davew3232

Members
  • Content Count

    32
  • Joined

  • Last visited

Posts posted by davew3232

  1. All processes killed

    ========== OTL ==========

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

    HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66}\ not found.

    Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\SEARCH\view folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\SEARCH folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\PRICE_GONG folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\NOTIFICATION\images folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\NOTIFICATION folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\options\js folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\options folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875 folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea} folder moved successfully.

    C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions folder moved successfully.

    Folder C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\ not found.

    Registry value HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Run\\TWC.Win7 deleted successfully.


    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.

    File Protocol\Handler\msdaipp - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.

    File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.

    File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap\ deleted successfully.

    File Protocol\Handler\mso-offdap - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.

    File Protocol\Handler\skype4com - No CLSID value found not found.

    64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

    ========== COMMANDS ==========

     

    [EMPTYJAVA]

     

    User: Administrator

     

    User: All Users

     

    User: Dave

    ->Java cache emptied: 8196 bytes

     

    User: Default

     

    User: Default User

     

    User: Default.migrated

     

    User: Guest

     

    User: HomeGroupUser$

     

    User: Public

     

    User: TEMP

     

    User: TEMP.Laptop

     

    Total Java Files Cleaned = 0.00 mb

     

     

    [EMPTYFLASH]

     

    User: Administrator

     

    User: All Users

     

    User: Dave

    ->Flash cache emptied: 57768 bytes

     

    User: Default

    ->Flash cache emptied: 57472 bytes

     

    User: Default User

    ->Flash cache emptied: 0 bytes

     

    User: Default.migrated

     

    User: Guest

     

    User: HomeGroupUser$

     

    User: Public

     

    User: TEMP

     

    User: TEMP.Laptop

     

    Total Flash Files Cleaned = 0.00 mb

     

     

    [EMPTYTEMP]

     

    User: Administrator

     

    User: All Users

     

    User: Dave

    ->Temp folder emptied: 7309879 bytes

    ->Temporary Internet Files folder emptied: 19222113 bytes

    ->Java cache emptied: 0 bytes

    ->FireFox cache emptied: 0 bytes

    ->Google Chrome cache emptied: 205966422 bytes

    ->Flash cache emptied: 0 bytes

     

    User: Default

    ->Temp folder emptied: 0 bytes

    ->Temporary Internet Files folder emptied: 0 bytes

    ->Flash cache emptied: 0 bytes

     

    User: Default User

    ->Temp folder emptied: 0 bytes

    ->Temporary Internet Files folder emptied: 0 bytes

    ->Flash cache emptied: 0 bytes

     

    User: Default.migrated

     

    User: Guest

     

    User: HomeGroupUser$

     

    User: Public

     

    User: TEMP

    ->Temp folder emptied: 0 bytes

    ->FireFox cache emptied: 0 bytes

    ->Google Chrome cache emptied: 0 bytes

     

    User: TEMP.Laptop

     

    %systemdrive% .tmp files removed: 0 bytes

    %systemroot% .tmp files removed: 0 bytes

    %systemroot%\System32 .tmp files removed: 0 bytes

    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes

    %systemroot%\System32\drivers .tmp files removed: 0 bytes

    Windows Temp folder emptied: 54550 bytes

    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes

    RecycleBin emptied: 23406152 bytes

     

    Total Files Cleaned = 244.00 mb

     

    C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

    HOSTS file reset successfully

    Restore point Set: OTL Restore Point

     

    OTL by OldTimer - Version 3.2.69.0 log created on 11122014_185847

     

    Files\Folders moved on Reboot...

    C:\Users\Dave\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll moved successfully.

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.

     

    PendingFileRenameOperations files...

     

    Registry entries deleted on Reboot...
  2.  Results of screen317's Security Check version 0.99.89  

       x64 (UAC is enabled)  

     Internet Explorer 11  

    ``````````````Antivirus/Firewall Check:`````````````` 

     Windows Firewall Enabled!  

    Windows Defender   

     WMI entry may not exist for antivirus; attempting automatic update. 

    `````````Anti-malware/Other Utilities Check:````````` 

     Java 7 Update 71  

     Java version out of Date! 

     Adobe Flash Player 15.0.0.223  

     Adobe Reader XI  

     Google Chrome 35.0.1916.153  

     Google Chrome 36.0.1985.125  

    ````````Process Check: objlist.exe by Laurent````````  

     Windows Defender MSMpEng.exe 

     Malwarebytes Anti-Malware mbamservice.exe  

     Malwarebytes Anti-Malware mbam.exe  

     Malwarebytes Anti-Malware mbamscheduler.exe   

    `````````````````System Health check````````````````` 

     Total Fragmentation on Drive C:  % 

    ````````````````````End of Log`````````````````````` 
  3. OTL Extras logfile created on: 11/11/2014 9:08:19 PM - Run 2

    OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dave\Desktop

    64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation

    Internet Explorer (Version = 9.11.9600.17351)

    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

     

    3.60 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 63.30% Memory free

    4.47 Gb Paging File | 3.10 Gb Available in Paging File | 69.22% Paging File free

    Paging file location(s): ?:\pagefile.sys [binary data]

     

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)

    Drive C: | 275.65 Gb Total Space | 217.72 Gb Free Space | 78.98% Space Free | Partition Type: NTFS

    Drive D: | 21.33 Gb Total Space | 2.57 Gb Free Space | 12.07% Space Free | Partition Type: NTFS

     

    Computer Name: LAPTOP | User Name: Dave | Logged in as Administrator.

    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

     

    ========== Extra Registry (SafeList) ==========

     

     

    ========== File Associations ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

    .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)

    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

     

    ========== Shell Spawning ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

    batfile [open] -- "%1" %*

    cmdfile [open] -- "%1" %*

    comfile [open] -- "%1" %*

    exefile [open] -- "%1" %*

    helpfile [open] -- Reg Error: Key error.

    htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

    InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)

    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

    piffile [open] -- "%1" %*

    regfile [merge] -- Reg Error: Key error.

    scrfile [config] -- "%1"

    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

    scrfile [open] -- "%1" /S

    txtfile [edit] -- Reg Error: Key error.

    Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"

    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [explore] -- Reg Error: Value error.

    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

    batfile [open] -- "%1" %*

    cmdfile [open] -- "%1" %*

    comfile [open] -- "%1" %*

    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

    exefile [open] -- "%1" %*

    helpfile [open] -- Reg Error: Key error.

    htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

    piffile [open] -- "%1" %*

    regfile [merge] -- Reg Error: Key error.

    scrfile [config] -- "%1"

    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

    scrfile [open] -- "%1" /S

    txtfile [edit] -- Reg Error: Key error.

    Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"

    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [explore] -- Reg Error: Value error.

