216997F717C451B8D15139 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_0a08177a6c4bbd6d\iexplore.exe
[2013/05/16 19:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_175c952fb503f6ba\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_20dde844529e8f3e\iexplore.exe
[2013/02/02 04:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 23:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013/07/26 01:47:06 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8D805B4EEEE0ECF6B604BE284978F135 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_ffb0112a37ee15f1\iexplore.exe
[2011/09/21 05:28:13 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2013/07/23 12:16:32 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/05/16 21:46:47 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=A1397D2A4924C390E55D146FB45FDF7C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_0df2d8da9977d637\iexplore.exe
[2013/04/04 21:55:57 | 000,763,504 | —- | M] (Microsoft Corporation) MD5=A1B0DEC3BB845C6369F97BC1A3542A07 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_0d15bba7809864d3\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/05/16 18:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_1847832ccdd89832\iexplore.exe
[2013/02/02 03:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2012/11/15 23:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/05/29 02:24:18 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=AFF2C99AD2C599108B6BD9E77C24B463 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_0d0dec99809dccc9\iexplore.exe
[2013/02/22 03:17:45 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=B21A57AA4CB928059A0C0C58A9E77A02 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_0da2595099b350a2\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2013/04/04 17:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_17e932d8ce1ee289\iexplore.exe
[2013/04/04 20:40:37 | 000,763,504 | —- | M] (Microsoft Corporation) MD5=C4A4F4AD91677DA1659A9ADE63746B8B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_0d94888699be208e\iexplore.exe
[2010/11/20 23:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/05/29 01:56:53 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=C9C29508A433DAF0118D28C4F38CDDFC – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_0df8da9699726e41\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/07/26 01:09:39 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_0a04bb7c6c4ed7ec\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_176296ebb4fe8ec4\iexplore.exe
[2013/01/08 20:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/09/21 05:28:11 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2011/09/21 05:28:12 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/09/21 05:28:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-058FE8F5.PF >
[2013/09/26 17:12:10 | 000,082,178 | —- | M] () MD5=320EBFA8B741981D0346A8193B7CCA2A – C:\Windows\Prefetch\IEXPLORE.EXE-058FE8F5.pf
< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/09/26 17:12:13 | 000,184,226 | —- | M] () MD5=562DAF54CC326B57115234DD8484F6C6 – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf
< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2012/12/18 15:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.CSS >
[2011/02/07 18:44:10 | 000,000,093 | —- | M] () MD5=F15FB82C578490B209442B8C1D5076CC – C:\ProgramData\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
[2011/02/07 18:44:10 | 000,000,093 | —- | M] () MD5=F15FB82C578490B209442B8C1D5076CC – C:\Users\All Users\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
< MD5 for: SERVICES.ESM >
[2013/02/08 11:39:44 | 000,008,731 | —- | M] () MD5=A481BF1A869654B9C4B5BC8ADD636782 – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\services.esm
[2013/02/08 11:39:44 | 000,008,731 | —- | M] () MD5=A481BF1A869654B9C4B5BC8ADD636782 – C:\Users\Susan\AppData\Local\Temp\services.esm
< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.INI >
[2011/02/07 18:44:10 | 000,000,012 | —- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 – C:\ProgramData\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
[2011/02/07 18:44:10 | 000,000,012 | —- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 – C:\Users\All Users\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SBS >
[2011/03/01 00:00:00 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Includes\Services.sbs
[2011/03/01 03:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Extracts\Services.sbs
< MD5 for: SERVICES.SBS-20110301.CAB >
[2013/08/17 09:05:26 | 000,041,248 | —- | M] () MD5=149FF3413EED31253183D6E65E383138 – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Downloads\Services.sbs-20110301.cab
< MD5 for: WINLOGON.ADML >
[2010/11/21 03:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2013/09/03 11:55:06 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/01/20 00:48:00 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2013/09/13 15:49:33 | 000,000,009 | —- | M] () – C:\END
[2013/09/26 17:10:41 | 3104,722,944 | -HS- | M] () – C:\hiberfil.sys
[2013/09/26 17:10:40 | 4139,630,592 | -HS- | M] () – C:\pagefile.sys
[2013/09/16 13:17:16 | 000,000,135 | —- | M] () – C:\Security_code.bat
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/09/12 16:57:44 | 000,322,048 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is FCBE-51BF
Directory of C:\
07/14/2009 01:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 01:08 AM All Users [C:\ProgramData]
07/14/2009 01:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 01:08 AM My Music [C:\Users\Default\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 01:08 AM My Music [C:\Users\Public\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Susan
12/20/2012 12:58 AM Application Data [C:\Users\Susan\AppData\Roaming]
12/20/2012 12:58 AM Cookies [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies]
12/20/2012 12:58 AM Local Settings [C:\Users\Susan\AppData\Local]
12/20/2012 12:58 AM My Documents [C:\Users\Susan\Documents]
12/20/2012 12:58 AM NetHood [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/20/2012 12:58 AM PrintHood [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/20/2012 12:58 AM Recent [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Recent]
12/20/2012 12:58 AM SendTo [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\SendTo]
12/20/2012 12:58 AM Start Menu [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu]
12/20/2012 12:58 AM Templates [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Susan\AppData\Local
12/20/2012 12:58 AM Application Data [C:\Users\Susan\AppData\Local]
12/20/2012 12:58 AM History [C:\Users\Susan\AppData\Local\Microsoft\Windows\History]
12/20/2012 12:58 AM Temporary Internet Files [C:\Users\Susan\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Susan\Documents
12/20/2012 12:58 AM My Music [C:\Users\Susan\Music]
12/20/2012 12:58 AM My Pictures [C:\Users\Susan\Pictures]
12/20/2012 12:58 AM My Videos [C:\Users\Susan\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 415,630,790,656 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/12/19 13:03:39 | 000,000,221 | -HS- | M] () – C:\Users\Susan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 9/26/2013 5:28:00 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Susan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.86 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 57.44% Memory free
7.71 Gb Paging File | 5.74 Gb Available in Paging File | 74.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 447.66 Gb Total Space | 387.30 Gb Free Space | 86.52% Space Free | Partition Type: NTFS
Computer Name: SUSAN-LAPTOP | User Name: Susan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04ADBB4C-7AF6-4D7B-AF34-0768469A2B67}" = rport=139 | protocol=6 | dir=out | app=system |
"{0655BDD4-69A0-4346-A5D0-1EF5DDEC65B5}" = rport=137 | protocol=17 | dir=out | app=system |
"{0953DB66-D4BB-4B0D-84A5-726122187EBC}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{103829AB-C0B2-4586-B54A-787C49A02D4B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{1587E8B4-6384-44BA-9F0C-B1B4BA9C3BB3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1CCF2D95-4329-4D9B-9B29-4926AEF53CF6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1D4749B2-9818-48DA-B455-EF3816C6CF10}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{22D9139C-7B72-48D7-915D-7A488C7CF916}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{240D2054-F4EB-4775-8492-EC2D219DB51F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{28CBABAB-7CCF-49D0-9EB9-B1B9464BB95D}" = lport=445 | protocol=6 | dir=in | app=system |
"{2E41175E-EF71-4E2C-BC85-993AD8027232}" = rport=445 | protocol=6 | dir=out | app=system |
"{3CAE88E2-5B94-4420-B55C-B2F3A94368BF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{48786DC4-2C13-4CE7-9BE9-FF1BE0F7FD0D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{52DE6EC9-DBD1-4F10-8687-DF861234EE1D}" = lport=137 | protocol=17 | dir=in | app=system |
"{53E0C3FD-1A03-4728-8F65-E70E9A4F7AF4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{563F7A25-5ED0-40F4-B513-B2AE4ABC6268}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{565B2A6F-F7CE-4AF7-857A-C91CFE4CBF44}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{59771679-9C78-489D-A4BF-605FC2989EB5}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5D45432B-ACDF-4888-B65E-FD0106680959}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{8040034F-BBC8-4E52-860C-C1072FCA8988}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{83C2C555-7811-480D-8AF0-EB4CE6CD6F22}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{8BDFCAD1-639C-4C9B-9C41-D7B6AA2B78FF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8C37143E-8856-47F1-A091-A95C00C0195F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{912DBC3A-1CE8-4BE0-90D7-141BF33256DF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{94984184-9930-439E-8AE7-5AC05F21B246}" = lport=139 | protocol=6 | dir=in | app=system |
"{94DC1D7C-0A37-4CED-9FB0-E18B61A65580}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{9DB9D098-D9F0-4390-99A2-CEB705E400D1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{A17E0438-39E8-4F66-BA46-109950352263}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A2909244-AECC-4FF6-92AE-5B492F2F0E98}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A490E5AA-978A-42C3-B2F3-118F3CE66F4C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{A5F5DDF7-F8A8-4EC3-8414-85A59FF22B86}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A6043D55-19EC-40BD-9412-365A0CCDAB1E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{A8A7223A-0FD9-43E4-A2C4-CCD00159BDEB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A8F0334E-E6C7-45BE-967B-76B9FD419461}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{ACE31730-7205-4194-B020-0822E5F07C14}" = rport=2869 | protocol=6 | dir=out | app=system |
"{AD8DC53A-A9DC-4212-91EA-CC2FDB2F024B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{B2B22AF5-7570-45FA-B076-DA0D7F0BD9DB}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{B4D9D840-E8AE-46D1-B7F0-D313095B400C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B67BCCF7-7BCD-4796-9DB3-C39DC31759A6}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{BEE12C76-8AB5-449B-94BE-086C631CF5AF}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{C050273D-685E-4EFF-ABD1-E391A1E551E2}" = lport=138 | protocol=17 | dir=in | app=system |
"{C5A1AF50-5957-45AF-A264-395CD7F6C4F7}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{C8EB1666-4856-4D42-AF60-A050514CEAE6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D1C9EA4C-23EF-4FEA-8FB8-993192586501}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{D87FDA28-3F37-4A4D-81D8-9A6FB39A8E12}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{EB945A89-E557-4A2E-A7DB-925B8F2D114A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F2CD2323-9A4F-4D1C-98DC-4EF964F9BEED}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F3B4A808-CDCB-46E7-81EE-2FE9D985CD9F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{FB4FAAF2-31E1-4EC9-A846-AFD2405DA323}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FEB8215A-DACB-475F-AA05-AAF8AC27A90A}" = rport=138 | protocol=17 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{11D2C4A2-AAF5-48E1-9D42-00800D17C737}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{1798807A-A26B-4523-889A-0BC2BE91EB30}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\clear.fi.exe |
"{17D0105F-1C5B-4EF1-8DC2-CD8C7B912B2D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{18C41018-A446-469A-B1BB-83BAD709722C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{1F4868F0-9432-4B76-BD47-C7BD116592A9}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{26174917-C0AC-4203-B1C4-C0C81538EE91}" = dir=in | app=c:\program files (x86)\acer\clear.fi\movie\touchmovieservice.exe |
"{2844BF72-4BCE-4019-AE0C-49BC0A2B8056}" = protocol=6 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
"{285DD813-9C47-4771-ADEC-5C6CDA2A0380}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{289AD9CA-8065-4F94-B586-AEBC10F2880A}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\dmr\dmrengine.exe |
"{2ADC2F64-F701-4A5E-B55B-4C014F1DD869}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\clml\clmlsvc.exe |
"{2E60C048-0FDB-4EDC-BEE1-652C7A988E45}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{31E69CEB-7748-4E2E-A128-2F8CAF14B05A}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\hpnetworkcommunicatorcom.exe |
"{34017392-28E2-4EDA-8719-85D0B9C83985}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{368DA8DD-91A4-41A5-BF52-83FD72F538FA}" = dir=in | app=c:\program files (x86)\acer\clear.fi\movie\touchmovie.exe |
"{3797BE0B-89EF-4416-93F5-69ED65B864F6}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3B5B95C9-A3A3-4236-A8C6-D900470BDA16}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3EAF1F1C-1F4B-40E5-835E-D339FC80CE77}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{40BE7B8E-E512-448D-A4E6-DF5D0582C5ED}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\dmr\dmrengine.exe |
"{459850D3-A87F-4BB9-A0E6-DFCB6523B504}" = protocol=6 | dir=in | app=c:\program files (x86)\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{4801BD53-49D9-4F9F-ABF8-3FF1F0A0B38B}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\sendafax.exe |
"{4A903D21-17F6-4BDA-8171-D98287F62568}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\clear.fiagent.exe |
"{4E504EF7-FAEA-4C86-8F8D-331C37E745C3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{52B55AEB-DA98-455D-9C86-437FADE13287}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{55DE6B54-0A44-4407-AEDB-E82181262E85}" = protocol=6 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"{5677A918-D05E-4C36-AAB9-279CC635438F}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{57D6C992-4354-4A0C-B35A-79B7226437F4}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\faxapplications.exe |
"{5D84BF12-AEEA-4F67-9211-608EEE6B6EC2}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5E688360-D8B0-47C9-AE94-BC6EB49D4225}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5EE9B8E3-DA39-4E11-BC9D-77B4F38D209E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{62640CE0-1790-4849-B6ED-796C280E751A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6324D973-F1B3-40AD-AD2D-5FF6215193FF}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6468C0E8-0F22-42A9-8FFA-3C13A8CC87BC}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark s300-s400 series\lxeafax.exe |
"{72F17001-A320-4804-BA2C-37C3C9755D25}" = protocol=17 | dir=in | app=c:\program files (x86)\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{7A9AFF25-E7DA-41D4-8ABC-22402C51CCE4}" = protocol=17 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{7D5E3D26-FFF4-429C-99DF-7B82B969E0FC}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\devicesetup.exe |
"{868A15F4-4187-4582-B110-4EAFC1AB37D6}" = protocol=17 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
"{86CEFCAF-D8B1-4C7D-8265-BE2B397B52EA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8BD56F8C-7C58-4110-8A74-E8A93110E500}" = protocol=17 | dir=in | app=c:\program files (x86)\simplefiles\simplefiles.exe |
"{91066994-DD64-4D89-BE32-F1226A9E9224}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{921208FF-AFD1-429F-A0AF-ECC6A9BCA0B4}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{987ACC97-B356-497B-BB12-11C1B9FF37FC}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{9FCFF30C-A524-4E0C-AFF4-6F1B1E64B37D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A0F57050-B9F0-4F2F-B0CC-CADEE3F99E35}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\dmr\dmrengine.exe |
"{A4C6F67D-AA9B-4AD0-96FC-3765A2356B24}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\hpnetworkcommunicator.exe |
"{A675D738-1C44-4394-98CA-0E733C8B6178}" = protocol=6 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{A7C3D687-D3FD-417A-B5A3-89486A8D2FAF}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B29370D5-4B84-4ACF-8BDD-9F9C6C91C685}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B2FA67B0-FB9A-4EBB-8FC5-B05E946CC65B}" = protocol=17 | dir=in | app=c:\program files (x86)\simplefiles\downloader.exe |
"{BA92A40C-9C4C-4A3C-A1B3-6A171C9E1652}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark s300-s400 series\lxeafax.exe |
"{BCD7CB3C-580B-4ABE-9F0F-E690DDAF1758}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C7D22EA8-5073-4B43-89AA-498EA213AA02}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C97C7C90-3DE7-4464-9E49-FB0FCCCC2B5C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CF115154-EC6E-4A85-845C-E1168C7C52CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CFD94CF5-3F07-4EA1-82BD-90F0566ECF87}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\digitalwizards.exe |
"{D1151BEE-8FE2-4045-B2F4-6447CAA17297}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{D44AB640-8F9D-4E61-B9DC-2C501E65F2C1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D8534F44-A8A1-4043-A30B-8B1BE8C6618D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D88BD773-B41F-475C-97B7-1B29712E751F}" = dir=in | app=c:\users\susan\appdata\local\microsoft\skydrive\skydrive.exe |
"{DC354CBE-8D61-4ECD-8A3C-62ED6DCA519A}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{E1F11D89-EA69-4D6C-9212-0797B8BC99FF}" = protocol=17 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"{E3A16DF7-CE0B-43B1-9601-540398DD106A}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E4CD7981-12CA-41A1-9322-CDB53688C9CF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E8F5F337-4024-4A29-BF21-08CB5276F918}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{EB7DA30E-79FE-4D16-B9BA-35AB87503334}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{EC669960-6E47-40D7-8394-E5D0DFA90015}" = protocol=6 | dir=in | app=c:\program files (x86)\simplefiles\downloader.exe |
"{EF241424-B752-4C0D-B79B-FA3825839A03}" = protocol=6 | dir=out | app=system |
"{F54A5837-10C2-41D7-857F-907A23A36A3F}" = protocol=6 | dir=in | app=c:\program files (x86)\simplefiles\simplefiles.exe |
"{FA535685-A8C8-4FBA-BAA4-7DC8B8AA9C32}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{0CE6D6AC-D73D-4E75-A0C1-E26F9F9979B0}C:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{4FF125F4-839A-4BE5-8833-E5D021F4C9AF}C:\users\susan\downloads\pess20setup2.exe" = protocol=6 | dir=in | app=c:\users\susan\downloads\pess20setup2.exe |
"TCP Query User{74FA084B-532D-4DBB-A2A5-76F92B73D622}C:\program files (x86)\jawbone\jawboneupdater.exe" = protocol=6 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"TCP Query User{B3585CA0-C294-42BE-A77F-A73873C1386F}C:\program files (x86)\scansoft\paperport\navbrowser.exe" = protocol=6 | dir=in | app=c:\program files (x86)\scansoft\paperport\navbrowser.exe |
"UDP Query User{0A545F58-1361-44BB-B067-9E06734688FC}C:\users\susan\downloads\pess20setup2.exe" = protocol=17 | dir=in | app=c:\users\susan\downloads\pess20setup2.exe |
"UDP Query User{609EC151-04A1-46AE-9E8A-A59EAEDC3014}C:\program files (x86)\scansoft\paperport\navbrowser.exe" = protocol=17 | dir=in | app=c:\program files (x86)\scansoft\paperport\navbrowser.exe |
"UDP Query User{660A59DF-A7A2-4916-A3CF-F77FEC253D68}C:\program files (x86)\jawbone\jawboneupdater.exe" = protocol=17 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"UDP Query User{B9E7DF9A-F196-4E94-984F-4A53ED569BC7}C:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{2BF5E9CC-C55D-4B0F-ACAF-FFE77F333CD8}" = HP Officejet Pro 8600 Product Improvement Study
"{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}" = Apple Mobile Device Support
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{4710662C-8204-4334-A977-B1AC9E547819}" = Broadcom Card Reader Driver Installer
"{4F917ED3-B077-4C7F-97D5-DDD59D3F4D7C}" = ActiveKEY_X64
"{5F611ADA-B98C-4DBB-ADDE-414F08457ECF}" = Windows Live Family Safety
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{791A06E2-340F-43B0-8FAB-62D151339362}" = HP Officejet Pro 8600 Basic Device Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{C91DCB72-F5BB-410D-A91A-314F5D1B4284}" = Broadcom NetLink Controller
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{E990722F-10AA-4A1A-9107-EAC5EE2CEC38}" = AKeyPCSyncClient_X64
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}" = iCloud
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6822EFD-3F7D-4B35-8845-757A26AEC8E2}" = Windows Live MIME IFilter
"{F73A118B-8271-47E2-8790-0C636B2539C5}" = iTunes
"{FEA1590B-540A-41FC-A95C-664493C82A21}" = Classic Shell
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 8.0.6.3_WHQL
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MyPC Backup" = MyPC Backup
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Office
"{01944037-D136-45EE-A007-403EAD929FC7}" = Windows Live Writer
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{061FF8F3-5226-4278-8AAB-282C1B024F58}" = Photo Common
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0AD576A7-EDCE-469E-ADD7-1AC9DB200C6B}" = Windows Live Mail
"{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Backup Manager V3
"{0EAD5B5C-534A-4486-8ECB-679E218ADEE1}" = Hi-Speed USB Bridge-Network Cable
"{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}" = Microsoft Application Compatibility Toolkit 5.6
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{10812DE7-2E57-4740-B226-6B3BE34AF9D7}" = Lexmark Tools for Office
"{13F3CEA5-9E2C-4C4E-9F0F-D0DB389CF4A9}" = Movie Maker
"{14C4C3B6-F1F4-401F-8C86-03E8E19AAC8C}" = clear.fi
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{17D26CDD-B87C-412B-92F0-2D5DD4313522}" = Facebook Messenger 2.1.4651.0
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack
"{184A0D4F-4BCF-40EF-A73C-F0313FDB5CCD}" = Windows Live Messenger
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}" = Windows Live Messenger
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FEE19BC-6F0C-42E4-82FF-FB597F6141DF}" = Windows Live Essentials
"{23170F69-40C1-2701-0921-000001000000}" = 7-Zip 9.21
"{23A3E560-069F-4CFC-8F6C-1B526EC735FC}" = Windows Live Writer Resources
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}" = Evernote v. 4.5.1
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2AEAFC79-79E6-4784-9CF9-D9D82932BF88}" = Windows Live Family Safety
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{35827710-D042-428B-A1E5-E20E12D2FEB9}" = SparkTrust PC Cleaner Plus
"{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Office
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3C63F944-803E-49A7-B3A2-B8AB3313E883}" = Windows Live UX Platform Language Pack
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{43AAE145-83CF-4C96-9A5E-756CEFCE879F}" = clear.fi Client
"{446CC8CE-0E90-44F7-ADD0-774B243EF090}" = Galerie de photos
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5524D7D3-FA5C-4AF7-8EB3-6FEA0D455326}" = Corel Office - Templates
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{66E13170-6BB6-48D0-97F1-511D11E3B01F}" = Corel Office
"{69D48C91-CCC2-4305-89DE-D1F8122EDBF4}" = Photo Common
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6C41841F-0ED6-4A78-BD19-B188726D2D80}" = Hi-Speed USB-USB Network Cable
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{70853C06-F097-452E-B090-682D8584551D}" = Corel Office - IPM
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B0C5EF6-DE4C-4E20-8889-C17604FFE5CD}" = Windows Live Family Safety
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8030AE22-7FA0-4880-A538-8906EDBF49F4}" = Windows Live Writer Resources
"{82BF2C5E-79A7-4A13-B508-D5E64A5B141E}" = Uninstall Helper
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86C40513-B5A4-476E-9EAB-EC118DCF4502}" = Windows Live Writer
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8AAEB5A5-A397-46B6-8AF3-B6DC790C4E48}" = Windows Live Messenger
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8D813AFF-D91D-4EE0-821F-B901FC2E89FA}" = Windows Live
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8F7FECEC-088F-431D-A5FB-2B59E1E69943}" = Galería de fotos
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90993BD9-C7D9-4C2F-B56C-2F7AFEBD4CD0}" = Windows Live UX Platform Language Pack
"{936F0E9D-5FCC-462F-B538-8D55C84EA326}" = AKeyPCSyncClient
"{944167EA-7F89-4705-8DCD-1D63B53141B0}" = Ad-Aware Antivirus
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007A-0416-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{96914829-DF65-40AE-8A31-6F3E96BAEBBD}" = Windows Live Mail
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}" = Windows Live Writer
"{99AA6730-54CD-4B9E-B05B-0A5196743923}" = Windows Live UX Platform Language Pack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A17946CA-18E5-4CF0-8D55-A56D804718F8}" = Movie Maker
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A2E5F2AA-2996-41EA-BCCD-9FD0476A5326}" = TWC Customer Controls
"{A5DC64EE-2FC4-4C35-9975-639DD8499369}" = Windows Live Family Safety
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{B20502AB-2A3F-48F9-AD09-9FB61689A6D4}" = Windows Live Writer
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B77D2795-23C0-4DBD-B7B5-CFB542D1FA3F}" = Windows Live Writer Resources
"{B80D3EA9-A252-4AE5-AC51-81729F5C586F}" = Windows Live Mail
"{B906C11A-D193-4143-9FA7-E2EE8A5A8F21}" = clear.fi
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}" = Dolby Advanced Audio v2
"{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials
"{C08D0804-1DB0-4375-AF23-7120F4C121E1}" = Windows Live Family Safety
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C32D87E1-6310-4CD5-8D6D-865AFE0E9B4E}" = Movie Maker
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C595F480-788A-4F8F-8277-1A91F32CA879}" = Windows Live Writer
"{C5CFE150-86C1-4D7C-B07B-9023A62628DC}" = honestech Easy Video Editor
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D28FDA7D-15C6-48A2-9868-6BCB28BE6254}" = Microsoft Picture It! Photo 2001
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark Printable Web
"{D322A9E3-758B-4D60-A7C4-65C88FD378D0}" = Bing Bar
"{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common
"{D9D4D271-609F-440D-A9EC-A66B0815CFE2}" = Windows Live Essentials
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB169E8F-5332-4DBF-B085-84AA2C373304}" = Windows Live Messenger
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DDFF51C0-A729-49E2-B777-8432C0F74FD9}" = Windows Live Mail
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E74EA3B1-7192-489D-9A57-0AE918FEC001}" = Corel Office - Launcher
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F341F73D-0D6E-4D37-995D-74F28EBD406C}" = Windows Live Writer Resources
"{F5248B7E-779A-4FA4-8134-D1933D8680FA}" = Galeria de Fotos
"{F54030F3-14B6-432D-9361-78DCB1473920}" = Photo Common
"{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"adawaretb" = Ad-Aware Security Add-on
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"Adobe AIR" = Adobe AIR
"Adobe Creative Cloud" = Adobe Creative Cloud
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Advanced SystemCare Ultimate_is1" = Advanced SystemCare Ultimate 6
"A-PDF Restrictions Remover_is1" = A-PDF Restrictions Remover
"Bookkeeping for Realtors_is1" = Bookkeeping for Realtors 2.1.1
"Classic Start Menu_is1" = Classic Start Menu 3.88
"Coupon Printer for Windows5.0.0.3" = Coupon Printer for Windows
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"Identity Card" = Identity Card
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Acer Backup Manager
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi
"InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"InstallWIX_{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"IrfanView" = IrfanView (remove only)
"Jawbone Updater" = Jawbone Updater
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mozilla Firefox 19.0 (x86 en-US)" = Mozilla Firefox 19.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"PaperPort 7.02" = PaperPort 7.02
"PC Essentials 20 Digital Download" = PC Essentials 20 Digital Download
"PDFlite" = PDFlite 0.8
"QuickBooks" = QuickBooks
"Shockwave" = Shockwave
"ShopAtHome.com Helper" = ShopAtHome.com Helper
"Uninstall Helper 2.0.1.0" = Uninstall Helper
"Un-Zip for Windows" = Un-Zip for Windows 9.22beta
"WinLiveSuite" = Windows Live Essentials
"zipForm6" = zipForm6
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"DSite" = Update for Image Editor
"Image Editor Packages" = Image Editor Packages
"jZip" = jZip
"SkyDriveSetup.exe" = Microsoft SkyDrive
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/17/2013 7:32:16 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 7042
Description =
Error - 9/17/2013 7:32:16 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 9002
Description =
Error - 9/17/2013 7:32:16 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3029
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3029
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3028
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3058
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 7010
Description =
Error - 9/17/2013 7:33:15 PM | Computer Name = Susan-Laptop | Source = WinMgmt | ID = 10
Description =
Error - 9/17/2013 7:35:26 PM | Computer Name = Susan-Laptop | Source = Application Hang | ID = 1002
Description = The program IEXPLORE.EXE version 10.0.9200.16686 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: f4c Start
Time: 01ceb3fe2fdd0d3f Termination Time: 56 Application Path: C:\Program Files (x86)\Internet
Explorer\IEXPLORE.EXE Report Id:
Error - 9/18/2013 9:23:29 AM | Computer Name = Susan-Laptop | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 7/23/2013 3:40:08 PM | Computer Name = Susan-Laptop | Source = DCOM | ID = 10005
Description =
Error - 7/23/2013 3:40:32 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:40:32 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:41:30 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:42:17 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:42:17 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:42:21 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:43:43 PM | Computer Name = Susan-Laptop | Source = ipnathlp | ID = 34001
Description =
Error - 7/23/2013 3:43:43 PM | Computer Name = Susan-Laptop | Source = ipnathlp | ID = 30013
Description =
Error - 7/23/2013 3:44:26 PM | Computer Name = Susan-Laptop | Source = DCOM | ID = 10016
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:10:19 PM, on 9/26/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\ProgramData\Search Protection\SearchProtection.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Jawbone\JawboneUpdater.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Susan\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
O2 - BHO: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: (no name) - {6C8DB2EC-499B-4897-A784-0E3186C97E9D} - (no file)
O2 - BHO: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O2 - BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O3 - Toolbar: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
O3 - Toolbar: Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
O4 - HKLM\..\Run: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" –showwindow=false –onOSstartup=true
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O4 - Startup: Launch Jawbone Updater.lnk = ?
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
O9 - Extra 'Tools' menuitem: Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
O9 - Extra button: (no name) - {64964764-1101-4bbd-8891-B56B1A53B9B3} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} (iCloud Web App Plugin) - https://www.icloud.com/system/iCloud.cab
O16 - DPF: {9C65AB3E-C9A8-4789-AE24-B365A1C4A6F9} (SNRet Control) - http://acer.custhelp.com/euf/assets/activex/snret.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0204621355979526) (0204621355979526mcinstcleanup) - Unknown owner - C:\Windows\TEMP\020462~1.EXE (file missing)
O23 - Service: Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Ad-Aware (SBAMSvc) - GFI Software - C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 14073 bytes
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16686 BrowserJavaVersion: 10.25.2
Run by [removed] at 18:11:56 on 2013-09-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3948.1837 [GMT -4:00]
.
AV: Kaspersky PURE 3.0 *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Lavasoft Ad-Aware *Enabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AV: Advanced SystemCare Ultimate *Disabled/Updated* {1C304DC4-1D72-5DB9-B33A-43B638ECFD30}
SP: Kaspersky PURE 3.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Aware *Enabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
FW: Kaspersky PURE 3.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\ProgramData\Search Protection\SearchProtection.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Jawbone\JawboneUpdater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_175_ActiveX.exe
C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\EgisTec IPS\PMMUpdate.exe
C:\Program Files\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\sysWow64\SearchProtocolHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
mStart Page = hxxp://www.google.com
mWinlogon: Userinit = userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} -
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
BHO: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: {6C8DB2EC-499B-4897-A784-0E3186C97E9D} -
BHO: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
BHO: Advanced SystemCare Browser Protection: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\BrowerProtect\ASCPlugin_Protection.dll
BHO: Lexmark Printable Web: {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
TB: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
TB: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
TB: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
TB: Bing Bar: {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
uRun: [ABBYY Screenshot Reader Retail]
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" –showwindow=false –onOSstartup=true
dRunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid}
StartupFolder: C:\Users\Susan\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Launch Jawbone Updater.lnk - C:\Program Files (x86)\Jawbone\LaunchJU.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
DPF: {9C65AB3E-C9A8-4789-AE24-B365A1C4A6F9} - hxxp://acer.custhelp.com/euf/assets/activex/snret.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{F5F8F2C6-F64E-450C-B3D8-EE32F9DF7453} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{F5F8F2C6-F64E-450C-B3D8-EE32F9DF7453}\7594C48454C4D435 : DHCPNameServer = 192.168.10.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck -
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
x64-mStart Page = hxxp://start.mysearchdial.com/?f=1&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=
x64-BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll
x64-TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
x64-IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} -
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck -
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\
FF - prefs.js: browser.search.selectedEngine - SecureSearch
FF - prefs.js: browser.startup.homepage - hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id;=adawaretb&v;=3_4&ent;=hp&u;=3B401CF1803A95D10E932752389BB7A3
FF - prefs.js: keyword.URL - hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id;=adawaretb&v;=3_4&hsimp;=yhs-lavasoft&ent;=bs&q;=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\PDFlite\npPdfViewer.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-08-29 21:57; [removed]; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\[removed]
FF - ExtSQL: 2013-09-09 21:59; {ad9a41d2-9a49-4fa6-a79e-71a0785364c8}; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
FF - ExtSQL: 2013-09-12 07:30; [removed]; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\[removed]
FF - ExtSQL: 2013-09-13 16:05; {7e8a1050-cf67-4575-92df-dcc60e7d952d}; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}
FF - ExtSQL: 2013-09-13 16:05; {465fcfbb-47a4-4866-a5d5-d12f9a77da00}; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
.