    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

     

    ========== Security Center Settings ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    "cval" = 1

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    "VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]

    "AntiVirusOverride" = 0

    "AntiSpywareOverride" = 0

    "FirewallOverride" = 0

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]

    "UpgradeTime" = Reg Error: Unknown registry data type -- File not found

     

    ========== Firewall Settings ==========

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    "EnableFirewall" = 1

    "DisableNotifications" = 0

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

    "EnableFirewall" = 1

    "DisableNotifications" = 0

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

    "EnableFirewall" = 1

    "DisableNotifications" = 0

     

    ========== Authorized Applications List ==========

     

     

    ========== Vista Active Open Ports Exception List ==========

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

     

    ========== Vista Active Application Exception List ==========

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

    "{1E8FACDA-593C-4192-8D9D-F9C62B219530}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 

    "{A0029681-0493-44F1-8AFF-5CA50BA15905}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe | 


    "{C2BBED50-011B-40BD-820B-37F8BA448099}" = dir=out | name=ebay | 


     

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

    "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector

    "{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt

    "{0FA995CC-C849-4755-B14B-5404CC75DC24}" = Energy Star

    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219

    "{21E47F47-C9A7-4454-BA48-388327B0EA00}" = RealNetworks - Microsoft Visual C++ 2010 Runtime

    "{23D2AFC7-C01E-4413-9D9A-0BABF52569BF}" = Microsoft Mouse and Keyboard Center

    "{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}" = iTunes

    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

    "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime

    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

    "{6096C0CC-7E19-4355-87F0-627EC5AA146D}" = iCloud

    "{63ADEC24-A374-80A8-E89B-BE401C787F75}" = AMD Catalyst Install Manager

    "{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64

    "{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter

    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour

    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

    "{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)

    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting

    "{A79A9231-0A5A-9384-21D0-DB753C2BE59B}" = AMD Fuel

    "{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}" = Apple Mobile Device Support

    "{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}" = HP Registration Service

    "{E82EC5DF-28FD-C8F4-ED08-B88728158260}" = ccc-utility64

    "{F089B734-1356-484F-A7B8-1B78F1616A15}" = HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6

    "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer

    "AVG" = AVG 2013

    "HP Imaging Device Functions" = HP Imaging Device Functions 14.0

    "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0

    "HPExtendedCapabilities" = HP Customer Participation Program 14.0

    "HPOCR" = OCR Software by I.R.I.S. 14.0

    "Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center

    "Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)

    "SynTPDeinstKey" = Synaptics TouchPad Driver

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

    "{0123AB93-E7A4-7F40-83B6-41EC2CF84B3F}" = CCC Help Dutch

    "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

    "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan

    "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements

    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

    "{0C3B99D2-35D0-6993-3C4B-A759419A8678}" = CCC Help Korean

    "{0C57987A-A03A-4B95-A309-D23F78F406CA}" = HP Utility Center

    "{0DCCD5F4-29E7-4AA0-8C1D-F8E1503B91F4}" = Catalyst Control Center - Branding

    "{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP

    "{1225C0F8-AB1A-BE3A-CD0C-DB8CA1613940}" = CCC Help Greek

    "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery

    "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant

    "{167158CE-1637-4167-8A1C-C2549EEA966A}" = The Weather Channel App

    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker

    "{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport

    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

    "{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10

    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

    "{26A24AE4-039D-4CA4-87B4-2F03217071FF}" = Java 7 Update 71

    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1

    "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox

    "{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8

    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery

    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery

    "{3C41A693-28E1-4335-A738-528B09DB600C}" = CCC Help Thai

    "{3C458872-A5BB-89F3-933C-2406F6D9E6F8}" = CCC Help Finnish

    "{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}" = QuickTime 7

    "{4734A746-A503-4B8E-A4FA-7B7C84A18D79}" = US Tech Support Framework

    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

    "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skypeâ„¢ 6.11

    "{4ED7050C-9332-4FB2-AB07-E94F25A53D39}" = HP Quick Launch

    "{528AB81B-D65A-4AB0-A2B6-82B51A087D01}" = HP Recovery Manager

    "{52A3FC19-6F84-F293-08C6-80A1D2F7477F}" = CCC Help Swedish

    "{56BA241F-580C-43D2-8403-947241AAE633}" = center

    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack

    "{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status

    "{5CD2FE1D-A3DB-F273-2798-EFAACF8492A5}" = CCC Help Portuguese

    "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM

    "{631EFC00-5A7A-4A90-9578-039EDA92DE0F}_is1" = HRBlockDirect version 1.1.2.0

    "{675D093B-815D-47FD-AB2C-192EC751E8E2}" = HP Software Framework

    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

    "{6A66D912-541C-54C6-43E6-17AF24700B91}" = CCC Help German

    "{6AAEB4CB-0573-41ec-89B0-0FE0D5134A8B}_is1" = MyCleanPC PC Optimizer

    "{6C8FF546-B0C0-0935-2F5E-7DC2DA727CFD}" = CCC Help Czech

    "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.2.3

    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

    "{734846E6-3E7A-04AC-0612-638A1D8A63F8}" = CCC Help Russian

    "{747F3993-036E-5F4F-1B82-7DA844B73966}" = Catalyst Control Center Localization All

    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime

    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

    "{793ED091-3F14-4968-3864-5C8A7727A5DA}" = CCC Help Chinese Standard

    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform

    "{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}" = Apple Application Support

    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver

    "{89D20029-0578-4D8D-979A-695C8D868868}" = H&R Block Deluxe + Efile 2012

    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

    "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg

    "{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390R 802.11bgn Wi-Fi Adapter

    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

    "{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content

    "{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional

    "{9285EABA-D88C-4A8A-6E9D-5F55BF03E46F}" = Catalyst Control Center InstallProxy

    "{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax

    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker

    "{93EB60BA-458D-FBE6-E466-CD170080E719}" = CCC Help Polish

    "{941DE69D-6CEE-4171-8F1F-3D7E352AA498}" = HP Wireless Button Driver

    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

    "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc

    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

    "{9C0F4CBD-8543-96CC-46F1-75E57B1B22A6}" = Catalyst Control Center Graphics Previews Common

    "{9C35EDE5-4B0F-45E7-A438-314BA889948E}" = HP MyRoom

    "{9E50DEC9-081B-441F-B647-98DBEA8B01DD}" = CorelDRAW 10

    "{9EF69B68-6DFE-F916-2D6E-E486D21A26C2}" = CCC Help Spanish

    "{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1

    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer

    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer

    "{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime

    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer

    "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.09)

    "{AD9F55C5-93F8-4CAB-A311-77C195912CA4}" = H&R Block Deluxe + Efile 2013

    "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update

    "{B1E7FE70-3B18-5BA2-8032-2547FC636A50}" = CCC Help Japanese

    "{B424890D-64FC-E0D1-4A17-4B512CA45CD9}" = CCC Help Italian

    "{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR

    "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2

    "{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter

    "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations

    "{BE64A239-E22E-9D77-AA57-36AE0443EC2F}" = CCC Help Chinese Traditional

    "{C045ED98-5FDB-45A0-AB48-C4B7560E7816}" = C309a

    "{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader

    "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint

    "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget

    "{CCCDD476-98F9-4B06-91DB-23F27CEC3BE1}" = HPDetect

    "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp

    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

    "{CF8C33C1-C978-527D-E0AF-530882DEB146}" = AMD VISION Engine Control Center

    "{D23CA718-0356-41F2-8E6A-B5C6CD383EF7}" = HP Documentation

    "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch

    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common

    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

    "{D5DC9541-12F0-59CF-9430-1136D5A58BD0}" = CCC Help Hungarian

    "{D7FBE7DC-A18F-4DFF-80BB-A478E4E09CF7}" = CCC Help Danish

    "{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq

    "{DC3C5C4A-1869-A99C-3AE4-55E0191105F0}" = CCC Help Norwegian

    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources

    "{DE431304-8040-43D4-8419-A58E210A3894}" = RealDownloader

    "{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw

    "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD

    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

    "{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center

    "{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}" = HP Support Assistant

    "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio

    "{E3AE96D6-E196-45B4-AF62-2B41998B9E37}" = UpdateService

    "{EB2CDF95-92D4-AC57-63B1-4E7F0BD8F9B8}" = CCC Help French

    "{ECA42F46-D80E-AD40-18FB-4BF64491CEE3}" = CCC Help English

    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219

    "{FA0E7183-6B11-4899-B25F-2C490543967E}" = PS_AIO_05_C309_Software_Min

    "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm

    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials

    "{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr

    "{FF282A38-D10B-E302-FBAD-5903C9DD9A5B}" = CCC Help Turkish

    "Adobe AIR" = Adobe AIR

    "Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin

    "Adobe Shockwave Player" = Adobe Shockwave Player 11.6

    "CorelDRAW 10" = CorelDRAW 10

    "Google Chrome" = Google Chrome

    "HP Photo Creations" = HP Photo Creations

    "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

    "InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10

    "InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8

    "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint

    "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD

    "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.3.1025

    "Paltalk Messenger" = 

    "Pdf995" = Pdf995 (installed by H&R Block)

    "PdfEdit995" = PdfEdit995 (installed by H&R Block)

    "PrintProjects" = PrintProjects

    "Rapport_msi" = Trusteer Endpoint Protection

    "RealPlayer 17.0" = RealPlayer Cloud

    "WildTangent hp Master Uninstall" = HP Games

    "WinLiveSuite" = Windows Live Essentials

     

    ========== HKEY_USERS Uninstall List ==========

     

    [HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

    "@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe" = SanDiskSecureAccess_Manager.exe

    "Dropbox" = Dropbox

    "OneDriveSetup.exe" = Microsoft OneDrive

     

    ========== Last 20 Event Log Errors ==========

     

    [ Application Events ]

    Error - 11/10/2014 11:23:22 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002

    Description = The program backgroundTaskHost.exe version 6.3.9600.16384 stopped 

    interacting with Windows and was closed. To see if more information about the problem

     is available, check the problem history in the Action Center control panel.    Process

     ID: c4    Start Time: 01cffd5e0d1808f7    Termination Time: 4294967295    Application Path:

     C:\WINDOWS\system32\backgroundTaskHost.exe    Report Id: 00d45714-6952-11e4-bf3d-c8cbb8b06c44

     

    Faulting

     package full name: 53987RBL3.FinanceHelper_1.1.0.73_neutral__z2nrd37h46pd8    Faulting

     package-relative application ID: App  

     

    Error - 11/10/2014 11:28:20 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002

    Description = The program wwahost.exe version 6.3.9600.17031 stopped interacting

     with Windows and was closed. To see if more information about the problem is available,

     check the problem history in the Action Center control panel.    Process ID: 14f8    Start

     Time: 01cffd5e0d10df01    Termination Time: 4294967295    Application Path: C:\WINDOWS\system32\wwahost.exe

     

    Report

     Id: 00cf954a-6952-11e4-bf3d-c8cbb8b06c44    Faulting package full name: AD2F1837.HPConnectedPhotopoweredbySnapfish_2.5.6.4614_neutral__v10z8vjag6ke6

     

    Faulting

     package-relative application ID: App  

     

    Error - 11/11/2014 10:48:39 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002

    Description = The program LiveComm.exe version 17.5.9600.20605 stopped interacting

     with Windows and was closed. To see if more information about the problem is available,

     check the problem history in the Action Center control panel.    Process ID: 300    Start

     Time: 01cffe21b9838d0e    Termination Time: 4294967295    Application Path: C:\Program 

    Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe

     

    Report

     Id: 60fea05d-6a16-11e4-bf3d-c8cbb8b06c44    Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe

     

    Faulting

     package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1  

     

    Error - 11/11/2014 11:33:03 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002

    Description = The program LiveComm.exe version 17.5.9600.20605 stopped interacting

     with Windows and was closed. To see if more information about the problem is available,

     check the problem history in the Action Center control panel.    Process ID: 1b04    Start

     Time: 01cffe28a53756a5    Termination Time: 4294967295    Application Path: C:\Program 

    Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe

     

    Report

     Id: 99e99d85-6a1c-11e4-bf3d-c8cbb8b06c44    Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe

     

    Faulting

     package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1  

     

    [ System Events ]

    Error - 11/10/2014 12:17:24 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7009

    Description = A timeout was reached (30000 milliseconds) while waiting for the Kodak

     AiO Network Discovery Service service to connect.

     

    Error - 11/10/2014 12:17:24 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000

    Description = The Kodak AiO Network Discovery Service service failed to start due

     to the following error:   %%1053

     

    Error - 11/10/2014 12:19:34 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000

    Description = The Google Update Service (gupdate) service failed to start due to

     the following error:   %%2

     

    Error - 11/12/2014 12:04:15 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7009

    Description = A timeout was reached (30000 milliseconds) while waiting for the Kodak

     AiO Network Discovery Service service to connect.

     

    Error - 11/12/2014 12:04:15 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000

    Description = The Kodak AiO Network Discovery Service service failed to start due

     to the following error:   %%1053

     

    Error - 11/12/2014 12:06:48 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000

    Description = The Google Update Service (gupdate) service failed to start due to

     the following error:   %%2

     

     

    < End of report >
  4. OTL logfile created on: 11/11/2014 9:08:19 PM - Run 2

    OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dave\Desktop

    64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation

    Internet Explorer (Version = 9.11.9600.17351)

    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

     

    3.60 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 63.30% Memory free

    4.47 Gb Paging File | 3.10 Gb Available in Paging File | 69.22% Paging File free

    Paging file location(s): ?:\pagefile.sys [binary data]

     

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)

    Drive C: | 275.65 Gb Total Space | 217.72 Gb Free Space | 78.98% Space Free | Partition Type: NTFS

    Drive D: | 21.33 Gb Total Space | 2.57 Gb Free Space | 12.07% Space Free | Partition Type: NTFS

     

    Computer Name: LAPTOP | User Name: Dave | Logged in as Administrator.