—- FIREFOX POLICIES —-
FF - user.js: extensions.mysearchdial.hmpg - true
FF - user.js: extensions.mysearchdial.hmpgUrl - hxxp://start.mysearchdial.com/?f=1&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=
FF - user.js: extensions.mysearchdial.dfltSrch - true
FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial
FF - user.js: extensions.mysearchdial.dnsErr - true
FF - user.js: extensions.mysearchdial_i.newTab - false
FF - user.js: extensions.mysearchdial.newTabUrl - hxxp://start.mysearchdial.com/?f=2&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=
FF - user.js: extensions.mysearchdial.tlbrSrchUrl - hxxp://start.mysearchdial.com/?f=3&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=&q;=
FF - user.js: extensions.mysearchdial.id - B888E303260C51BF
FF - user.js: extensions.mysearchdial.instlDay - 15957
FF - user.js: extensions.mysearchdial.vrsn -
FF - user.js: extensions.mysearchdial.vrsni -
FF - user.js: extensions.mysearchdial_i.vrsnTs - 18:25:52
FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial
FF - user.js: extensions.mysearchdial.prdct - mysearchdial
FF - user.js: extensions.mysearchdial.aflt - dnld2msd
FF - user.js: extensions.mysearchdial_i.smplGrp - none
FF - user.js: extensions.mysearchdial.tlbrId - base
FF - user.js: extensions.mysearchdial.instlRef -
FF - user.js: extensions.mysearchdial.dfltLng -
FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
FF - user.js: extensions.mysearchdial.excTlbr - false
FF - user.js: extensions.mysearchdial_i.hmpg - true
FF - user.js: extensions.mysearchdial.cr - 1399021852
FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtF
yEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q
FF - user.js: extensions.irmysearch.aflt - dnld2msd
FF - user.js: extensions.irmysearch.instlRef -
FF - user.js: extensions.irmysearch.cr - 1399021852
FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtF
yEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q
.
.
.
.
.
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - fcbe51bf00000000000008edb91380fe
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15961
FF - user.js: extensions.delta.vrsn - [removed]
FF - user.js: extensions.delta.vrsni - [removed]
FF - user.js: extensions.delta.vrsnTs - [removed]:56:11
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=123639&tsp;=5004
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;C:\Windows\System32\drivers\CSCrySec.sys [2013-7-23 84536]
R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2013-2-23 14456]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;C:\Windows\System32\drivers\CSVirtualDiskDrv.sys [2013-7-23 66616]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2012-8-2 28504]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2012-10-18 54368]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2012-8-13 178448]
R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2012-1-20 22648]
R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2012-1-20 20520]
R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2012-1-20 62776]
R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2013-6-13 1236336]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [2012-12-20 356968]
R2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]
R2 sbapifs;sbapifs;C:\Windows\System32\drivers\sbapifs.sys [2012-9-12 82872]
R3 b57xdbd;Broadcom xD Picture Bus Driver Service;C:\Windows\System32\drivers\b57xdbd.sys [2011-1-20 67624]
R3 b57xdmp;Broadcom xD Picture vstorp client drv;C:\Windows\System32\drivers\b57xdmp.sys [2011-1-20 19496]
R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE [2013-7-23 240288]
R3 bScsiMSa;bScsiMSa;C:\Windows\System32\drivers\bScsiMSa.sys [2011-5-16 51240]
R3 bScsiSDa;bScsiSDa;C:\Windows\System32\drivers\bScsiSDa.sys [2011-5-6 86056]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-9-16 30368]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2012-1-20 142632]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-5-10 425000]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2012-9-3 29016]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2012-9-3 29528]
S2 0204621355979526mcinstcleanup;McAfee Application Installer Cleanup (0204621355979526);C:\Windows\TEMP\020462~1.EXE C:\PROGRA~2\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> C:\Windows\TEMP\020462~1.EXE C:\PROGRA~2\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE [2013-7-23 193696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-9-16 36000]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2012-3-2 138280]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-9-16 330912]
S3 btath_avdt;Atheros Bluetooth AVDT Service;C:\Windows\System32\drivers\btath_avdt.sys [2011-9-16 110240]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-9-16 167584]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-9-16 68256]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-9-16 280992]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-1-2 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 gfiark;gfiark;C:\Windows\System32\drivers\gfiark.sys [2013-2-24 39504]
S3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-1-20 317440]
S3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 07/08/2013,1.2.6.1;C:\Windows\System32\drivers\libusb0.sys [2012-11-29 52320]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-2-24 25928]
S3 PhSerUsb;Enfora Enabler IIIG USB Driver;C:\Windows\System32\drivers\PhSerUsb.sys [2010-7-7 71416]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-12-20 1255736]
S4 AdvancedSystemCareService6;Advanced SystemCare Service 6;C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCSvc.exe [2013-9-12 1051088]
S4 AKeyPCSyncService;ActiveKEY PCSync Service;C:\Supra\AKeyPCSyncClient\AKeyPCSyncService.exe [2010-8-4 107832]
S4 ASCAntivirusSrv;AdvancedSystemCareAntivirus;C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe [2013-9-12 623936]
S4 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-9-16 105120]
S4 BackupStack;Computer Backup (MyPC Backup);C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2013-7-1 32808]
S4 CSObjectsSrv;CryptoStorage control service;C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2012-12-21 819040]
S4 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2012-1-20 353360]
S4 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2011-6-21 173424]
S4 ePowerSvc;ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2012-4-14 872552]
S4 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S4 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2011-5-29 36456]
S4 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-1-20 13592]
S4 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2012-1-20 244624]
S4 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-2-24 418376]
S4 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-2-24 701512]
S4 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-4-23 256832]
S4 SDScannerService;Spybot-S&D; 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-8-9 1817560]
S4 SDUpdateService;Spybot-S&D; 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-8-9 1033688]
S4 SDWSCService;Spybot-S&D; 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-8-9 171928]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
.
=============== Created Last 30 ================
.
2013-09-26 00:23:12 ——– d—–w- C:\Users\Susan\AppData\Roaming\JawboneUpdater
2013-09-26 00:23:12 ——– d—–w- C:\Program Files (x86)\Jawbone
2013-09-24 02:33:05 262552 —-a-w- C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2013-09-24 02:33:01 26520 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-09-21 16:45:57 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-21 16:45:57 ——– d—–w- C:\Program Files\iTunes
2013-09-21 16:45:57 ——– d—–w- C:\Program Files\iPod
2013-09-21 16:45:57 ——– d—–w- C:\Program Files (x86)\iTunes
2013-09-17 18:26:18 ——– d—–w- C:\Users\Susan\AppData\Roaming\LavasoftStatistics
2013-09-17 18:26:18 ——– d—–w- C:\ProgramData\Ad-Aware Antivirus
2013-09-17 18:14:45 ——– d—–w- C:\Program Files (x86)\Ad-Aware Antivirus
2013-09-17 18:13:54 ——– d—–w- C:\ProgramData\Search Protection
2013-09-17 18:13:50 ——– d—–w- C:\ProgramData\blekko toolbars
2013-09-17 18:13:49 ——– d—–w- C:\Users\Susan\AppData\Local\adawarebp
2013-09-17 18:13:47 ——– d—–w- C:\ProgramData\Ad-Aware Browsing Protection
2013-09-17 18:13:40 ——– d—–w- C:\Program Files (x86)\Toolbar Cleaner
2013-09-17 18:13:13 ——– d—–w- C:\Program Files (x86)\Lavasoft
2013-09-17 18:08:06 47496 —-a-w- C:\Windows\System32\sbbd.exe
2013-09-17 18:08:04 ——– d—–w- C:\Users\Susan\AppData\Roaming\Ad-Aware Antivirus
2013-09-17 17:23:11 9694160 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A870E8F7-A4B4-47BC-A420-C018391BDD51}\mpengine.dll
2013-09-17 00:46:14 ——– d—–w- C:\A-Scans
2013-09-16 20:02:18 741480 ——w- C:\Windows\System32\HPDiscoPM5912.dll
2013-09-16 20:01:50 ——– d—–w- C:\Program Files\HP
2013-09-16 18:24:00 135 —-a-w- C:\Security_code.bat
2013-09-16 02:20:56 ——– d—–w- C:\A-TT
2013-09-13 19:49:35 ——– d—–w- C:\Users\Susan\AppData\Roaming\PerformerSoft
2013-09-13 19:49:28 ——– d—–w- C:\Program Files (x86)\7Go Games
2013-09-13 19:49:22 ——– d—–w- C:\Program Files (x86)\PC Performer
2013-09-13 19:49:22 ——– d—–w- C:\Program Files (x86)\ffdshow
2013-09-13 19:40:22 ——– d—–w- C:\ProgramData\Conduit
2013-09-13 19:40:18 ——– d—–w- C:\Program Files (x86)\SweetPacks
2013-09-13 19:40:01 ——– d—–w- C:\Users\Susan\AppData\Local\CRE
2013-09-13 19:39:42 ——– d—–w- C:\Program Files (x86)\SearchProtect
2013-09-13 19:39:37 ——– d—–w- C:\Users\Susan\AppData\Roaming\SearchProtect
2013-09-13 19:38:09 ——– d—–w- C:\Program Files (x86)\BrowseFox
2013-09-13 04:57:08 ——– d—–w- C:\Program Files (x86)\MyPC Backup
2013-09-13 04:56:02 ——– d—–w- C:\ProgramData\DSearchLink
2013-09-13 04:55:44 ——– d—–w- C:\ProgramData\Babylon
2013-09-13 04:54:57 ——– d—–w- C:\Users\Susan\AppData\Roaming\SimpleFiles
2013-09-13 03:43:55 ——– d—–w- C:\Users\Susan\AppData\Roaming\Intel Corporation
2013-09-13 03:12:39 ——– d—–w- C:\Users\Susan\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
2013-09-13 03:11:48 ——– d—–w- C:\Users\Susan\AppData\Roaming\DSite
2013-09-13 03:11:47 ——– d—–w- C:\Program Files (x86)\Image Converter
2013-09-12 14:54:30 ——– d—–w- C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
2013-09-12 14:54:26 ——– d—–w- C:\IObit
2013-09-12 14:54:25 ——– d—–w- C:\ProgramData\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
2013-09-12 14:54:22 ——– d—–w- C:\ProgramData\IObit
2013-09-12 14:54:21 ——– d—–w- C:\Users\Susan\AppData\Roaming\IObit
2013-09-12 14:54:07 ——– d—–w- C:\Program Files (x86)\IObit
2013-09-12 13:52:16 ——– d—–w- C:\Users\Susan\AppData\Local\BMExplorer
2013-09-11 22:32:30 155584 —-a-w- C:\Windows\System32\drivers\ataport.sys
2013-09-09 22:36:56 ——– d—–w- C:\ProgramData\A-PDF
2013-09-09 22:25:06 ——– d—–w- C:\Program Files (x86)\A-PDF Restrictions Remover
2013-09-09 22:06:08 ——– d—–w- C:\Users\Susan\AppData\Local\Wondershare
2013-09-09 22:06:06 ——– d—–w- C:\Program Files (x86)\Common Files\Wondershare
2013-09-09 22:05:42 ——– d—–w- C:\ProgramData\PDFEditor
2013-09-09 22:05:41 ——– d—–w- C:\Users\Susan\AppData\Roaming\Wondershare
2013-09-08 15:22:26 ——– d—–w- C:\Users\Susan\AppData\Roaming\SparkTrust
2013-09-08 15:22:26 ——– d—–w- C:\Users\Susan\AppData\Roaming\DriverCure
2013-09-08 15:22:06 ——– d—–w- C:\Program Files (x86)\Common Files\SparkTrust
2013-09-08 15:22:01 ——– d—–w- C:\ProgramData\SparkTrust
2013-09-08 15:22:01 ——– d—–w- C:\Program Files (x86)\SparkTrust
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll
2013-09-05 02:46:29 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-09-05 02:28:28 ——– d—–w- C:\Users\Susan\AppData\Local\C8A13589-5A4C-46D8-9394-743EDDBDAB2B.aplzod
2013-09-05 02:24:13 ——– d—–w- C:\Users\Susan\AppData\Local\Apple
2013-09-05 02:24:00 ——– d—–w- C:\Program Files\Bonjour
2013-09-05 02:24:00 ——– d—–w- C:\Program Files (x86)\Bonjour
2013-09-05 02:15:21 ——– d—–w- C:\Program Files (x86)\JustCloud
2013-09-03 17:12:55 ——– d—–w- C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-09-03 15:54:25 ——– d—–w- C:\Program Files\Enigma Software Group
2013-09-03 15:53:36 ——– d—–w- C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP
2013-09-03 15:53:30 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-09-03 03:57:31 ——– d—–w- C:\ProgramData\Atheros
2013-09-03 03:53:58 ——– d—–w- C:\Users\Susan\AppData\Roaming\Atheros
2013-09-03 03:53:03 ——– d—–w- C:\Program Files (x86)\Bluetooth Suite
2013-08-30 20:07:22 67192 —-a-w- C:\Windows\SysWow64\libusb0.dll
2013-08-30 19:57:34 74872 —-a-w- C:\Windows\System32\libusb0.dll
.
==================== Find3M ====================
.
2013-09-25 16:59:43 692616 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-25 16:59:42 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-17 18:08:05 14456 —-a-w- C:\Windows\System32\drivers\gfibto.sys
2013-09-03 03:58:44 952 –sha-w- C:\ProgramData\KGyGaAvL.sys
2013-08-10 05:22:18 2241024 —-a-w- C:\Windows\System32\wininet.dll
2013-08-10 05:20:59 3959296 —-a-w- C:\Windows\System32\jscript9.dll
2013-08-10 05:20:55 67072 —-a-w- C:\Windows\System32\iesetup.dll
2013-08-10 05:20:55 136704 —-a-w- C:\Windows\System32\iesysprep.dll
2013-08-10 03:59:10 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-08-10 03:58:09 2876928 —-a-w- C:\Windows\SysWow64\jscript9.dll
2013-08-10 03:58:06 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-08-10 03:58:06 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-08-10 03:17:38 2706432 —-a-w- C:\Windows\System32\mshtml.tlb
2013-08-10 03:07:50 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-08-10 02:27:59 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-08-10 02:17:19 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-08-08 01:20:43 3155456 —-a-w- C:\Windows\System32\win32k.sys
2013-08-07 08:22:02 278800 ——w- C:\Windows\System32\MpSigStub.exe
2013-08-05 15:39:40 96168 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-05 15:39:39 867240 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-08-05 15:39:39 789416 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-08-02 02:23:53 5550528 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-08-02 02:15:44 1732032 —-a-w- C:\Windows\System32\ntdll.dll
2013-08-02 02:15:03 362496 —-a-w- C:\Windows\System32\wow64win.dll
2013-08-02 02:15:03 243712 —-a-w- C:\Windows\System32\wow64.dll
2013-08-02 02:15:03 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2013-08-02 02:14:57 215040 —-a-w- C:\Windows\System32\winsrv.dll
2013-08-02 02:14:11 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2013-08-02 02:13:34 424448 —-a-w- C:\Windows\System32\KernelBase.dll
2013-08-02 01:59:30 3968960 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-02 01:59:30 3913664 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-08-02 01:51:23 1292192 —-a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-02 01:50:42 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2013-08-02 01:50:42 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2013-08-02 01:09:17 338432 —-a-w- C:\Windows\System32\conhost.exe
2013-08-02 00:59:09 112640 —-a-w- C:\Windows\System32\smss.exe
2013-08-02 00:45:37 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2013-08-02 00:45:36 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-02 00:45:35 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2013-08-02 00:45:34 2048 —-a-w- C:\Windows\SysWow64\user.exe
2013-08-02 00:43:05 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-07-25 09:25:54 1888768 —-a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-23 20:04:07 54368 —-a-w- C:\Windows\System32\drivers\kltdi.sys
2013-07-23 20:04:07 178448 —-a-w- C:\Windows\System32\drivers\kneps.sys
2013-07-23 20:04:06 90208 —-a-w- C:\Windows\System32\drivers\klflt.sys
2013-07-23 16:15:17 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-07-19 01:58:42 2048 —-a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2013-07-09 05:52:52 224256 —-a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 —-a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 —-a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 —-a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33 663552 —-a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10 175104 —-a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 —-a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-06 06:03:53 1910208 —-a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 18:12:43.04 ===============
Thank you again - I hope you are able to see my problem here.