    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

     

    ========== Processes (SafeList) ==========

     

    PRC - [2014/11/10 20:36:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Desktop\OTL.com

    PRC - [2014/10/13 17:02:32 | 002,607,384 | ---- | M] (IBM Corp.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe

    PRC - [2014/10/13 17:02:32 | 001,919,256 | ---- | M] (IBM Corp.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe

    PRC - [2014/10/01 11:09:30 | 000,968,504 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

    PRC - [2014/10/01 11:09:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

    PRC - [2014/10/01 11:09:20 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

    PRC - [2014/09/12 02:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    PRC - [2014/04/05 14:43:08 | 001,141,848 | ---- | M] (RealNetworks, Inc.) -- c:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

    PRC - [2014/03/20 20:13:30 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

    PRC - [2014/03/15 02:18:20 | 000,039,568 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

    PRC - [2012/10/12 14:16:50 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe

    PRC - [2012/07/09 13:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    PRC - [2012/06/07 20:34:06 | 000,111,120 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe

     

     

    ========== Modules (No Company Name) ==========

     

    MOD - [2014/03/23 16:04:20 | 000,557,056 | ---- | M] () -- C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll

    MOD - [2012/06/08 11:34:06 | 000,016,400 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll

    MOD - [2012/06/07 20:34:06 | 000,627,216 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll

     

     

    ========== Services (SafeList) ==========

     

    SRV:64bit: - [2014/09/10 05:41:00 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)

    SRV:64bit: - [2014/08/15 20:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)

    SRV:64bit: - [2014/08/15 17:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)

    SRV:64bit: - [2014/08/15 17:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)

    SRV:64bit: - [2014/07/24 00:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)

    SRV:64bit: - [2014/04/06 04:20:36 | 000,201,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)

    SRV:64bit: - [2014/03/23 19:31:14 | 000,347,880 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)

    SRV:64bit: - [2014/03/23 19:31:14 | 000,023,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)

    SRV:64bit: - [2014/03/13 23:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)

    SRV:64bit: - [2014/03/07 22:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)

    SRV:64bit: - [2014/03/06 00:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)

    SRV:64bit: - [2014/02/22 08:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\WSService.dll -- (WSService)

    SRV:64bit: - [2014/02/22 02:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)

    SRV:64bit: - [2014/02/22 02:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)

    SRV:64bit: - [2014/02/22 02:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)

    SRV:64bit: - [2014/02/22 02:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)

    SRV:64bit: - [2014/01/22 01:27:09 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc)

    SRV:64bit: - [2013/12/13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

    SRV:64bit: - [2013/12/10 00:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)

    SRV:64bit: - [2013/08/22 04:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)

    SRV:64bit: - [2013/08/22 04:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)

    SRV:64bit: - [2013/08/22 04:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)

    SRV:64bit: - [2013/08/22 04:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)

    SRV:64bit: - [2013/08/22 04:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)

    SRV:64bit: - [2013/08/22 03:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)

    SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)

    SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)

    SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)

    SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)

    SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)

    SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)

    SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)

    SRV:64bit: - [2013/08/22 03:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)

    SRV:64bit: - [2013/08/22 02:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)

    SRV:64bit: - [2013/08/22 02:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)

    SRV:64bit: - [2013/08/22 02:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)

    SRV:64bit: - [2013/08/22 02:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)

    SRV:64bit: - [2013/08/22 02:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)

    SRV:64bit: - [2013/08/22 02:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)

    SRV:64bit: - [2013/08/22 02:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)

    SRV:64bit: - [2013/08/22 02:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)

    SRV:64bit: - [2013/05/29 19:47:42 | 000,322,048 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)

    SRV:64bit: - [2012/08/06 12:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)

    SRV - [2014/11/11 20:15:36 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

    SRV - [2014/10/13 17:02:32 | 001,919,256 | ---- | M] (IBM Corp.) [Auto | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)

    SRV - [2014/10/01 11:09:30 | 000,968,504 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)

    SRV - [2014/10/01 11:09:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)

    SRV - [2014/09/12 02:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)

    SRV - [2014/08/15 20:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)

    SRV - [2014/04/05 14:43:08 | 001,141,848 | ---- | M] (RealNetworks, Inc.) [Auto | Running] -- c:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe -- (RealPlayer Cloud Service)

    SRV - [2014/03/20 20:13:30 | 000,023,552 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe -- (RealPlayerUpdateSvc)

    SRV - [2014/03/15 02:18:20 | 000,039,568 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)

    SRV - [2014/03/13 23:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)

    SRV - [2014/01/22 01:27:11 | 000,475,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)

    SRV - [2014/01/22 01:27:08 | 000,066,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)

    SRV - [2014/01/22 01:27:07 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)

    SRV - [2013/11/04 18:31:56 | 000,092,160 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)

    SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)

    SRV - [2013/08/21 20:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)

    SRV - [2013/08/21 19:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)

    SRV - [2012/07/13 18:02:16 | 002,451,456 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)

    SRV - [2012/07/09 13:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)

    SRV - [2011/08/18 00:29:52 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)

    SRV - [2009/08/05 12:49:44 | 000,284,016 | ---- | M] (Eastman Kodak Company) [Auto | Stopped] -- C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe -- (Kodak AiO Network Discovery Service)

     

     

    ========== Driver Services (SafeList) ==========

     

    DRV:64bit: - [2014/11/11 21:05:35 | 000,129,752 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)

    DRV:64bit: - [2014/10/13 17:02:42 | 000,534,104 | ---- | M] (IBM Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RapportKE64.sys -- (RapportKE64)

    DRV:64bit: - [2014/10/13 17:02:42 | 000,289,656 | ---- | M] (IBM Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RapportHades64.sys -- (RapportHades64)

    DRV:64bit: - [2014/10/01 11:11:26 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)

    DRV:64bit: - [2014/10/01 11:11:12 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)

    DRV:64bit: - [2014/08/14 17:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)

    DRV:64bit: - [2014/07/24 08:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)

    DRV:64bit: - [2014/07/24 08:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)

    DRV:64bit: - [2014/07/24 04:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)

    DRV:64bit: - [2014/05/01 06:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)

    DRV:64bit: - [2014/03/23 19:30:57 | 000,257,880 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)

    DRV:64bit: - [2014/03/23 19:30:57 | 000,123,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)

    DRV:64bit: - [2014/03/23 19:27:03 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)

    DRV:64bit: - [2014/03/19 20:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)

    DRV:64bit: - [2014/03/19 14:23:14 | 000,050,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)

    DRV:64bit: - [2014/03/13 05:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)

    DRV:64bit: - [2014/03/08 13:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)

    DRV:64bit: - [2014/02/22 09:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)

    DRV:64bit: - [2014/02/22 08:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)

    DRV:64bit: - [2014/02/22 08:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)

    DRV:64bit: - [2014/02/22 08:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)

    DRV:64bit: - [2014/02/22 08:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)

    DRV:64bit: - [2014/02/22 05:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)

    DRV:64bit: - [2014/01/22 01:34:53 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)

    DRV:64bit: - [2014/01/22 01:34:52 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)

    DRV:64bit: - [2014/01/22 01:34:52 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)

    DRV:64bit: - [2014/01/08 23:48:02 | 000,010,112 | ---- | M] (support.com, Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssmirrdr.sys -- (ssmirrdr)

    DRV:64bit: - [2014/01/07 08:02:04 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)

    DRV:64bit: - [2014/01/07 07:42:08 | 000,076,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)

    DRV:64bit: - [2013/12/13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)

    DRV:64bit: - [2013/12/13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

    DRV:64bit: - [2013/12/02 17:32:18 | 002,483,376 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)

    DRV:64bit: - [2013/11/14 00:28:58 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)

    DRV:64bit: - [2013/11/14 00:25:25 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)

    DRV:64bit: - [2013/11/14 00:16:57 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)

    DRV:64bit: - [2013/11/14 00:16:54 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)

    DRV:64bit: - [2013/08/22 06:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)

    DRV:64bit: - [2013/08/22 06:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

    DRV:64bit: - [2013/08/22 05:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)

    DRV:64bit: - [2013/08/22 05:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)