MaWilly
I was up and running fine and then all kinds of strange things would not work and they had been working before. Pop-up, wrong pages showing up, programs running wrong and tech support can't figure issues out….. I am posting all the logs below.
OTL logfile created on: 9/26/2013 5:28:00 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Susan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.86 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 57.44% Memory free
7.71 Gb Paging File | 5.74 Gb Available in Paging File | 74.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 447.66 Gb Total Space | 387.30 Gb Free Space | 86.52% Space Free | Partition Type: NTFS
Computer Name: SUSAN-LAPTOP | User Name: Susan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Susan\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Jawbone\JawboneUpdater.exe ()
PRC - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE (Microsoft Corporation.)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\ProgramData\Search Protection\SearchProtection.exe (Lavasoft)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
PRC - C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll ()
MOD - C:\Program Files (x86)\Jawbone\JawboneUpdater.exe ()
MOD - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
MOD - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll ()
MOD - C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\zlib1.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\dblite.dll ()
MOD - C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll ()
MOD - C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe ()
========== Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (ASCAntivirusSrv) – C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe (IOBit)
SRV - (BackupStack) – C:\Program Files (x86)\MyPC Backup\BackupStack.exe (Just Develop It)
SRV - (Ad-Aware Service) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (CSObjectsSrv) – C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (AdvancedSystemCareService6) – C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCSvc.exe (IObit)
SRV - (SBAMSvc) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (AKeyPCSyncService) – C:\Supra\AKeyPCSyncClient\AKeyPCSyncService.exe (GE Security Inc)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys File not found
DRV:64bit: - (gfibto) – C:\Windows\SysNative\drivers\gfibto.sys (GFI Software)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kneps) – C:\Windows\SysNative\drivers\kneps.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kltdi) – C:\Windows\SysNative\drivers\kltdi.sys (Kaspersky Lab ZAO)
DRV:64bit: - (gfiark) – C:\Windows\SysNative\drivers\gfiark.sys (ThreatTrack Security)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (libusb0) – C:\Windows\SysNative\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV:64bit: - (sbapifs) – C:\Windows\SysNative\drivers\sbapifs.sys (GFI Software)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (klkbdflt) – C:\Windows\SysNative\drivers\klkbdflt.sys (Kaspersky Lab)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (bcbtums) – C:\Windows\SysNative\drivers\bcbtums.sys (Broadcom Corporation.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NTI Corporation)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NTI Corporation)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (btath_avdt) – C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (CSCrySec) – C:\Windows\SysNative\drivers\CSCrySec.sys (Infowatch)
DRV:64bit: - (CSVirtualDiskDrv) – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV:64bit: - (bScsiMSa) – C:\Windows\SysNative\drivers\bScsiMSa.sys (Broadcom Corporation)
DRV:64bit: - (k57nd60a) – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (bScsiSDa) – C:\Windows\SysNative\drivers\bScsiSDa.sys (Broadcom Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ETD) – C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (b57xdmp) – C:\Windows\SysNative\drivers\b57xdmp.sys (Broadcom Corporation)
DRV:64bit: - (b57xdbd) – C:\Windows\SysNative\drivers\b57xdbd.sys (Broadcom Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (PhSerUsb) – C:\Windows\SysNative\drivers\PhSerUsb.sys (PHILOG)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (BTKRNL) – C:\Windows\SysNative\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a;=d…9021852&ir;=
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{198B59FC-240E-9B00-5ADB-543F6EFA549C}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://start.mysearchdial.com/results.php?…9021852&ir;=
IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…_oid=26-12-2012
&tb;_mrud=26-12-2012
IE - HKLM\..\SearchScopes\{4C945085-5934-CFE5-38A0-4DF9A373F38F}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://start.mysearchdial.com/results.php?…9021852&ir;=
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes\{04522A6B-F138-430A-8DF6-65D88AB383B3}: "URL" = http://start.mysearchdial.com/results.php?…9021852&ir;=
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www2.delta-search.com/?q={searchTer…39&tsp;=5004
IE - HKCU\..\SearchScopes\{198B59FC-240E-9B00-5ADB-543F6EFA549C}: "URL" = http://websearch.shopathome.com?user_id={8…q={searchTerms}
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://securedsearch2.lavasoft.com/results…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "SecureSearch"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://securedsearch2.lavasoft.com/index.php?pr=vmn&id;=adawaretb&v;=3_4&ent;=hp&u;=3B401CF1803A95D10E932752389BB7A3"
FF - prefs.js..extensions.enabledAddons: %7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%7D:7.0
FF - prefs.js..extensions.enabledAddons: ascsurfingprotection%40iobit.com:1.0
FF - prefs.js..extensions.enabledAddons: 7go%407go.com:1.0.0.0
FF - prefs.js..extensions.enabledAddons: %7B87934c42-161d-45bc-8cef-ef18abe2a30c%7D:3.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - prefs.js..keyword.URL: "http://securedsearch2.lavasoft.com/results.php?pr=vmn&id;=adawaretb&v;=3_4&hsimp;=yhs-lavasoft&ent;=bs&q;="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mozilla.zeniko.ch/PDFlite_Browser_Plugin: C:\Program Files (x86)\PDFlite\npPdfViewer.dll (Simon Bünzli)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@mozilla.zeniko.ch/PDFlite_Browser_Plugin: C:\Program Files (x86)\PDFlite\npPdfViewer.dll (Simon Bünzli)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/12/19 14:32:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[removed] [2013/07/23 16:05:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/09/23 22:33:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/12/31 20:50:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Extensions
[2013/09/25 20:01:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions
[2013/09/16 23:01:16 | 000,000,000 | —D | M] (appbario12) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
[2013/09/25 20:01:57 | 000,000,000 | —D | M] (SweetPacks) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}
[2013/09/17 14:13:32 | 000,000,000 | —D | M] (Ad-Aware Security Add-on) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2013/09/09 21:59:17 | 000,000,000 | —D | M] ("MySearchDial" />) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
[2013/09/13 16:05:36 | 000,000,000 | —D | M] (7Go Games) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\[removed]
[2013/09/12 10:54:12 | 000,000,000 | —D | M] (Advanced SystemCare Surfing Protection) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\[removed]
[2013/09/25 20:01:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\staged
[2013/08/29 21:57:08 | 000,007,979 | —- | M] () (No name found) – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\Extensions\[removed]
[2013/09/13 15:50:32 | 000,000,997 | —- | M] () – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\searchplugins\conduit.xml
[2013/09/09 21:59:22 | 000,002,393 | —- | M] () – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\searchplugins\Mysearchdial.xml
[2013/09/13 15:39:05 | 000,002,144 | —- | M] () – C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\searchplugins\MyStart Search.xml
[2013/05/07 21:26:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/09/23 22:33:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/09/23 22:33:05 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/08/08 13:47:04 | 000,000,644 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\adawaretb.xml
========== Chrome ==========
CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…279411&UM;=2
CHR - default_search_provider: suggest_url = http://suggest.search.conduit.com/CSuggest…140117&UM;=2
CHR - homepage: http://securedsearch2.lavasoft.com/index.p…E932752389BB7A3
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\pdf.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: SumatraPDF Browser Plugin (Enabled) = C:\Program Files (x86)\PDFlite\npPdfViewer.dll
CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_1\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_2\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_3\
CHR - Extension: Safe Money = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_0\
CHR - Extension: Safe Money = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.2.558_1\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4292_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\
CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1\
CHR - Extension: Chrome In-App Payments service = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.9_0\
CHR - Extension: Lavasoft NewTab = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole\0.12_0\
CHR - Extension: No name found = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0\
CHR - Extension: Anti-Banner = C:\Users\Susan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_1\
O1 HOSTS File: ([2013/09/12 15:43:58 | 000,449,438 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15429 more lines…
O2:64bit: - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Kaspersky Passsword Manager Toolbar) - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O2 - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (no name) - {6C8DB2EC-499B-4897-A784-0E3186C97E9D} - No CLSID value found.
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Advanced SystemCare Browser Protection) - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\BrowerProtect\ASCPlugin_Protection.dll (IObit)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (ClassicIE9BHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft)
O3:64bit: - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Kaspersky Passsword Manager Toolbar) - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe (Lavasoft)
O4 - HKCU..\Run: [ABBYY Screenshot Reader Retail] File not found
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - Startup: C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch Jawbone Updater.lnk = C:\Program Files (x86)\Jawbone\LaunchJU.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm ()
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe (IvoSoft)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} https://www.icloud.com/system/iCloud.cab (iCloud Web App Plugin)
O16 - DPF: {9C65AB3E-C9A8-4789-AE24-B365A1C4A6F9} http://acer.custhelp.com/euf/assets/activex/snret.cab (SNRet Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F5F8F2C6-F64E-450C-B3D8-EE32F9DF7453}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2013/09/03 11:55:06 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{cd147cfc-8616-11e1-8453-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{cd147cfc-8616-11e1-8453-806e6f6e6963}\Shell\AutoRun\command - "" = D:\disk1\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\SysWow64\SL_ANET.ACM (Sipro Lab Telecom Inc.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.MP42 - C:\Windows\SysWow64\MPG4C32.DLL (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\Windows\SysWow64\MPG4C32.DLL (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/09/26 11:31:10 | 000,000,000 | —D | C] – C:\Users\Susan\Desktop\Adobe Application Manager 7.0
[2013/09/25 20:24:04 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jawbone
[2013/09/25 20:23:12 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\JawboneUpdater
[2013/09/25 20:23:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Jawbone
[2013/09/21 12:46:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/09/21 12:45:57 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/09/17 14:26:18 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\LavasoftStatistics
[2013/09/17 14:26:18 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Antivirus
[2013/09/17 14:14:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2013/09/17 14:14:46 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2013/09/17 14:14:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2013/09/17 14:13:54 | 000,000,000 | —D | C] – C:\ProgramData\Search Protection
[2013/09/17 14:13:50 | 000,000,000 | —D | C] – C:\ProgramData\blekko toolbars
[2013/09/17 14:13:49 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\adawarebp
[2013/09/17 14:13:47 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2013/09/17 14:13:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2013/09/17 14:13:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2013/09/17 14:08:06 | 000,047,496 | —- | C] (GFI Software) – C:\Windows\SysNative\sbbd.exe
[2013/09/17 14:08:04 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Ad-Aware Antivirus
[2013/09/17 13:57:14 | 000,000,000 | —D | C] – C:\Users\Susan\Documents\ProcAlyzer Dumps
[2013/09/16 20:46:14 | 000,000,000 | —D | C] – C:\A-Scans
[2013/09/16 16:02:18 | 000,741,480 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\HPDiscoPM5912.dll
[2013/09/16 16:01:50 | 000,000,000 | —D | C] – C:\Program Files\HP
[2013/09/15 22:20:56 | 000,000,000 | —D | C] – C:\A-TT
[2013/09/13 15:49:35 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\PerformerSoft
[2013/09/13 15:49:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\7Go Games
[2013/09/13 15:49:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2013/09/13 15:49:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Performer
[2013/09/13 15:49:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\ffdshow
[2013/09/13 15:49:12 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/09/13 15:40:22 | 000,000,000 | —D | C] – C:\ProgramData\Conduit
[2013/09/13 15:40:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetPacks
[2013/09/13 15:40:01 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\CRE
[2013/09/13 15:39:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\SearchProtect
[2013/09/13 15:39:37 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\SearchProtect
[2013/09/13 15:38:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\BrowseFox
[2013/09/13 00:57:09 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
[2013/09/13 00:57:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyPC Backup
[2013/09/13 00:56:02 | 000,000,000 | —D | C] – C:\ProgramData\DSearchLink
[2013/09/13 00:55:44 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/09/13 00:54:57 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\SimpleFiles
[2013/09/12 23:43:55 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Intel Corporation
[2013/09/12 23:12:39 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
[2013/09/12 23:11:48 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\DSite
[2013/09/12 23:11:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Image Converter
[2013/09/12 13:58:21 | 000,000,000 | —D | C] – C:\Users\Susan\Desktop\Computer Care
[2013/09/12 10:54:30 | 000,000,000 | —D | C] – C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
[2013/09/12 10:54:26 | 000,000,000 | —D | C] – C:\IObit
[2013/09/12 10:54:25 | 000,000,000 | —D | C] – C:\ProgramData\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
[2013/09/12 10:54:22 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2013/09/12 10:54:21 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\IObit
[2013/09/12 10:54:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare Ultimate
[2013/09/12 10:54:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2013/09/12 09:52:16 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\BMExplorer
[2013/09/12 07:33:02 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/09/12 07:33:02 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/09/12 07:33:01 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/12 07:33:01 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/12 07:33:01 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/09/12 07:33:01 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/09/12 07:33:01 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/12 07:33:01 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/12 07:33:01 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/12 07:33:01 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/12 07:33:01 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/12 07:32:59 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/12 07:32:59 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/12 07:32:59 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/12 07:32:58 | 003,959,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/11 21:15:10 | 000,000,000 | —D | C] – C:\Users\Susan\Documents\OneNote Notebooks
[2013/09/11 18:32:30 | 000,155,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ataport.sys
[2013/09/11 18:32:29 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/09/11 18:32:29 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/09/11 18:32:29 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/09/11 18:32:29 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/09/11 18:32:28 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/09/11 18:32:28 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/09/11 18:32:28 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/09/11 18:32:28 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/09/11 18:32:28 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/09/11 18:32:28 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/09/11 18:32:28 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/09/11 18:32:28 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/09/11 18:32:28 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/09/11 18:32:28 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/09/11 18:32:28 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/09/11 18:32:28 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/09/11 18:32:28 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/09/11 18:32:28 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/09/11 18:32:28 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/09/11 18:32:28 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/09/11 18:32:28 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/09/11 18:32:28 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/09/11 18:32:27 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/09/11 18:32:27 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/09/11 18:32:27 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[2013/09/11 18:32:27 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apisetschema.dll