    DRV:64bit: - [2013/08/22 05:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)

    DRV:64bit: - [2013/08/22 05:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)

    DRV:64bit: - [2013/08/22 05:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)

    DRV:64bit: - [2013/08/22 05:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

    DRV:64bit: - [2013/08/22 05:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

    DRV:64bit: - [2013/08/22 05:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)

    DRV:64bit: - [2013/08/22 05:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

    DRV:64bit: - [2013/08/22 05:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)

    DRV:64bit: - [2013/08/22 05:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)

    DRV:64bit: - [2013/08/22 05:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

    DRV:64bit: - [2013/08/22 05:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

    DRV:64bit: - [2013/08/22 05:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)

    DRV:64bit: - [2013/08/22 05:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

    DRV:64bit: - [2013/08/22 05:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)

    DRV:64bit: - [2013/08/22 05:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)

    DRV:64bit: - [2013/08/22 05:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

    DRV:64bit: - [2013/08/22 05:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)

    DRV:64bit: - [2013/08/22 05:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)

    DRV:64bit: - [2013/08/22 05:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

    DRV:64bit: - [2013/08/22 05:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)

    DRV:64bit: - [2013/08/22 05:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)

    DRV:64bit: - [2013/08/22 05:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)

    DRV:64bit: - [2013/08/22 05:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)

    DRV:64bit: - [2013/08/22 05:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)

    DRV:64bit: - [2013/08/22 05:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)

    DRV:64bit: - [2013/08/22 04:39:58 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)

    DRV:64bit: - [2013/08/22 04:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)

    DRV:64bit: - [2013/08/22 04:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)

    DRV:64bit: - [2013/08/22 04:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)

    DRV:64bit: - [2013/08/22 04:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)

    DRV:64bit: - [2013/08/22 04:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)

    DRV:64bit: - [2013/08/22 04:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)

    DRV:64bit: - [2013/08/22 04:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)

    DRV:64bit: - [2013/08/22 04:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)

    DRV:64bit: - [2013/08/22 04:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)

    DRV:64bit: - [2013/08/22 04:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)

    DRV:64bit: - [2013/08/22 04:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)

    DRV:64bit: - [2013/08/22 04:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)

    DRV:64bit: - [2013/08/22 04:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)

    DRV:64bit: - [2013/08/22 04:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)

    DRV:64bit: - [2013/08/22 04:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)

    DRV:64bit: - [2013/08/22 04:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)

    DRV:64bit: - [2013/08/22 04:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)

    DRV:64bit: - [2013/08/22 04:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)

    DRV:64bit: - [2013/08/22 04:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)

    DRV:64bit: - [2013/08/22 04:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)

    DRV:64bit: - [2013/08/22 04:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)

    DRV:64bit: - [2013/08/22 03:27:46 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)

    DRV:64bit: - [2013/08/22 01:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)

    DRV:64bit: - [2013/08/12 16:25:46 | 000,017,624 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)

    DRV:64bit: - [2013/08/09 17:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)

    DRV:64bit: - [2013/07/30 11:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)

    DRV:64bit: - [2013/07/25 12:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)

    DRV:64bit: - [2013/05/29 19:47:43 | 000,542,208 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)

    DRV:64bit: - [2012/08/24 02:38:28 | 000,448,312 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)

    DRV:64bit: - [2012/08/24 02:38:28 | 000,043,832 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)

    DRV:64bit: - [2012/08/24 02:38:26 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv)

    DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)

    DRV:64bit: - [2012/08/03 14:07:30 | 000,020,288 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WirelessButtonDriver64.sys -- (WirelessButtonDriver)

    DRV:64bit: - [2012/07/23 14:35:12 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)

    DRV:64bit: - [2012/07/23 14:35:12 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)

    DRV:64bit: - [2012/07/04 11:41:58 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)

    DRV:64bit: - [2012/06/25 10:24:50 | 000,092,536 | ---- | M] (CyberLink) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\CLVirtualDrive.sys -- (CLVirtualDrive)

    DRV:64bit: - [2012/06/18 19:07:50 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)

    DRV:64bit: - [2012/06/12 22:41:22 | 000,683,664 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)

    DRV - [2014/10/13 17:02:42 | 000,557,656 | ---- | M] (IBM Corp.) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys -- (RapportPG64)

    DRV - [2014/10/13 17:02:42 | 000,445,880 | ---- | M] (IBM Corp.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys -- (RapportEI64)

    DRV - [2014/10/10 15:57:39 | 000,761,720 | ---- | M] () [Kernel | System | Running] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_80055.sys -- (RapportCerberus_80055)

     

     

    ========== Standard Registry (SafeList) ==========

     

     

    ========== Internet Explorer ==========

     

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

     

     

    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = 

    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:14297;https=127.0.0.1:14297

     

    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = 

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:14297;https=127.0.0.1:14297

     

     

     

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" = http://www.google.com/search?q={searchTerms}

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:14081;https=127.0.0.1:14081

     

     

    ========== FireFox ==========

     

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()

    FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found

    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)

    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)

    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=17.0.8.22: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=17.0.8: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=17.0.8: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=17.0.8: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=17.0.8.22: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)

    FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)

    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll File not found

    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll File not found

    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKCU\Software\MozillaPlugins\hp.com/HPDetect: C:\Users\Dave\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)

     

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014/04/05 14:46:48 | 000,000,000 | ---D | M]

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0FAA5C82-A094-4541-8811-D3361F972A81}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2014/04/05 14:46:48 | 000,000,000 | ---D | M]

     

    [2013/10/08 20:54:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions

    [2014/11/09 18:21:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}

     

    ========== Chrome  ==========

     

    CHR - default_search_provider:  (Enabled)

    CHR - default_search_provider: search_url = 

    CHR - default_search_provider: suggest_url = 

    CHR - homepage: 

    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll

    CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

    CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll

    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll

    CHR - plugin: Norton Confidential (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.0.0.72_0\npcoplgn.dll

    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll

    CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dll

    CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit)  (Disabled) = c:\program files (x86)\real\realplayer\netscape6\nppl3260.dll

    CHR - plugin: RealPlayer Video Downloader for PepperFlash  (32-bit)  (Disabled) = c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll

    CHR - plugin: RealPlayer Download Plugin (Disabled) = c:\program files (x86)\real\realplayer\netscape6\nprpplugin.dll

    CHR - plugin: RocketLife Secure Plug-In Layer (Disabled) = c:\programdata\visan\plugins\nprlsecurepluginlayer.dll

    CHR - Extension: Google Drive = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\

    CHR - Extension: YouTube = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\

    CHR - Extension: Google Search = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\

    CHR - Extension: Google Wallet = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\

    CHR - Extension: Gmail = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

     

    O1 HOSTS File: ([2013/11/02 08:48:46 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts

    O1 - Hosts: 127.0.0.1       localhost

    O1 - Hosts: ::1       localhost

    O2:64bit: - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)

    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

    O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)

    O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)

    O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

    O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)

    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

    O4:64bit: - HKLM..\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)

    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

    O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)

    O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)

    O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)

    O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

    O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)

    O4 - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002..\Run: [TWC.Win7] C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe File not found

    O4:64bit: - HKLM..\RunOnce: [NCPluginUpdater] C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)

    O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

    O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3





    O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)

    O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)

    O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)

    O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)

    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)

    O13 - gopher Prefix: missing

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 72.21.70.3 67.215.21.202

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}: DhcpNameServer = 72.21.70.3 67.215.21.202

    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found

    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found

    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found

    O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found

    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found

    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)

    O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)

    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

    O32 - HKLM CDRom: AutoRun - 1

    O33 - MountPoints2\{bb7712fa-a231-11e3-beeb-c8cbb8b06c44}\Shell - "" = AutoRun

    O33 - MountPoints2\{bb7712fa-a231-11e3-beeb-c8cbb8b06c44}\Shell\AutoRun\command - "" = "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL F:\TL-Bootstrap.exe

    O34 - HKLM BootExecute: (autocheck autochk *)

    O34 - HKLM BootExecute: (MACHINE BootExecut)

    O35:64bit: - HKLM\..comfile [open] -- "%1" %*

    O35:64bit: - HKLM\..exefile [open] -- "%1" %*

    O35 - HKLM\..comfile [open] -- "%1" %*

    O35 - HKLM\..exefile [open] -- "%1" %*

    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

    O37 - HKLM\...com [@ = comfile] -- "%1" %*

    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

     

    ========== Files/Folders - Created Within 30 Days ==========

     

    [2014/11/11 20:14:02 | 017,926,832 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerInstaller.exe

    [2014/11/11 19:42:34 | 000,000,000 | ---D | C] -- C:\FRST

    [2014/11/10 20:36:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Dave\Desktop\OTL.com

    [2014/11/09 20:16:53 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys

    [2014/11/09 20:15:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

    [2014/11/09 20:14:53 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys

    [2014/11/09 20:14:52 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys

    [2014/11/09 20:14:52 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys

    [2014/11/09 20:14:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware

    [2014/11/09 19:04:25 | 000,000,000 | ---D | C] -- C:\AdwCleaner

    [2014/11/09 18:54:02 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN

    [2014/11/09 18:46:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp

    [2014/11/09 18:46:50 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Temp

    [2014/11/09 18:09:12 | 000,000,000 | ---D | C] -- C:\zoek

    [2014/11/09 16:58:26 | 000,000,000 | ---D | C] -- C:\zoek_backup

    [2014/11/02 08:53:26 | 000,272,808 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe

    [2014/11/02 08:52:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

    [2014/11/02 08:52:27 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe

    [2014/11/02 08:52:27 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe

    [2014/11/02 08:52:27 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll

    [2014/11/02 08:51:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java

    [2014/10/24 18:28:36 | 000,000,000 | ---D | C] -- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7

    [2014/10/15 20:12:22 | 000,105,440 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl

    [2014/10/15 20:12:21 | 000,706,016 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe

    [2014/10/14 19:38:41 | 005,829,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll

    [2014/10/14 19:38:23 | 002,108,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl

    [2014/10/14 19:38:23 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll

    [2014/10/14 19:38:22 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl

    [2014/10/14 19:38:21 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe

    [2014/10/14 19:38:19 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll

    [2014/10/14 19:38:17 | 000,289,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll

    [2014/10/14 19:38:16 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll

    [2014/10/14 19:38:16 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll

    [2014/10/14 19:38:16 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll

    [2014/10/14 19:38:15 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll

    [2014/10/14 19:38:15 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll

    [2014/10/14 19:38:14 | 000,775,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll

    [2014/10/14 19:38:13 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll

    [2014/10/14 19:36:43 | 000,921,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll

    [2014/10/14 19:36:42 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll

    [2014/10/14 19:36:38 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll

    [2014/10/14 19:36:10 | 001,702,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll

    [2014/10/14 19:36:10 | 000,839,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll

    [2014/10/14 19:36:10 | 000,672,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll

    [2014/10/14 19:36:10 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll

    [2014/10/14 19:36:10 | 000,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe

    [2014/10/14 19:36:09 | 000,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll

    [2014/10/14 19:36:09 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll

    [2014/10/14 19:36:09 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll

    [2014/10/14 19:36:09 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll

    [2014/10/14 19:36:09 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll

    [2014/10/14 19:36:08 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll

    [2014/10/14 19:36:08 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe

    [2014/10/14 19:36:08 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe

    [2014/10/14 19:34:57 | 008,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll

    [2014/10/14 19:34:54 | 005,902,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll

    [2014/10/14 19:34:53 | 006,649,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll

    [2014/10/14 19:34:52 | 005,777,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll

    [2014/10/14 19:34:51 | 004,758,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll

    [2014/10/14 19:34:49 | 001,106,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll

    [2014/10/14 19:34:48 | 001,710,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll

    [2014/10/14 19:34:48 | 001,112,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll

    [2014/10/14 19:34:45 | 001,507,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll

    [2014/10/14 19:34:45 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll

    [2014/10/14 19:34:44 | 000,756,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll

    [2014/10/14 19:34:43 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll

    [2014/10/14 19:34:40 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll

    [2014/10/14 19:34:38 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe

    [2014/10/14 19:34:38 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll

    [2014/10/14 19:34:38 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll

    [2014/10/14 19:34:37 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS

    [2014/10/14 19:34:37 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll

    [2014/10/14 19:34:37 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll

    [2014/10/14 19:34:36 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll

    [2014/10/14 19:34:36 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll

    [2014/10/14 19:34:36 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll

    [2014/10/14 19:34:36 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll

    [2014/10/14 19:34:34 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll

    [2014/10/14 19:34:34 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll

    [2014/10/14 19:34:08 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll

    [2014/10/14 19:34:08 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll

    [2014/10/14 19:34:04 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll

    [2014/10/14 19:34:04 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll

    [2014/10/14 19:34:01 | 000,527,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll

    [2014/10/14 19:33:55 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll

    [2014/10/14 19:33:55 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll

    [2014/10/14 19:23:02 | 002,779,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll

    [2014/10/14 19:23:01 | 002,646,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll

    [2014/10/14 19:23:00 | 002,321,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll

    [1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]

     

    ========== Files - Modified Within 30 Days ==========

     

    [2014/11/11 21:14:07 | 000,000,908 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

    [2014/11/11 21:13:51 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job

    [2014/11/11 21:05:35 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys

    [2014/11/11 21:05:34 | 000,022,961 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141111210435

    [2014/11/11 21:04:03 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat

    [2014/11/11 21:03:57 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys

    [2014/11/11 21:03:53 | 3088,904,192 | -HS- | M] () -- C:\hiberfil.sys

    [2014/11/11 20:52:20 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\HP Photo Creations Communicator.job

    [2014/11/11 20:31:13 | 000,000,330 | ---- | M] () -- C:\WINDOWS\tasks\PrintProjects Communicator.job

    [2014/11/11 20:14:38 | 017,926,832 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerInstaller.exe

    [2014/11/11 19:39:17 | 000,124,421 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141110201537

    [2014/11/11 19:39:17 | 000,102,664 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141111193818

    [2014/11/10 20:38:54 | 000,854,448 | ---- | M] () -- C:\Users\Dave\Desktop\SecurityCheck.exe