[2013/09/11 18:32:27 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/09/11 18:32:24 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/09/09 20:29:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A-PDF Restrictions Remover
[2013/09/09 18:36:56 | 000,000,000 | —D | C] – C:\ProgramData\A-PDF
[2013/09/09 18:25:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\A-PDF Restrictions Remover
[2013/09/09 18:06:08 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\Wondershare
[2013/09/09 18:06:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wondershare
[2013/09/09 18:05:42 | 000,000,000 | —D | C] – C:\ProgramData\PDFEditor
[2013/09/09 18:05:41 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Wondershare
[2013/09/08 11:22:26 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\SparkTrust
[2013/09/08 11:22:26 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\DriverCure
[2013/09/08 11:22:14 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SparkTrust
[2013/09/08 11:22:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\SparkTrust
[2013/09/08 11:22:01 | 000,000,000 | —D | C] – C:\ProgramData\SparkTrust
[2013/09/08 11:22:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\SparkTrust
[2013/09/07 08:55:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/09/07 08:54:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2013/09/04 22:46:29 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013/09/04 22:28:28 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\C8A13589-5A4C-46D8-9394-743EDDBDAB2B.aplzod
[2013/09/04 22:24:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
[2013/09/04 22:24:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/09/04 22:24:13 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Local\Apple
[2013/09/04 22:24:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/09/04 22:24:00 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/09/04 22:24:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/09/04 22:23:47 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/09/04 22:23:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/09/04 22:15:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\JustCloud
[2013/09/03 11:54:25 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2013/09/03 11:53:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013/09/02 23:57:31 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2013/09/02 23:53:58 | 000,000,000 | —D | C] – C:\Users\Susan\AppData\Roaming\Atheros
[2013/09/02 23:53:20 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
[2013/09/02 23:53:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bluetooth Suite
[2013/08/30 16:07:22 | 000,067,192 | —- | C] (http://libusb-win32.sourceforge.net) – C:\Windows\SysWow64\libusb0.dll
[2013/08/30 15:57:34 | 000,074,872 | —- | C] (http://libusb-win32.sourceforge.net) – C:\Windows\SysNative\libusb0.dll
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/09/26 17:30:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/26 17:18:48 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 17:18:48 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 17:15:00 | 000,000,928 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-339540949-112371563-2919833766-1001UA.job
[2013/09/26 17:11:32 | 000,000,438 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.ics
[2013/09/26 17:11:00 | 000,000,286 | —- | M] () – C:\Windows\tasks\DSite.job
[2013/09/26 17:10:52 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/26 17:10:52 | 000,000,474 | —- | M] () – C:\Windows\tasks\SparkTrust Update Version3 Startup Task.job
[2013/09/26 17:10:49 | 000,000,414 | —- | M] () – C:\Windows\tasks\PC Optimizer Pro64 startups.job
[2013/09/26 17:10:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/26 17:10:41 | 3104,722,944 | -HS- | M] () – C:\hiberfil.sys
[2013/09/26 17:00:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/26 16:25:57 | 000,001,070 | —- | M] () – C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2013/09/25 20:51:14 | 000,730,384 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/25 20:51:14 | 000,627,082 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/25 20:51:14 | 000,107,366 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/25 20:24:04 | 000,000,992 | —- | M] () – C:\Users\Susan\Desktop\Jawbone Updater.lnk
[2013/09/25 20:23:12 | 000,000,824 | —- | M] () – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch Jawbone Updater.lnk
[2013/09/25 20:15:00 | 000,000,906 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-339540949-112371563-2919833766-1001Core.job
[2013/09/25 19:40:36 | 000,000,134 | —- | M] () – C:\Users\Susan\Desktop\Jawbone Support.url
[2013/09/25 19:33:45 | 000,000,464 | —- | M] () – C:\Windows\tasks\SparkTrust Registration3.job
[2013/09/25 12:59:43 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/25 12:59:42 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/22 12:08:32 | 000,000,522 | —- | M] () – C:\Windows\tasks\SparkTrust PC Cleaner Plus.job
[2013/09/21 12:52:25 | 000,000,017 | —- | M] () – C:\Users\Susan\AppData\Local\resmon.resmoncfg
[2013/09/21 12:46:44 | 000,001,747 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/17 14:08:05 | 000,014,456 | —- | M] (GFI Software) – C:\Windows\SysNative\drivers\gfibto.sys
[2013/09/16 16:02:17 | 000,002,204 | —- | M] () – C:\Users\Public\Desktop\HP Officejet Pro 8600.lnk
[2013/09/16 14:19:25 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/16 13:17:16 | 000,000,135 | —- | M] () – C:\Security_code.bat
[2013/09/15 22:31:36 | 000,000,679 | —- | M] () – C:\Users\Susan\Desktop\Therapeutic Touch.lnk
[2013/09/13 15:49:33 | 000,000,009 | —- | M] () – C:\END
[2013/09/13 00:57:09 | 000,001,051 | —- | M] () – C:\Users\Susan\Desktop\MyPC Backup.lnk
[2013/09/13 00:11:02 | 000,000,096 | —- | M] () – C:\Users\Susan\AppData\Roaming\WB.CFG
[2013/09/12 23:41:02 | 000,001,101 | —- | M] () – C:\Users\Susan\Desktop\Adobe Photoshop.lnk
[2013/09/12 22:28:21 | 000,001,063 | —- | M] () – C:\Users\Susan\Desktop\Adobe Bridge CS3.lnk
[2013/09/12 15:43:58 | 000,449,438 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/09/12 09:53:33 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2013/09/12 07:39:20 | 002,378,368 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/12 07:24:14 | 000,000,422 | —- | M] () – C:\Windows\tasks\SparkTrust Update Version3.job
[2013/09/09 22:36:17 | 000,000,200 | —- | M] () – C:\Users\Susan\Desktop\Facebook.url
[2013/09/09 21:05:09 | 000,001,097 | —- | M] () – C:\Users\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2013/09/03 11:55:06 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2013/09/02 23:58:44 | 000,000,952 | -HS- | M] () – C:\ProgramData\KGyGaAvL.sys
[2013/09/02 23:54:03 | 000,246,804 | —- | M] () – C:\Windows\SysNative\drivers\AtherosBt.bin
[2013/09/02 23:54:03 | 000,001,242 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x01.dfu
[2013/09/02 23:54:03 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40_0x02.dfu
[2013/09/02 23:54:03 | 000,001,204 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_40.dfu
[2013/09/02 23:54:03 | 000,001,198 | —- | M] () – C:\Windows\SysNative\drivers\ramps_0x01020200_26.dfu
[2013/08/31 19:24:48 | 000,449,438 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130912-154358.backup
[2013/08/31 19:23:46 | 000,012,473 | —- | M] () – C:\Windows\WinInit.Ini
[2013/08/31 17:45:01 | 000,449,438 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130831-192448.backup
[2013/08/31 14:25:30 | 000,000,301 | —- | M] () – C:\Users\Susan\Desktop\Home - Lumosity.url
[2013/08/30 16:07:22 | 000,067,192 | —- | M] (http://libusb-win32.sourceforge.net) – C:\Windows\SysWow64\libusb0.dll
[2013/08/30 15:57:34 | 000,074,872 | —- | M] (http://libusb-win32.sourceforge.net) – C:\Windows\SysNative\libusb0.dll
[2013/08/29 09:58:58 | 000,001,262 | —- | M] () – C:\Users\Susan\Desktop\Tri-City NYPS Home Page.url
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/09/26 16:25:57 | 000,001,082 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
[2013/09/26 16:25:57 | 000,001,070 | —- | C] () – C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2013/09/25 20:24:04 | 000,000,992 | —- | C] () – C:\Users\Susan\Desktop\Jawbone Updater.lnk
[2013/09/25 20:23:12 | 000,000,824 | —- | C] () – C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch Jawbone Updater.lnk
[2013/09/25 19:40:22 | 000,000,134 | —- | C] () – C:\Users\Susan\Desktop\Jawbone Support.url
[2013/09/21 12:52:25 | 000,000,017 | —- | C] () – C:\Users\Susan\AppData\Local\resmon.resmoncfg
[2013/09/21 12:46:44 | 000,001,747 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/16 16:02:17 | 000,002,204 | —- | C] () – C:\Users\Public\Desktop\HP Officejet Pro 8600.lnk
[2013/09/16 15:36:34 | 000,000,962 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2013/09/16 14:24:00 | 000,000,135 | —- | C] () – C:\Security_code.bat
[2013/09/16 14:19:25 | 000,001,073 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/15 22:30:59 | 000,000,679 | —- | C] () – C:\Users\Susan\Desktop\Therapeutic Touch.lnk
[2013/09/13 15:39:06 | 000,000,009 | —- | C] () – C:\END
[2013/09/13 00:57:09 | 000,001,051 | —- | C] () – C:\Users\Susan\Desktop\MyPC Backup.lnk
[2013/09/13 00:11:02 | 000,000,096 | —- | C] () – C:\Users\Susan\AppData\Roaming\WB.CFG
[2013/09/12 23:41:53 | 000,001,063 | —- | C] () – C:\Users\Susan\Desktop\Adobe Bridge CS3.lnk
[2013/09/12 23:41:02 | 000,001,101 | —- | C] () – C:\Users\Susan\Desktop\Adobe Photoshop.lnk
[2013/09/12 23:11:49 | 000,000,286 | —- | C] () – C:\Windows\tasks\DSite.job
[2013/09/12 22:35:36 | 000,001,101 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS3.lnk
[2013/09/12 22:32:59 | 000,001,187 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Stock Photos CS3.lnk
[2013/09/12 22:31:10 | 000,001,367 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk
[2013/09/12 22:30:49 | 000,001,156 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS3.lnk
[2013/09/12 22:28:21 | 000,001,063 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS3.lnk
[2013/09/12 09:53:33 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2013/09/08 11:22:30 | 000,000,464 | —- | C] () – C:\Windows\tasks\SparkTrust Registration3.job
[2013/09/08 11:22:13 | 000,000,474 | —- | C] () – C:\Windows\tasks\SparkTrust Update Version3 Startup Task.job
[2013/09/08 11:22:13 | 000,000,422 | —- | C] () – C:\Windows\tasks\SparkTrust Update Version3.job
[2013/09/08 11:22:08 | 000,000,522 | —- | C] () – C:\Windows\tasks\SparkTrust PC Cleaner Plus.job
[2013/09/04 22:24:09 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/09/03 11:55:06 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2013/08/31 14:25:30 | 000,000,301 | —- | C] () – C:\Users\Susan\Desktop\Home - Lumosity.url
[2013/08/29 09:58:58 | 000,001,262 | —- | C] () – C:\Users\Susan\Desktop\Tri-City NYPS Home Page.url
[2013/08/23 11:44:30 | 000,000,088 | —- | C] () – C:\Users\Susan\.java.policy
[2013/03/28 19:54:14 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2013/03/14 21:57:11 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/02/24 21:22:18 | 000,743,534 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/02/19 21:27:36 | 000,000,028 | —- | C] () – C:\Windows\ICOA.INI
[2013/02/19 21:27:22 | 000,000,000 | —- | C] () – C:\Windows\QFNONL.ini
[2013/02/19 21:27:22 | 000,000,000 | —- | C] () – C:\Windows\QFN.ini
[2013/02/19 21:27:22 | 000,000,000 | —- | C] () – C:\Windows\QDQICK.ini
[2012/12/31 20:05:30 | 000,005,776 | —- | C] () – C:\Windows\Icoadb32.dat
[2012/12/31 20:05:30 | 000,000,064 | —- | C] () – C:\Windows\QBWCD.INI
[2012/12/29 21:32:18 | 000,012,473 | —- | C] () – C:\Windows\WinInit.Ini
[2012/12/20 23:30:39 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\LXEAsmr.dll
[2012/12/20 23:30:38 | 000,299,008 | —- | C] () – C:\Windows\SysWow64\LXEAsm.dll
[2012/12/20 23:06:01 | 000,001,080 | —- | C] () – C:\Windows\maxlink.ini
[2012/12/20 23:06:01 | 000,000,020 | —- | C] () – C:\Windows\calera.ini
[2012/12/20 23:05:58 | 000,269,312 | —- | C] () – C:\Windows\SysWow64\FPXIG.DLL
[2012/12/20 23:05:58 | 000,068,096 | —- | C] () – C:\Windows\SysWow64\IGFPX32P.DLL
[2012/12/20 23:05:58 | 000,065,024 | —- | C] () – C:\Windows\SysWow64\JPEGACC.DLL
[2012/12/20 23:05:51 | 000,101,376 | —- | C] () – C:\Windows\SysWow64\WELSOF32.DLL
[2012/12/20 21:28:10 | 000,000,952 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2012/12/20 00:16:09 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/12/14 02:42:30 | 000,963,452 | —- | C] () – C:\Windows\SysWow64\igcodeckrng600.bin
[2012/12/14 02:42:30 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2012/12/14 02:42:28 | 000,272,928 | —- | C] () – C:\Windows\SysWow64\igvpkrng600.bin
[2012/01/20 00:40:35 | 000,963,116 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2012/01/20 00:40:35 | 000,218,304 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2012/01/20 00:40:31 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
========== ZeroAccess Check ==========
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/07/25 22:24:57 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/07/25 21:55:59 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 23:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/09/12 23:12:39 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
[2013/09/17 15:12:17 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Ad-Aware Antivirus
[2013/09/26 16:45:10 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Classic Start Menu
[2013/09/03 17:10:55 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\DefaultTab
[2013/09/08 11:22:26 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\DriverCure
[2013/09/16 15:10:00 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Dropbox
[2013/09/12 23:11:48 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\DSite
[2013/09/13 09:34:04 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\IObit
[2013/04/20 09:51:17 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\IrfanView
[2013/09/25 20:24:11 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\JawboneUpdater
[2013/02/18 20:35:06 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\PDFlite
[2013/09/16 14:30:22 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\PerformerSoft
[2013/01/23 22:15:27 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\PowerCinema
[2013/03/09 22:34:35 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\S300-S400 Series
[2013/09/08 12:43:41 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Screensaver
[2013/09/13 15:50:40 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\SearchProtect
[2013/09/08 12:43:40 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\ShopAtHome
[2013/09/13 00:56:56 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\SimpleFiles
[2013/09/08 11:22:26 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\SparkTrust
[2012/12/31 20:50:06 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Thunderbird
[2012/12/29 19:57:02 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\WildTangent
[2013/02/22 20:00:46 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Windows Live Writer
[2013/09/09 18:06:29 | 000,000,000 | —D | M] – C:\Users\Susan\AppData\Roaming\Wondershare
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2010/11/21 03:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2013/05/16 10:58:12 | 003,859,928 | —- | M] (Safer-Networking Ltd.) MD5=03250DB0886A23B1F6C077C5D9F152B0 – C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
[2011/07/14 01:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/07/14 01:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/07/14 01:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/07/14 01:30:29 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 23:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/07/14 01:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/07/14 01:30:29 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 23:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 03:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 03:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2013/01/08 21:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2013/07/26 02:23:39 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_16893df21e3dcd43\iexplore.exe
[2013/05/17 00:10:41 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=1423FF1BFD2ECD9CFC8C17EA4F98B20F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_0d07eadd80a334bf\iexplore.exe
[2013/08/10 02:31:28 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=1F3B062444AD6F667B5336E78D5A02B7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_ffb36d2837eafb72\iexplore.exe
[2013/02/22 03:04:50 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_0d238c71808d94e7\iexplore.exe
[2013/07/23 12:16:33 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_177836c3b4ee56e2\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_184d84e8cdd3303c\iexplore.exe
[2013/08/10 02:10:22 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D – C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/10 02:10:22 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_168ab5d61e3c99b7\iexplore.exe
[2013/08/10 00:18:11 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/08/10 00:18:11 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_20df6028529d5bb2\iexplore.exe
[2013/04/04 18:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_176a65f9b4f926ce\iexplore.exe
[2013/02/22 00:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_17f703a2ce14129d\iexplore.exe
[2013/08/10 01:13:42 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=48A1306191216997F717C451B8D15139 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_0a08177a6c4bbd6d\iexplore.exe
[2013/05/16 19:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_175c952fb503f6ba\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_20dde844529e8f3e\iexplore.exe
[2013/02/02 04:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 23:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013/07/26 01:47:06 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8D805B4EEEE0ECF6B604BE284978F135 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_ffb0112a37ee15f1\iexplore.exe
[2011/09/21 05:28:13 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2013/07/23 12:16:32 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/05/16 21:46:47 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=A1397D2A4924C390E55D146FB45FDF7C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_0df2d8da9977d637\iexplore.exe