    [2014/11/10 20:36:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Desktop\OTL.com

    [2014/11/10 20:16:35 | 000,033,834 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109211734

    [2014/11/09 20:15:39 | 000,001,078 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

    [2014/11/09 19:47:12 | 000,108,693 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109194611

    [2014/11/09 19:13:35 | 000,038,679 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109191234

    [2014/11/09 18:57:59 | 000,956,540 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI

    [2014/11/09 18:57:59 | 000,796,126 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat

    [2014/11/09 18:57:59 | 000,161,346 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat

    [2014/11/09 18:51:22 | 000,025,377 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109185022

    [2014/11/09 18:50:29 | 000,000,008 | RHS- | M] () -- C:\ProgramData\ntuser.pol

    [2014/11/09 16:58:23 | 000,024,064 | ---- | M] () -- C:\WINDOWS\zoek-delete.exe

    [2014/11/09 04:41:33 | 001,738,235 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141108044053

    [2014/11/09 04:41:33 | 001,023,708 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109044052

    [2014/11/08 04:41:30 | 000,994,658 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141107145630

    [2014/11/07 16:59:10 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\HPCeeScheduleForDave.job

    [2014/11/07 14:57:28 | 000,102,692 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141106195626

    [2014/11/06 19:57:24 | 000,003,634 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141105214132

    [2014/11/05 19:15:28 | 001,378,478 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141104031446

    [2014/11/05 19:15:28 | 000,176,385 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141105191432

    [2014/11/04 03:14:56 | 001,738,366 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141103031446

    [2014/11/03 03:14:54 | 000,504,737 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141102201553

    [2014/11/02 08:52:02 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll

    [2014/11/02 08:51:56 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe

    [2014/11/02 08:51:56 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe

    [2014/11/02 08:51:55 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe

    [2014/11/02 07:48:50 | 000,901,277 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141102074757

    [2014/11/02 07:48:50 | 000,505,736 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141102014845

    [2014/11/02 00:47:39 | 000,000,532 | ---- | M] () -- C:\WINDOWS\SysNative\ASOROSet.bin

    [2014/10/24 18:32:33 | 000,001,755 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk

    [2014/10/24 17:34:49 | 000,001,817 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk

    [2014/10/15 20:10:05 | 001,797,088 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT

    [2014/10/13 17:02:42 | 000,534,104 | ---- | M] (IBM Corp.) -- C:\WINDOWS\SysNative\drivers\RapportKE64.sys

    [2014/10/13 17:02:42 | 000,289,656 | ---- | M] (IBM Corp.) -- C:\WINDOWS\SysNative\drivers\RapportHades64.sys

    [1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]

     

    ========== Files Created - No Company Name ==========

     

    [2014/11/11 21:05:34 | 000,015,715 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141111210435

    [2014/11/11 19:39:17 | 000,102,664 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141111193818

    [2014/11/10 20:38:40 | 000,854,448 | ---- | C] () -- C:\Users\Dave\Desktop\SecurityCheck.exe

    [2014/11/10 20:16:35 | 000,124,421 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141110201537

    [2014/11/09 21:18:34 | 000,033,834 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109211734

    [2014/11/09 20:15:39 | 000,001,078 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

    [2014/11/09 19:47:12 | 000,108,693 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109194611

    [2014/11/09 19:13:35 | 000,038,679 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109191234

    [2014/11/09 18:51:22 | 000,025,377 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109185022

    [2014/11/09 18:46:53 | 000,024,064 | ---- | C] () -- C:\WINDOWS\zoek-delete.exe

    [2014/11/09 04:41:33 | 001,023,708 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109044052

    [2014/11/08 04:41:30 | 001,738,235 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141108044053

    [2014/11/07 14:57:28 | 000,994,658 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141107145630

    [2014/11/06 19:57:24 | 000,102,692 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141106195626

    [2014/11/05 21:42:31 | 000,003,634 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141105214132

    [2014/11/05 19:15:28 | 000,176,385 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141105191432

    [2014/11/04 03:14:56 | 001,378,478 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141104031446

    [2014/11/03 03:14:54 | 001,738,366 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141103031446

    [2014/11/02 20:16:52 | 000,504,737 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141102201553

    [2014/11/02 07:48:50 | 000,901,277 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141102074757

    [2014/11/02 00:49:45 | 000,505,736 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141102014845

    [2014/10/24 18:32:33 | 000,001,755 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk

    [2014/10/24 17:34:48 | 000,001,817 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk

    [2014/10/14 19:34:34 | 000,388,729 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml

    [2014/08/29 14:58:45 | 000,005,120 | ---- | C] () -- C:\Users\Dave\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    [2014/08/08 10:32:43 | 000,000,008 | RHS- | C] () -- C:\ProgramData\ntuser.pol

    [2014/04/25 19:35:00 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini

    [2014/02/22 15:20:28 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll

    [2014/02/05 13:14:58 | 000,000,142 | ---- | C] () -- C:\WINDOWS\wpd99.drv

    [2014/02/05 13:14:41 | 000,040,448 | ---- | C] () -- C:\WINDOWS\SysWow64\pdf995mon64.dll

    [2014/01/22 00:48:02 | 000,930,400 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI

    [2014/01/22 00:44:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin

    [2013/12/13 10:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat

    [2013/12/13 10:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat

    [2013/12/13 10:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat

    [2013/12/13 10:23:24 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe

    [2013/12/13 10:23:24 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe

    [2013/12/13 10:23:14 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll

    [2013/09/27 21:05:34 | 000,003,734 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml

    [2013/08/22 08:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat

    [2013/08/22 08:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT

    [2013/08/22 07:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat

    [2013/08/22 00:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin

    [2013/08/21 20:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll

    [2013/08/21 16:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll

    [2013/08/21 16:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat

    [2013/07/12 18:51:22 | 000,000,017 | ---- | C] () -- C:\Users\Dave\AppData\Local\resmon.resmoncfg

    [2013/03/17 15:59:51 | 000,001,067 | ---- | C] () -- C:\WINDOWS\hpomdl35.dat.temp

    [2013/03/17 15:33:22 | 000,225,825 | ---- | C] () -- C:\WINDOWS\hpoins35.dat

    [2013/03/17 15:33:22 | 000,001,067 | ---- | C] () -- C:\WINDOWS\hpomdl35.dat

    [2012/12/27 18:13:50 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

     

    ========== ZeroAccess Check ==========

     

    [2014/01/22 17:08:29 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

     

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

     

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

     

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

     

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

     

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    "" = C:\Windows\SysNative\shell32.dll -- [2014/08/15 21:08:41 | 021,195,616 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Apartment

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    "" = %SystemRoot%\system32\shell32.dll -- [2014/08/15 20:16:40 | 018,722,600 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Apartment

     

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64

    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 02:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Free

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

    "" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 19:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Free

     

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64

    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 02:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Both

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

     

    ========== LOP Check ==========

     

    [2013/12/27 21:35:06 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\AVAST Software

    [2013/02/26 21:50:50 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\AVG

    [2013/09/20 21:09:17 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\AVG2013

    [2013/11/08 12:15:04 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\com.zoosk.Desktop

    [2013/11/08 12:15:05 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1

    [2014/08/28 18:21:28 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Dropbox