[2013/04/04 21:55:57 | 000,763,504 | —- | M] (Microsoft Corporation) MD5=A1B0DEC3BB845C6369F97BC1A3542A07 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_0d15bba7809864d3\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/05/16 18:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_1847832ccdd89832\iexplore.exe
[2013/02/02 03:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2012/11/15 23:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/05/29 02:24:18 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=AFF2C99AD2C599108B6BD9E77C24B463 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_0d0dec99809dccc9\iexplore.exe
[2013/02/22 03:17:45 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=B21A57AA4CB928059A0C0C58A9E77A02 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_0da2595099b350a2\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2013/04/04 17:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_17e932d8ce1ee289\iexplore.exe
[2013/04/04 20:40:37 | 000,763,504 | —- | M] (Microsoft Corporation) MD5=C4A4F4AD91677DA1659A9ADE63746B8B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_0d94888699be208e\iexplore.exe
[2010/11/20 23:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/05/29 01:56:53 | 000,763,544 | —- | M] (Microsoft Corporation) MD5=C9C29508A433DAF0118D28C4F38CDDFC – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_0df8da9699726e41\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/07/26 01:09:39 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_0a04bb7c6c4ed7ec\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_176296ebb4fe8ec4\iexplore.exe
[2013/01/08 20:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/09/21 05:28:11 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2011/09/21 05:28:12 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/09/21 05:28:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/07/23 12:16:33 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-058FE8F5.PF >
[2013/09/26 17:12:10 | 000,082,178 | —- | M] () MD5=320EBFA8B741981D0346A8193B7CCA2A – C:\Windows\Prefetch\IEXPLORE.EXE-058FE8F5.pf
< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/09/26 17:12:13 | 000,184,226 | —- | M] () MD5=562DAF54CC326B57115234DD8484F6C6 – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf
< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2012/12/18 15:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.CSS >
[2011/02/07 18:44:10 | 000,000,093 | —- | M] () MD5=F15FB82C578490B209442B8C1D5076CC – C:\ProgramData\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
[2011/02/07 18:44:10 | 000,000,093 | —- | M] () MD5=F15FB82C578490B209442B8C1D5076CC – C:\Users\All Users\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
< MD5 for: SERVICES.ESM >
[2013/02/08 11:39:44 | 000,008,731 | —- | M] () MD5=A481BF1A869654B9C4B5BC8ADD636782 – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\services.esm
[2013/02/08 11:39:44 | 000,008,731 | —- | M] () MD5=A481BF1A869654B9C4B5BC8ADD636782 – C:\Users\Susan\AppData\Local\Temp\services.esm
< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 03:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.INI >
[2011/02/07 18:44:10 | 000,000,012 | —- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 – C:\ProgramData\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
[2011/02/07 18:44:10 | 000,000,012 | —- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 – C:\Users\All Users\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 03:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 03:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SBS >
[2011/03/01 00:00:00 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Includes\Services.sbs
[2011/03/01 03:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Extracts\Services.sbs
< MD5 for: SERVICES.SBS-20110301.CAB >
[2013/08/17 09:05:26 | 000,041,248 | —- | M] () MD5=149FF3413EED31253183D6E65E383138 – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Downloads\Services.sbs-20110301.cab
< MD5 for: WINLOGON.ADML >
[2010/11/21 03:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 23:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 03:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 03:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2013/09/03 11:55:06 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/01/20 00:48:00 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2013/09/13 15:49:33 | 000,000,009 | —- | M] () – C:\END
[2013/09/26 17:10:41 | 3104,722,944 | -HS- | M] () – C:\hiberfil.sys
[2013/09/26 17:10:40 | 4139,630,592 | -HS- | M] () – C:\pagefile.sys
[2013/09/16 13:17:16 | 000,000,135 | —- | M] () – C:\Security_code.bat
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/09/12 16:57:44 | 000,322,048 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is FCBE-51BF
Directory of C:\
07/14/2009 01:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 01:08 AM All Users [C:\ProgramData]
07/14/2009 01:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 01:08 AM My Music [C:\Users\Default\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 01:08 AM My Music [C:\Users\Public\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Susan
12/20/2012 12:58 AM Application Data [C:\Users\Susan\AppData\Roaming]
12/20/2012 12:58 AM Cookies [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Cookies]
12/20/2012 12:58 AM Local Settings [C:\Users\Susan\AppData\Local]
12/20/2012 12:58 AM My Documents [C:\Users\Susan\Documents]
12/20/2012 12:58 AM NetHood [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/20/2012 12:58 AM PrintHood [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/20/2012 12:58 AM Recent [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Recent]
12/20/2012 12:58 AM SendTo [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\SendTo]
12/20/2012 12:58 AM Start Menu [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Start Menu]
12/20/2012 12:58 AM Templates [C:\Users\Susan\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Susan\AppData\Local
12/20/2012 12:58 AM Application Data [C:\Users\Susan\AppData\Local]
12/20/2012 12:58 AM History [C:\Users\Susan\AppData\Local\Microsoft\Windows\History]
12/20/2012 12:58 AM Temporary Internet Files [C:\Users\Susan\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Susan\Documents
12/20/2012 12:58 AM My Music [C:\Users\Susan\Music]
12/20/2012 12:58 AM My Pictures [C:\Users\Susan\Pictures]
12/20/2012 12:58 AM My Videos [C:\Users\Susan\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 415,630,790,656 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/12/19 13:03:39 | 000,000,221 | -HS- | M] () – C:\Users\Susan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 9/26/2013 5:28:00 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Susan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.86 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 57.44% Memory free
7.71 Gb Paging File | 5.74 Gb Available in Paging File | 74.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 447.66 Gb Total Space | 387.30 Gb Free Space | 86.52% Space Free | Partition Type: NTFS
Computer Name: SUSAN-LAPTOP | User Name: Susan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04ADBB4C-7AF6-4D7B-AF34-0768469A2B67}" = rport=139 | protocol=6 | dir=out | app=system |
"{0655BDD4-69A0-4346-A5D0-1EF5DDEC65B5}" = rport=137 | protocol=17 | dir=out | app=system |
"{0953DB66-D4BB-4B0D-84A5-726122187EBC}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{103829AB-C0B2-4586-B54A-787C49A02D4B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{1587E8B4-6384-44BA-9F0C-B1B4BA9C3BB3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1CCF2D95-4329-4D9B-9B29-4926AEF53CF6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1D4749B2-9818-48DA-B455-EF3816C6CF10}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{22D9139C-7B72-48D7-915D-7A488C7CF916}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{240D2054-F4EB-4775-8492-EC2D219DB51F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{28CBABAB-7CCF-49D0-9EB9-B1B9464BB95D}" = lport=445 | protocol=6 | dir=in | app=system |
"{2E41175E-EF71-4E2C-BC85-993AD8027232}" = rport=445 | protocol=6 | dir=out | app=system |
"{3CAE88E2-5B94-4420-B55C-B2F3A94368BF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{48786DC4-2C13-4CE7-9BE9-FF1BE0F7FD0D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{52DE6EC9-DBD1-4F10-8687-DF861234EE1D}" = lport=137 | protocol=17 | dir=in | app=system |
"{53E0C3FD-1A03-4728-8F65-E70E9A4F7AF4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{563F7A25-5ED0-40F4-B513-B2AE4ABC6268}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{565B2A6F-F7CE-4AF7-857A-C91CFE4CBF44}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{59771679-9C78-489D-A4BF-605FC2989EB5}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5D45432B-ACDF-4888-B65E-FD0106680959}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{8040034F-BBC8-4E52-860C-C1072FCA8988}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{83C2C555-7811-480D-8AF0-EB4CE6CD6F22}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{8BDFCAD1-639C-4C9B-9C41-D7B6AA2B78FF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8C37143E-8856-47F1-A091-A95C00C0195F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{912DBC3A-1CE8-4BE0-90D7-141BF33256DF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{94984184-9930-439E-8AE7-5AC05F21B246}" = lport=139 | protocol=6 | dir=in | app=system |
"{94DC1D7C-0A37-4CED-9FB0-E18B61A65580}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{9DB9D098-D9F0-4390-99A2-CEB705E400D1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{A17E0438-39E8-4F66-BA46-109950352263}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A2909244-AECC-4FF6-92AE-5B492F2F0E98}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A490E5AA-978A-42C3-B2F3-118F3CE66F4C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{A5F5DDF7-F8A8-4EC3-8414-85A59FF22B86}" = rport=10243 | protocol=6 | dir=out | app=system |
"{A6043D55-19EC-40BD-9412-365A0CCDAB1E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{A8A7223A-0FD9-43E4-A2C4-CCD00159BDEB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A8F0334E-E6C7-45BE-967B-76B9FD419461}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{ACE31730-7205-4194-B020-0822E5F07C14}" = rport=2869 | protocol=6 | dir=out | app=system |
"{AD8DC53A-A9DC-4212-91EA-CC2FDB2F024B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{B2B22AF5-7570-45FA-B076-DA0D7F0BD9DB}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{B4D9D840-E8AE-46D1-B7F0-D313095B400C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B67BCCF7-7BCD-4796-9DB3-C39DC31759A6}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{BEE12C76-8AB5-449B-94BE-086C631CF5AF}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{C050273D-685E-4EFF-ABD1-E391A1E551E2}" = lport=138 | protocol=17 | dir=in | app=system |
"{C5A1AF50-5957-45AF-A264-395CD7F6C4F7}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{C8EB1666-4856-4D42-AF60-A050514CEAE6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D1C9EA4C-23EF-4FEA-8FB8-993192586501}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe |
"{D87FDA28-3F37-4A4D-81D8-9A6FB39A8E12}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{EB945A89-E557-4A2E-A7DB-925B8F2D114A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F2CD2323-9A4F-4D1C-98DC-4EF964F9BEED}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F3B4A808-CDCB-46E7-81EE-2FE9D985CD9F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{FB4FAAF2-31E1-4EC9-A846-AFD2405DA323}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FEB8215A-DACB-475F-AA05-AAF8AC27A90A}" = rport=138 | protocol=17 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{11D2C4A2-AAF5-48E1-9D42-00800D17C737}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{1798807A-A26B-4523-889A-0BC2BE91EB30}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\clear.fi.exe |
"{17D0105F-1C5B-4EF1-8DC2-CD8C7B912B2D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{18C41018-A446-469A-B1BB-83BAD709722C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{1F4868F0-9432-4B76-BD47-C7BD116592A9}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{26174917-C0AC-4203-B1C4-C0C81538EE91}" = dir=in | app=c:\program files (x86)\acer\clear.fi\movie\touchmovieservice.exe |
"{2844BF72-4BCE-4019-AE0C-49BC0A2B8056}" = protocol=6 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
"{285DD813-9C47-4771-ADEC-5C6CDA2A0380}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{289AD9CA-8065-4F94-B586-AEBC10F2880A}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\dmr\dmrengine.exe |
"{2ADC2F64-F701-4A5E-B55B-4C014F1DD869}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\clml\clmlsvc.exe |
"{2E60C048-0FDB-4EDC-BEE1-652C7A988E45}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{31E69CEB-7748-4E2E-A128-2F8CAF14B05A}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\hpnetworkcommunicatorcom.exe |
"{34017392-28E2-4EDA-8719-85D0B9C83985}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{368DA8DD-91A4-41A5-BF52-83FD72F538FA}" = dir=in | app=c:\program files (x86)\acer\clear.fi\movie\touchmovie.exe |
"{3797BE0B-89EF-4416-93F5-69ED65B864F6}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3B5B95C9-A3A3-4236-A8C6-D900470BDA16}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3EAF1F1C-1F4B-40E5-835E-D339FC80CE77}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{40BE7B8E-E512-448D-A4E6-DF5D0582C5ED}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\dmr\dmrengine.exe |
"{459850D3-A87F-4BB9-A0E6-DFCB6523B504}" = protocol=6 | dir=in | app=c:\program files (x86)\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{4801BD53-49D9-4F9F-ABF8-3FF1F0A0B38B}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\sendafax.exe |
"{4A903D21-17F6-4BDA-8171-D98287F62568}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\clear.fiagent.exe |
"{4E504EF7-FAEA-4C86-8F8D-331C37E745C3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{52B55AEB-DA98-455D-9C86-437FADE13287}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{55DE6B54-0A44-4407-AEDB-E82181262E85}" = protocol=6 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"{5677A918-D05E-4C36-AAB9-279CC635438F}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{57D6C992-4354-4A0C-B35A-79B7226437F4}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\faxapplications.exe |
"{5D84BF12-AEEA-4F67-9211-608EEE6B6EC2}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5E688360-D8B0-47C9-AE94-BC6EB49D4225}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5EE9B8E3-DA39-4E11-BC9D-77B4F38D209E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{62640CE0-1790-4849-B6ED-796C280E751A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6324D973-F1B3-40AD-AD2D-5FF6215193FF}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6468C0E8-0F22-42A9-8FFA-3C13A8CC87BC}" = protocol=17 | dir=in | app=c:\program files (x86)\lexmark s300-s400 series\lxeafax.exe |
"{72F17001-A320-4804-BA2C-37C3C9755D25}" = protocol=17 | dir=in | app=c:\program files (x86)\lavasoft\adaware securesearch toolbar\dtuser.exe |
"{7A9AFF25-E7DA-41D4-8ABC-22402C51CCE4}" = protocol=17 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{7D5E3D26-FFF4-429C-99DF-7B82B969E0FC}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\devicesetup.exe |
"{868A15F4-4187-4582-B110-4EAFC1AB37D6}" = protocol=17 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
"{86CEFCAF-D8B1-4C7D-8265-BE2B397B52EA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8BD56F8C-7C58-4110-8A74-E8A93110E500}" = protocol=17 | dir=in | app=c:\program files (x86)\simplefiles\simplefiles.exe |
"{91066994-DD64-4D89-BE32-F1226A9E9224}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{921208FF-AFD1-429F-A0AF-ECC6A9BCA0B4}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{987ACC97-B356-497B-BB12-11C1B9FF37FC}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{9FCFF30C-A524-4E0C-AFF4-6F1B1E64B37D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A0F57050-B9F0-4F2F-B0CC-CADEE3F99E35}" = dir=in | app=c:\program files (x86)\acer\clear.fi\mvp\kernel\dmr\dmrengine.exe |
"{A4C6F67D-AA9B-4AD0-96FC-3765A2356B24}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\hpnetworkcommunicator.exe |
"{A675D738-1C44-4394-98CA-0E733C8B6178}" = protocol=6 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{A7C3D687-D3FD-417A-B5A3-89486A8D2FAF}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B29370D5-4B84-4ACF-8BDD-9F9C6C91C685}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B2FA67B0-FB9A-4EBB-8FC5-B05E946CC65B}" = protocol=17 | dir=in | app=c:\program files (x86)\simplefiles\downloader.exe |
"{BA92A40C-9C4C-4A3C-A1B3-6A171C9E1652}" = protocol=6 | dir=in | app=c:\program files (x86)\lexmark s300-s400 series\lxeafax.exe |
"{BCD7CB3C-580B-4ABE-9F0F-E690DDAF1758}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C7D22EA8-5073-4B43-89AA-498EA213AA02}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C97C7C90-3DE7-4464-9E49-FB0FCCCC2B5C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CF115154-EC6E-4A85-845C-E1168C7C52CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CFD94CF5-3F07-4EA1-82BD-90F0566ECF87}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\digitalwizards.exe |
"{D1151BEE-8FE2-4045-B2F4-6447CAA17297}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{D44AB640-8F9D-4E61-B9DC-2C501E65F2C1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D8534F44-A8A1-4043-A30B-8B1BE8C6618D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D88BD773-B41F-475C-97B7-1B29712E751F}" = dir=in | app=c:\users\susan\appdata\local\microsoft\skydrive\skydrive.exe |
"{DC354CBE-8D61-4ECD-8A3C-62ED6DCA519A}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{E1F11D89-EA69-4D6C-9212-0797B8BC99FF}" = protocol=17 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"{E3A16DF7-CE0B-43B1-9601-540398DD106A}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E4CD7981-12CA-41A1-9322-CDB53688C9CF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E8F5F337-4024-4A29-BF21-08CB5276F918}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{EB7DA30E-79FE-4D16-B9BA-35AB87503334}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{EC669960-6E47-40D7-8394-E5D0DFA90015}" = protocol=6 | dir=in | app=c:\program files (x86)\simplefiles\downloader.exe |
"{EF241424-B752-4C0D-B79B-FA3825839A03}" = protocol=6 | dir=out | app=system |
"{F54A5837-10C2-41D7-857F-907A23A36A3F}" = protocol=6 | dir=in | app=c:\program files (x86)\simplefiles\simplefiles.exe |
"{FA535685-A8C8-4FBA-BAA4-7DC8B8AA9C32}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{0CE6D6AC-D73D-4E75-A0C1-E26F9F9979B0}C:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{4FF125F4-839A-4BE5-8833-E5D021F4C9AF}C:\users\susan\downloads\pess20setup2.exe" = protocol=6 | dir=in | app=c:\users\susan\downloads\pess20setup2.exe |
"TCP Query User{74FA084B-532D-4DBB-A2A5-76F92B73D622}C:\program files (x86)\jawbone\jawboneupdater.exe" = protocol=6 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"TCP Query User{B3585CA0-C294-42BE-A77F-A73873C1386F}C:\program files (x86)\scansoft\paperport\navbrowser.exe" = protocol=6 | dir=in | app=c:\program files (x86)\scansoft\paperport\navbrowser.exe |
"UDP Query User{0A545F58-1361-44BB-B067-9E06734688FC}C:\users\susan\downloads\pess20setup2.exe" = protocol=17 | dir=in | app=c:\users\susan\downloads\pess20setup2.exe |
"UDP Query User{609EC151-04A1-46AE-9E8A-A59EAEDC3014}C:\program files (x86)\scansoft\paperport\navbrowser.exe" = protocol=17 | dir=in | app=c:\program files (x86)\scansoft\paperport\navbrowser.exe |
"UDP Query User{660A59DF-A7A2-4916-A3CF-F77FEC253D68}C:\program files (x86)\jawbone\jawboneupdater.exe" = protocol=17 | dir=in | app=c:\program files (x86)\jawbone\jawboneupdater.exe |
"UDP Query User{B9E7DF9A-F196-4E94-984F-4A53ED569BC7}C:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\susan\appdata\roaming\dropbox\bin\dropbox.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{2BF5E9CC-C55D-4B0F-ACAF-FFE77F333CD8}" = HP Officejet Pro 8600 Product Improvement Study
"{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}" = Apple Mobile Device Support
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{4710662C-8204-4334-A977-B1AC9E547819}" = Broadcom Card Reader Driver Installer
"{4F917ED3-B077-4C7F-97D5-DDD59D3F4D7C}" = ActiveKEY_X64
"{5F611ADA-B98C-4DBB-ADDE-414F08457ECF}" = Windows Live Family Safety
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{791A06E2-340F-43B0-8FAB-62D151339362}" = HP Officejet Pro 8600 Basic Device Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{C91DCB72-F5BB-410D-A91A-314F5D1B4284}" = Broadcom NetLink Controller
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{E990722F-10AA-4A1A-9107-EAC5EE2CEC38}" = AKeyPCSyncClient_X64
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}" = iCloud
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6822EFD-3F7D-4B35-8845-757A26AEC8E2}" = Windows Live MIME IFilter
"{F73A118B-8271-47E2-8790-0C636B2539C5}" = iTunes
"{FEA1590B-540A-41FC-A95C-664493C82A21}" = Classic Shell
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 8.0.6.3_WHQL
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MyPC Backup" = MyPC Backup
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Office
"{01944037-D136-45EE-A007-403EAD929FC7}" = Windows Live Writer
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{061FF8F3-5226-4278-8AAB-282C1B024F58}" = Photo Common
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0AD576A7-EDCE-469E-ADD7-1AC9DB200C6B}" = Windows Live Mail
"{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Backup Manager V3
"{0EAD5B5C-534A-4486-8ECB-679E218ADEE1}" = Hi-Speed USB Bridge-Network Cable
"{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}" = Microsoft Application Compatibility Toolkit 5.6
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{10812DE7-2E57-4740-B226-6B3BE34AF9D7}" = Lexmark Tools for Office
"{13F3CEA5-9E2C-4C4E-9F0F-D0DB389CF4A9}" = Movie Maker
"{14C4C3B6-F1F4-401F-8C86-03E8E19AAC8C}" = clear.fi
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{17D26CDD-B87C-412B-92F0-2D5DD4313522}" = Facebook Messenger 2.1.4651.0
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack
"{184A0D4F-4BCF-40EF-A73C-F0313FDB5CCD}" = Windows Live Messenger
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}" = Windows Live Messenger
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FEE19BC-6F0C-42E4-82FF-FB597F6141DF}" = Windows Live Essentials
"{23170F69-40C1-2701-0921-000001000000}" = 7-Zip 9.21
"{23A3E560-069F-4CFC-8F6C-1B526EC735FC}" = Windows Live Writer Resources
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}" = Evernote v. 4.5.1
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2AEAFC79-79E6-4784-9CF9-D9D82932BF88}" = Windows Live Family Safety
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{35827710-D042-428B-A1E5-E20E12D2FEB9}" = SparkTrust PC Cleaner Plus
"{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}" = Corel Office
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3C63F944-803E-49A7-B3A2-B8AB3313E883}" = Windows Live UX Platform Language Pack
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{43AAE145-83CF-4C96-9A5E-756CEFCE879F}" = clear.fi Client
"{446CC8CE-0E90-44F7-ADD0-774B243EF090}" = Galerie de photos
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5524D7D3-FA5C-4AF7-8EB3-6FEA0D455326}" = Corel Office - Templates
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{66E13170-6BB6-48D0-97F1-511D11E3B01F}" = Corel Office
"{69D48C91-CCC2-4305-89DE-D1F8122EDBF4}" = Photo Common
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6C41841F-0ED6-4A78-BD19-B188726D2D80}" = Hi-Speed USB-USB Network Cable
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{70853C06-F097-452E-B090-682D8584551D}" = Corel Office - IPM
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B0C5EF6-DE4C-4E20-8889-C17604FFE5CD}" = Windows Live Family Safety
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8030AE22-7FA0-4880-A538-8906EDBF49F4}" = Windows Live Writer Resources
"{82BF2C5E-79A7-4A13-B508-D5E64A5B141E}" = Uninstall Helper
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86C40513-B5A4-476E-9EAB-EC118DCF4502}" = Windows Live Writer
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8AAEB5A5-A397-46B6-8AF3-B6DC790C4E48}" = Windows Live Messenger
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8D813AFF-D91D-4EE0-821F-B901FC2E89FA}" = Windows Live
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8F7FECEC-088F-431D-A5FB-2B59E1E69943}" = Galería de fotos
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90993BD9-C7D9-4C2F-B56C-2F7AFEBD4CD0}" = Windows Live UX Platform Language Pack
"{936F0E9D-5FCC-462F-B538-8D55C84EA326}" = AKeyPCSyncClient
"{944167EA-7F89-4705-8DCD-1D63B53141B0}" = Ad-Aware Antivirus
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007A-0416-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{96914829-DF65-40AE-8A31-6F3E96BAEBBD}" = Windows Live Mail
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}" = Windows Live Writer
"{99AA6730-54CD-4B9E-B05B-0A5196743923}" = Windows Live UX Platform Language Pack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A17946CA-18E5-4CF0-8D55-A56D804718F8}" = Movie Maker
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A2E5F2AA-2996-41EA-BCCD-9FD0476A5326}" = TWC Customer Controls
"{A5DC64EE-2FC4-4C35-9975-639DD8499369}" = Windows Live Family Safety
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{B20502AB-2A3F-48F9-AD09-9FB61689A6D4}" = Windows Live Writer
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B77D2795-23C0-4DBD-B7B5-CFB542D1FA3F}" = Windows Live Writer Resources
"{B80D3EA9-A252-4AE5-AC51-81729F5C586F}" = Windows Live Mail
"{B906C11A-D193-4143-9FA7-E2EE8A5A8F21}" = clear.fi
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}" = Dolby Advanced Audio v2
"{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials
"{C08D0804-1DB0-4375-AF23-7120F4C121E1}" = Windows Live Family Safety
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C32D87E1-6310-4CD5-8D6D-865AFE0E9B4E}" = Movie Maker
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C595F480-788A-4F8F-8277-1A91F32CA879}" = Windows Live Writer
"{C5CFE150-86C1-4D7C-B07B-9023A62628DC}" = honestech Easy Video Editor
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D28FDA7D-15C6-48A2-9868-6BCB28BE6254}" = Microsoft Picture It! Photo 2001
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark Printable Web
"{D322A9E3-758B-4D60-A7C4-65C88FD378D0}" = Bing Bar
"{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common
"{D9D4D271-609F-440D-A9EC-A66B0815CFE2}" = Windows Live Essentials
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB169E8F-5332-4DBF-B085-84AA2C373304}" = Windows Live Messenger
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DDFF51C0-A729-49E2-B777-8432C0F74FD9}" = Windows Live Mail
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E74EA3B1-7192-489D-9A57-0AE918FEC001}" = Corel Office - Launcher
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F341F73D-0D6E-4D37-995D-74F28EBD406C}" = Windows Live Writer Resources
"{F5248B7E-779A-4FA4-8134-D1933D8680FA}" = Galeria de Fotos
"{F54030F3-14B6-432D-9361-78DCB1473920}" = Photo Common
"{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"adawaretb" = Ad-Aware Security Add-on
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"Adobe AIR" = Adobe AIR
"Adobe Creative Cloud" = Adobe Creative Cloud
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Advanced SystemCare Ultimate_is1" = Advanced SystemCare Ultimate 6
"A-PDF Restrictions Remover_is1" = A-PDF Restrictions Remover
"Bookkeeping for Realtors_is1" = Bookkeeping for Realtors 2.1.1
"Classic Start Menu_is1" = Classic Start Menu 3.88
"Coupon Printer for Windows5.0.0.3" = Coupon Printer for Windows
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"Identity Card" = Identity Card
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Acer Backup Manager
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi
"InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"InstallWIX_{D0702EE9-9DE4-419A-9C6C-4730B1C985BA}" = Kaspersky PURE 3.0
"IrfanView" = IrfanView (remove only)
"Jawbone Updater" = Jawbone Updater
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mozilla Firefox 19.0 (x86 en-US)" = Mozilla Firefox 19.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"PaperPort 7.02" = PaperPort 7.02
"PC Essentials 20 Digital Download" = PC Essentials 20 Digital Download
"PDFlite" = PDFlite 0.8
"QuickBooks" = QuickBooks
"Shockwave" = Shockwave
"ShopAtHome.com Helper" = ShopAtHome.com Helper
"Uninstall Helper 2.0.1.0" = Uninstall Helper
"Un-Zip for Windows" = Un-Zip for Windows 9.22beta
"WinLiveSuite" = Windows Live Essentials
"zipForm6" = zipForm6
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"DSite" = Update for Image Editor
"Image Editor Packages" = Image Editor Packages
"jZip" = jZip
"SkyDriveSetup.exe" = Microsoft SkyDrive
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/17/2013 7:32:16 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 7042
Description =
Error - 9/17/2013 7:32:16 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 9002
Description =
Error - 9/17/2013 7:32:16 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3029
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3029
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3028
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 3058
Description =
Error - 9/17/2013 7:32:29 PM | Computer Name = Susan-Laptop | Source = Windows Search Service | ID = 7010
Description =
Error - 9/17/2013 7:33:15 PM | Computer Name = Susan-Laptop | Source = WinMgmt | ID = 10
Description =
Error - 9/17/2013 7:35:26 PM | Computer Name = Susan-Laptop | Source = Application Hang | ID = 1002
Description = The program IEXPLORE.EXE version 10.0.9200.16686 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: f4c Start
Time: 01ceb3fe2fdd0d3f Termination Time: 56 Application Path: C:\Program Files (x86)\Internet
Explorer\IEXPLORE.EXE Report Id:
Error - 9/18/2013 9:23:29 AM | Computer Name = Susan-Laptop | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 7/23/2013 3:40:08 PM | Computer Name = Susan-Laptop | Source = DCOM | ID = 10005
Description =
Error - 7/23/2013 3:40:32 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:40:32 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:41:30 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:42:17 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:42:17 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:42:21 PM | Computer Name = Susan-Laptop | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 7/23/2013 3:43:43 PM | Computer Name = Susan-Laptop | Source = ipnathlp | ID = 34001
Description =
Error - 7/23/2013 3:43:43 PM | Computer Name = Susan-Laptop | Source = ipnathlp | ID = 30013
Description =
Error - 7/23/2013 3:44:26 PM | Computer Name = Susan-Laptop | Source = DCOM | ID = 10016
Description =
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:10:19 PM, on 9/26/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\ProgramData\Search Protection\SearchProtection.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Jawbone\JawboneUpdater.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Susan\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
O2 - BHO: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: (no name) - {6C8DB2EC-499B-4897-A784-0E3186C97E9D} - (no file)
O2 - BHO: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O2 - BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Kaspersky Passsword Manager Toolbar - {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\PROGRA~2\KASPER~1\KASPER~1.0\KASPER~2\spIEBho.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O3 - Toolbar: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
O3 - Toolbar: Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
O4 - HKLM\..\Run: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" –showwindow=false –onOSstartup=true
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O4 - Startup: Launch Jawbone Updater.lnk = ?
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
O9 - Extra 'Tools' menuitem: Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
O9 - Extra button: (no name) - {64964764-1101-4bbd-8891-B56B1A53B9B3} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} (iCloud Web App Plugin) - https://www.icloud.com/system/iCloud.cab
O16 - DPF: {9C65AB3E-C9A8-4789-AE24-B365A1C4A6F9} (SNRet Control) - http://acer.custhelp.com/euf/assets/activex/snret.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0204621355979526) (0204621355979526mcinstcleanup) - Unknown owner - C:\Windows\TEMP\020462~1.EXE (file missing)
O23 - Service: Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Ad-Aware (SBAMSvc) - GFI Software - C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 14073 bytes
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16686 BrowserJavaVersion: 10.25.2
Run by [removed] at 18:11:56 on 2013-09-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3948.1837 [GMT -4:00]
.
AV: Kaspersky PURE 3.0 *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Lavasoft Ad-Aware *Enabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AV: Advanced SystemCare Ultimate *Disabled/Updated* {1C304DC4-1D72-5DB9-B33A-43B638ECFD30}
SP: Kaspersky PURE 3.0 *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Aware *Enabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
FW: Kaspersky PURE 3.0 *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\ProgramData\Search Protection\SearchProtection.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Jawbone\JawboneUpdater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_175_ActiveX.exe
C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\EgisTec IPS\PMMUpdate.exe
C:\Program Files\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\sysWow64\SearchProtocolHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
mStart Page = hxxp://www.google.com
mWinlogon: Userinit = userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} -
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
BHO: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
BHO: {6C8DB2EC-499B-4897-A784-0E3186C97E9D} -
BHO: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\OnlineBanking\online_banking_bho.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
BHO: Advanced SystemCare Browser Protection: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\BrowerProtect\ASCPlugin_Protection.dll
BHO: Lexmark Printable Web: {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
TB: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
TB: Kaspersky Passsword Manager Toolbar: {215BA832-75A3-426E-A4FC-7C5B58CE6A10} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\Kaspersky Password Manager\spIEBho.dll
TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
TB: Ad-Aware Security Add-on: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
TB: Bing Bar: {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
uRun: [ABBYY Screenshot Reader Retail]
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe"
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" –showwindow=false –onOSstartup=true
dRunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid}
StartupFolder: C:\Users\Susan\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Launch Jawbone Updater.lnk - C:\Program Files (x86)\Jawbone\LaunchJU.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ie_banner_deny.htm
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
DPF: {9C65AB3E-C9A8-4789-AE24-B365A1C4A6F9} - hxxp://acer.custhelp.com/euf/assets/activex/snret.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{F5F8F2C6-F64E-450C-B3D8-EE32F9DF7453} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{F5F8F2C6-F64E-450C-B3D8-EE32F9DF7453}\7594C48454C4D435 : DHCPNameServer = 192.168.10.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck -
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
x64-mStart Page = hxxp://start.mysearchdial.com/?f=1&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=
x64-BHO: ExplorerBHO Class: {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
x64-BHO: ClassicIE9BHO Class: {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll
x64-TB: Classic Explorer Bar: {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
x64-IE: {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe
x64-IE: {64964764-1101-4bbd-8891-B56B1A53B9B3} - {553891B7-A0D5-4526-BE18-D3CE461D6310}
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} -
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck -
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\
FF - prefs.js: browser.search.selectedEngine - SecureSearch
FF - prefs.js: browser.startup.homepage - hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id;=adawaretb&v;=3_4&ent;=hp&u;=3B401CF1803A95D10E932752389BB7A3
FF - prefs.js: keyword.URL - hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id;=adawaretb&v;=3_4&hsimp;=yhs-lavasoft&ent;=bs&q;=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\PDFlite\npPdfViewer.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-08-29 21:57; [removed]; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\[removed]
FF - ExtSQL: 2013-09-09 21:59; {ad9a41d2-9a49-4fa6-a79e-71a0785364c8}; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
FF - ExtSQL: 2013-09-12 07:30; [removed]; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\[removed]
FF - ExtSQL: 2013-09-13 16:05; {7e8a1050-cf67-4575-92df-dcc60e7d952d}; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}
FF - ExtSQL: 2013-09-13 16:05; {465fcfbb-47a4-4866-a5d5-d12f9a77da00}; C:\Users\Susan\AppData\Roaming\Mozilla\Firefox\Profiles\pklkns8n.default\extensions\{465fcfbb-47a4-4866-a5d5-d12f9a77da00}
.
—- FIREFOX POLICIES —-
FF - user.js: extensions.mysearchdial.hmpg - true
FF - user.js: extensions.mysearchdial.hmpgUrl - hxxp://start.mysearchdial.com/?f=1&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=
FF - user.js: extensions.mysearchdial.dfltSrch - true
FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial
FF - user.js: extensions.mysearchdial.dnsErr - true
FF - user.js: extensions.mysearchdial_i.newTab - false
FF - user.js: extensions.mysearchdial.newTabUrl - hxxp://start.mysearchdial.com/?f=2&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=
FF - user.js: extensions.mysearchdial.tlbrSrchUrl - hxxp://start.mysearchdial.com/?f=3&a;=dnld2msd&cd;=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2Xzut
BtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr;=1399021852&ir;=&q;=
FF - user.js: extensions.mysearchdial.id - B888E303260C51BF
FF - user.js: extensions.mysearchdial.instlDay - 15957
FF - user.js: extensions.mysearchdial.vrsn -
FF - user.js: extensions.mysearchdial.vrsni -
FF - user.js: extensions.mysearchdial_i.vrsnTs - 18:25:52
FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial
FF - user.js: extensions.mysearchdial.prdct - mysearchdial
FF - user.js: extensions.mysearchdial.aflt - dnld2msd
FF - user.js: extensions.mysearchdial_i.smplGrp - none
FF - user.js: extensions.mysearchdial.tlbrId - base
FF - user.js: extensions.mysearchdial.instlRef -
FF - user.js: extensions.mysearchdial.dfltLng -
FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
FF - user.js: extensions.mysearchdial.excTlbr - false
FF - user.js: extensions.mysearchdial_i.hmpg - true
FF - user.js: extensions.mysearchdial.cr - 1399021852
FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtF
yEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q
FF - user.js: extensions.irmysearch.aflt - dnld2msd
FF - user.js: extensions.irmysearch.instlRef -
FF - user.js: extensions.irmysearch.cr - 1399021852
FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtAtDtAtByCtD0CyDtC0B0FtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtF
yEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q
.
.
.
.
.
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - fcbe51bf00000000000008edb91380fe
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15961
FF - user.js: extensions.delta.vrsn - [removed]
FF - user.js: extensions.delta.vrsni - [removed]
FF - user.js: extensions.delta.vrsnTs - [removed]:56:11
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=123639&tsp;=5004
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R0 CSCrySec;InfoWatch Encrypt Sector Library driver;C:\Windows\System32\drivers\CSCrySec.sys [2013-7-23 84536]
R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2013-2-23 14456]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;C:\Windows\System32\drivers\CSVirtualDiskDrv.sys [2013-7-23 66616]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2012-8-2 28504]
R1 kltdi;kltdi;C:\Windows\System32\drivers\kltdi.sys [2012-10-18 54368]
R1 kneps;kneps;C:\Windows\System32\drivers\kneps.sys [2012-8-13 178448]
R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2012-1-20 22648]
R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2012-1-20 20520]
R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2012-1-20 62776]
R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2013-6-13 1236336]
R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [2012-12-20 356968]
R2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]
R2 sbapifs;sbapifs;C:\Windows\System32\drivers\sbapifs.sys [2012-9-12 82872]
R3 b57xdbd;Broadcom xD Picture Bus Driver Service;C:\Windows\System32\drivers\b57xdbd.sys [2011-1-20 67624]
R3 b57xdmp;Broadcom xD Picture vstorp client drv;C:\Windows\System32\drivers\b57xdmp.sys [2011-1-20 19496]
R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE [2013-7-23 240288]
R3 bScsiMSa;bScsiMSa;C:\Windows\System32\drivers\bScsiMSa.sys [2011-5-16 51240]
R3 bScsiSDa;bScsiSDa;C:\Windows\System32\drivers\bScsiSDa.sys [2011-5-6 86056]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-9-16 30368]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2012-1-20 142632]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-5-10 425000]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\drivers\klkbdflt.sys [2012-9-3 29016]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2012-9-3 29528]
S2 0204621355979526mcinstcleanup;McAfee Application Installer Cleanup (0204621355979526);C:\Windows\TEMP\020462~1.EXE C:\PROGRA~2\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> C:\Windows\TEMP\020462~1.EXE C:\PROGRA~2\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.EXE [2013-7-23 193696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-9-16 36000]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2012-3-2 138280]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-9-16 330912]
S3 btath_avdt;Atheros Bluetooth AVDT Service;C:\Windows\System32\drivers\btath_avdt.sys [2011-9-16 110240]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-9-16 167584]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-9-16 68256]
S3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-9-16 280992]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-1-2 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 gfiark;gfiark;C:\Windows\System32\drivers\gfiark.sys [2013-2-24 39504]
S3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-1-20 317440]
S3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 07/08/2013,1.2.6.1;C:\Windows\System32\drivers\libusb0.sys [2012-11-29 52320]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-2-24 25928]
S3 PhSerUsb;Enfora Enabler IIIG USB Driver;C:\Windows\System32\drivers\PhSerUsb.sys [2010-7-7 71416]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-12-20 1255736]
S4 AdvancedSystemCareService6;Advanced SystemCare Service 6;C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCSvc.exe [2013-9-12 1051088]
S4 AKeyPCSyncService;ActiveKEY PCSync Service;C:\Supra\AKeyPCSyncClient\AKeyPCSyncService.exe [2010-8-4 107832]
S4 ASCAntivirusSrv;AdvancedSystemCareAntivirus;C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe [2013-9-12 623936]
S4 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-9-16 105120]
S4 BackupStack;Computer Backup (MyPC Backup);C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2013-7-1 32808]
S4 CSObjectsSrv;CryptoStorage control service;C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2012-12-21 819040]
S4 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2012-1-20 353360]
S4 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2011-6-21 173424]
S4 ePowerSvc;ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2012-4-14 872552]
S4 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S4 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2011-5-29 36456]
S4 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-1-20 13592]
S4 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2012-1-20 244624]
S4 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-2-24 418376]
S4 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-2-24 701512]
S4 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-4-23 256832]
S4 SDScannerService;Spybot-S&D; 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-8-9 1817560]
S4 SDUpdateService;Spybot-S&D; 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-8-9 1033688]
S4 SDWSCService;Spybot-S&D; 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-8-9 171928]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
.
=============== Created Last 30 ================
.
2013-09-26 00:23:12 ——– d—–w- C:\Users\Susan\AppData\Roaming\JawboneUpdater
2013-09-26 00:23:12 ——– d—–w- C:\Program Files (x86)\Jawbone
2013-09-24 02:33:05 262552 —-a-w- C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2013-09-24 02:33:01 26520 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-09-21 16:45:57 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-21 16:45:57 ——– d—–w- C:\Program Files\iTunes
2013-09-21 16:45:57 ——– d—–w- C:\Program Files\iPod
2013-09-21 16:45:57 ——– d—–w- C:\Program Files (x86)\iTunes
2013-09-17 18:26:18 ——– d—–w- C:\Users\Susan\AppData\Roaming\LavasoftStatistics
2013-09-17 18:26:18 ——– d—–w- C:\ProgramData\Ad-Aware Antivirus
2013-09-17 18:14:45 ——– d—–w- C:\Program Files (x86)\Ad-Aware Antivirus
2013-09-17 18:13:54 ——– d—–w- C:\ProgramData\Search Protection
2013-09-17 18:13:50 ——– d—–w- C:\ProgramData\blekko toolbars
2013-09-17 18:13:49 ——– d—–w- C:\Users\Susan\AppData\Local\adawarebp
2013-09-17 18:13:47 ——– d—–w- C:\ProgramData\Ad-Aware Browsing Protection
2013-09-17 18:13:40 ——– d—–w- C:\Program Files (x86)\Toolbar Cleaner
2013-09-17 18:13:13 ——– d—–w- C:\Program Files (x86)\Lavasoft
2013-09-17 18:08:06 47496 —-a-w- C:\Windows\System32\sbbd.exe
2013-09-17 18:08:04 ——– d—–w- C:\Users\Susan\AppData\Roaming\Ad-Aware Antivirus
2013-09-17 17:23:11 9694160 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A870E8F7-A4B4-47BC-A420-C018391BDD51}\mpengine.dll
2013-09-17 00:46:14 ——– d—–w- C:\A-Scans
2013-09-16 20:02:18 741480 ——w- C:\Windows\System32\HPDiscoPM5912.dll
2013-09-16 20:01:50 ——– d—–w- C:\Program Files\HP
2013-09-16 18:24:00 135 —-a-w- C:\Security_code.bat
2013-09-16 02:20:56 ——– d—–w- C:\A-TT
2013-09-13 19:49:35 ——– d—–w- C:\Users\Susan\AppData\Roaming\PerformerSoft
2013-09-13 19:49:28 ——– d—–w- C:\Program Files (x86)\7Go Games
2013-09-13 19:49:22 ——– d—–w- C:\Program Files (x86)\PC Performer
2013-09-13 19:49:22 ——– d—–w- C:\Program Files (x86)\ffdshow
2013-09-13 19:40:22 ——– d—–w- C:\ProgramData\Conduit
2013-09-13 19:40:18 ——– d—–w- C:\Program Files (x86)\SweetPacks
2013-09-13 19:40:01 ——– d—–w- C:\Users\Susan\AppData\Local\CRE
2013-09-13 19:39:42 ——– d—–w- C:\Program Files (x86)\SearchProtect
2013-09-13 19:39:37 ——– d—–w- C:\Users\Susan\AppData\Roaming\SearchProtect
2013-09-13 19:38:09 ——– d—–w- C:\Program Files (x86)\BrowseFox
2013-09-13 04:57:08 ——– d—–w- C:\Program Files (x86)\MyPC Backup
2013-09-13 04:56:02 ——– d—–w- C:\ProgramData\DSearchLink
2013-09-13 04:55:44 ——– d—–w- C:\ProgramData\Babylon
2013-09-13 04:54:57 ——– d—–w- C:\Users\Susan\AppData\Roaming\SimpleFiles
2013-09-13 03:43:55 ——– d—–w- C:\Users\Susan\AppData\Roaming\Intel Corporation
2013-09-13 03:12:39 ——– d—–w- C:\Users\Susan\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
2013-09-13 03:11:48 ——– d—–w- C:\Users\Susan\AppData\Roaming\DSite
2013-09-13 03:11:47 ——– d—–w- C:\Program Files (x86)\Image Converter
2013-09-12 14:54:30 ——– d—–w- C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
2013-09-12 14:54:26 ——– d—–w- C:\IObit
2013-09-12 14:54:25 ——– d—–w- C:\ProgramData\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
2013-09-12 14:54:22 ——– d—–w- C:\ProgramData\IObit
2013-09-12 14:54:21 ——– d—–w- C:\Users\Susan\AppData\Roaming\IObit
2013-09-12 14:54:07 ——– d—–w- C:\Program Files (x86)\IObit
2013-09-12 13:52:16 ——– d—–w- C:\Users\Susan\AppData\Local\BMExplorer
2013-09-11 22:32:30 155584 —-a-w- C:\Windows\System32\drivers\ataport.sys
2013-09-09 22:36:56 ——– d—–w- C:\ProgramData\A-PDF
2013-09-09 22:25:06 ——– d—–w- C:\Program Files (x86)\A-PDF Restrictions Remover
2013-09-09 22:06:08 ——– d—–w- C:\Users\Susan\AppData\Local\Wondershare
2013-09-09 22:06:06 ——– d—–w- C:\Program Files (x86)\Common Files\Wondershare
2013-09-09 22:05:42 ——– d—–w- C:\ProgramData\PDFEditor
2013-09-09 22:05:41 ——– d—–w- C:\Users\Susan\AppData\Roaming\Wondershare
2013-09-08 15:22:26 ——– d—–w- C:\Users\Susan\AppData\Roaming\SparkTrust
2013-09-08 15:22:26 ——– d—–w- C:\Users\Susan\AppData\Roaming\DriverCure
2013-09-08 15:22:06 ——– d—–w- C:\Program Files (x86)\Common Files\SparkTrust
2013-09-08 15:22:01 ——– d—–w- C:\ProgramData\SparkTrust
2013-09-08 15:22:01 ——– d—–w- C:\Program Files (x86)\SparkTrust
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll
2013-09-07 12:55:35 159744 —-a-w- C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll
2013-09-05 02:46:29 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-09-05 02:28:28 ——– d—–w- C:\Users\Susan\AppData\Local\C8A13589-5A4C-46D8-9394-743EDDBDAB2B.aplzod
2013-09-05 02:24:13 ——– d—–w- C:\Users\Susan\AppData\Local\Apple
2013-09-05 02:24:00 ——– d—–w- C:\Program Files\Bonjour
2013-09-05 02:24:00 ——– d—–w- C:\Program Files (x86)\Bonjour
2013-09-05 02:15:21 ——– d—–w- C:\Program Files (x86)\JustCloud
2013-09-03 17:12:55 ——– d—–w- C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-09-03 15:54:25 ——– d—–w- C:\Program Files\Enigma Software Group
2013-09-03 15:53:36 ——– d—–w- C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP
2013-09-03 15:53:30 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-09-03 03:57:31 ——– d—–w- C:\ProgramData\Atheros
2013-09-03 03:53:58 ——– d—–w- C:\Users\Susan\AppData\Roaming\Atheros
2013-09-03 03:53:03 ——– d—–w- C:\Program Files (x86)\Bluetooth Suite
2013-08-30 20:07:22 67192 —-a-w- C:\Windows\SysWow64\libusb0.dll
2013-08-30 19:57:34 74872 —-a-w- C:\Windows\System32\libusb0.dll
.
==================== Find3M ====================
.
2013-09-25 16:59:43 692616 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-09-25 16:59:42 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-17 18:08:05 14456 —-a-w- C:\Windows\System32\drivers\gfibto.sys
2013-09-03 03:58:44 952 –sha-w- C:\ProgramData\KGyGaAvL.sys
2013-08-10 05:22:18 2241024 —-a-w- C:\Windows\System32\wininet.dll
2013-08-10 05:20:59 3959296 —-a-w- C:\Windows\System32\jscript9.dll
2013-08-10 05:20:55 67072 —-a-w- C:\Windows\System32\iesetup.dll
2013-08-10 05:20:55 136704 —-a-w- C:\Windows\System32\iesysprep.dll
2013-08-10 03:59:10 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-08-10 03:58:09 2876928 —-a-w- C:\Windows\SysWow64\jscript9.dll
2013-08-10 03:58:06 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-08-10 03:58:06 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-08-10 03:17:38 2706432 —-a-w- C:\Windows\System32\mshtml.tlb
2013-08-10 03:07:50 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-08-10 02:27:59 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-08-10 02:17:19 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-08-08 01:20:43 3155456 —-a-w- C:\Windows\System32\win32k.sys
2013-08-07 08:22:02 278800 ——w- C:\Windows\System32\MpSigStub.exe
2013-08-05 15:39:40 96168 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-08-05 15:39:39 867240 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-08-05 15:39:39 789416 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-08-02 02:23:53 5550528 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-08-02 02:15:44 1732032 —-a-w- C:\Windows\System32\ntdll.dll
2013-08-02 02:15:03 362496 —-a-w- C:\Windows\System32\wow64win.dll
2013-08-02 02:15:03 243712 —-a-w- C:\Windows\System32\wow64.dll
2013-08-02 02:15:03 13312 —-a-w- C:\Windows\System32\wow64cpu.dll
2013-08-02 02:14:57 215040 —-a-w- C:\Windows\System32\winsrv.dll
2013-08-02 02:14:11 16384 —-a-w- C:\Windows\System32\ntvdm64.dll
2013-08-02 02:13:34 424448 —-a-w- C:\Windows\System32\KernelBase.dll
2013-08-02 01:59:30 3968960 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-02 01:59:30 3913664 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-08-02 01:51:23 1292192 —-a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-02 01:50:42 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2013-08-02 01:50:42 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll
2013-08-02 01:09:17 338432 —-a-w- C:\Windows\System32\conhost.exe
2013-08-02 00:59:09 112640 —-a-w- C:\Windows\System32\smss.exe
2013-08-02 00:45:37 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2013-08-02 00:45:36 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-02 00:45:35 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2013-08-02 00:45:34 2048 —-a-w- C:\Windows\SysWow64\user.exe
2013-08-02 00:43:05 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43:05 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43:05 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43:05 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2013-07-25 09:25:54 1888768 —-a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 —-a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-23 20:04:07 54368 —-a-w- C:\Windows\System32\drivers\kltdi.sys
2013-07-23 20:04:07 178448 —-a-w- C:\Windows\System32\drivers\kneps.sys
2013-07-23 20:04:06 90208 —-a-w- C:\Windows\System32\drivers\klflt.sys
2013-07-23 16:15:17 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-07-19 01:58:42 2048 —-a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2013-07-09 05:52:52 224256 —-a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 —-a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 —-a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 —-a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 04:52:33 663552 —-a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:10 175104 —-a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 —-a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-06 06:03:53 1910208 —-a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 18:12:43.04 ===============
Thank you again - I hope you are able to see my problem here.
MaWilly