    [2014/02/22 14:33:36 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\HewlettPackard

    [2013/01/07 12:20:50 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\OpenOffice.org

    [2014/04/25 18:58:49 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Oracle

    [2014/06/22 15:51:31 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Paltalk

    [2014/02/05 13:17:18 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\pdf995

    [2013/07/28 09:52:27 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SanDisk

    [2013/07/26 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SanDisk SecureAccess

    [2014/04/25 19:13:21 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SmartDraw

    [2014/03/02 11:47:28 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\supportdotcom

    [2012/12/25 18:52:39 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Synaptics

    [2014/02/05 13:17:35 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\TaxCut

    [2013/02/26 21:39:11 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\TuneUp Software

    [2013/01/04 16:52:26 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Visan

    [2014/03/02 18:41:13 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\WildTangent

    [2014/06/28 09:26:00 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Windows

    [2014/01/22 01:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software

    [2014/01/22 01:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software

    [2013/09/20 18:34:22 | 000,000,000 | ---D | M] -- C:\Users\TEMP\AppData\Roaming\AVG2014

    [2013/03/07 11:22:48 | 000,000,000 | ---D | M] -- C:\Users\TEMP\AppData\Roaming\TuneUp Software

     

    ========== Purity Check ==========

     

     

     

    ========== Alternate Data Streams ==========

     

    @Alternate Data Stream - 36 bytes -> C:\Users\Dave\OneDrive:ms-properties

    @Alternate Data Stream - 220 bytes -> C:\Users\Dave\SkyDrive:ms-properties

    @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:373E1720

     

    < End of report >
  5. Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014

    Ran by Dave (administrator) on LAPTOP on 11-11-2014 19:42:57

    Running from C:\Users\Dave\Downloads

    Loaded Profiles: Dave &  (Available profiles: Dave)

    Platform: Windows 7 Ultimate (X64) OS Language: English (United States)

    Internet Explorer Version 11

    Boot Mode: Normal


     

    ==================== Processes (Whitelisted) =================

     

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

     

    (IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe

    (AMD) C:\Windows\System32\atiesrxx.exe

    (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe

    (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

    (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe

    (Microsoft Corporation) C:\Windows\System32\dasHost.exe

    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

    () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

    (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

    () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

    (Microsoft Corporation) C:\Windows\System32\dllhost.exe

    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe

    (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    (Microsoft Corporation) C:\Windows\System32\LogonUI.exe

    (AMD) C:\Windows\System32\atieclxx.exe

    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe

    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe

    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe

    (IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe

    (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe

    (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe

    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe

    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    (IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe

    (Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe

    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\livecomm.exe

    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    (Microsoft Corporation) C:\Windows\System32\rundll32.exe

    (Microsoft Corporation) C:\Windows\System32\wsqmcons.exe

    (Microsoft Corporation) C:\Windows\System32\rundll32.exe

    (Microsoft Corporation) C:\Users\Dave\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe

    (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe

    (Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe

     

     

    ==================== Registry (Whitelisted) ==================

     

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

     

    HKLM\...\Run: [synTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-24] (Synaptics Incorporated)

    HKLM\...\Run: [sysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-29] (IDT, Inc.)

    HKLM-x32\...\Run: [startCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)

    HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491320 2012-07-26] (CyberLink Corp.)

    HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)

    HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [580512 2012-07-09] (Hewlett-Packard Development Company, L.P.)

    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)

    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)

    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)

    HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [296520 2014-04-05] (RealNetworks, Inc.)

    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)

    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)

    HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)

    HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-08-19] (Hewlett-Packard)

    HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\Run: [TWC.Win7] => C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe

    HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\MountPoints2: {bb7712fa-a231-11e3-beeb-c8cbb8b06c44} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL F:\TL-Bootstrap.exe

    HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [TWC.Win7] => C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe

    HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {bb7712fa-a231-11e3-beeb-c8cbb8b06c44} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL F:\TL-Bootstrap.exe

    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

    ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk

    ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)

    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk

    ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)

    Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

    ShortcutTarget: Dropbox.lnk -> C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

    Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk

    ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File

    ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File

    ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File

    ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File

    ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File

     

    ==================== Internet (Whitelisted) ====================

     

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

     

    ProxyServer: http=127.0.0.1:14081;https=127.0.0.1:14081

    StartMenuInternet: IEXPLORE.EXE - iexplore.exe

    SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}

    BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)

    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)

    BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)

    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

    BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

    BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)

    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

    Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)

    Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)

    Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)

    Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)

    Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)

    Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)

    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

    Tcpip\Parameters: [DhcpNameServer] 72.21.70.3 67.215.21.202

     

    FireFox:

    ========

    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()

    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)

    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()

    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

    FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)

    FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)

    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

    FF Plugin-x32: @real.com/nppl3260;version=17.0.8.22 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

    FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.8 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)

    FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.8 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)

    FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.8 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)

    FF Plugin-x32: @real.com/nprpplugin;version=17.0.8.22 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)

    FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)

    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File

    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File

    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF Plugin HKU\S-1-5-21-2989837996-1790684633-2971567215-1002: hp.com/HPDetect -> C:\Users\Dave\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)

    FF Plugin HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: hp.com/HPDetect -> C:\Users\Dave\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)

    FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

    FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-04-05]

    FF HKLM-x32\...\Firefox\Extensions: [{0FAA5C82-A094-4541-8811-D3361F972A81}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

     

    Chrome: 

    =======

    CHR dev: Chrome dev build detected! <======= ATTENTION

    CHR Profile: C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default

    CHR Extension: (Google Drive) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-25]

    CHR Extension: (YouTube) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-25]

    CHR Extension: (Google Search) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-25]

    CHR Extension: (Google Wallet) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-03]

    CHR Extension: (Gmail) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-25]

    CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-03-15]

    CHR StartMenuInternet: Google Chrome - chrome.exe

     

    ==================== Services (Whitelisted) =================

     

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

     

    R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]

    R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]

    R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]

    R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]

    R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-21] (Microsoft Corporation)

    S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-13] (Microsoft Corporation)

    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)

    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)

    S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]

    S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-05] (Microsoft Corporation)

    S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]

    R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1919256 2014-10-13] (IBM Corp.)

    R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-03-15] ()

    R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-04-05] (RealNetworks, Inc.)

    R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-03-20] () [File not signed]

    S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-21] (Microsoft Corporation)

    S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-21] (Microsoft Corporation)

    S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-01-22] (Microsoft Corporation)

    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)

    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-23] (Microsoft Corporation)

    S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]

    S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]

     

    ==================== Drivers (Whitelisted) ====================

     

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

     

    R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)

    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)

    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-11] (Malwarebytes Corporation)

    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)

    R1 RapportCerberus_80055; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_80055.sys [761720 2014-10-10] ()

    R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [445880 2014-10-13] (IBM Corp.)

    S3 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [289656 2014-10-13] (IBM Corp.)

    S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [534104 2014-10-13] (IBM Corp.)

    S3 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [557656 2014-10-13] (IBM Corp.)

    S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)

    S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)

    S3 ssmirrdr; C:\Windows\system32\DRIVERS\ssmirrdr.sys [10112 2014-01-08] (support.com, Inc)

    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)

    R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.)

     

    ==================== NetSvcs (Whitelisted) ===================

     

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

     

     

    ==================== One Month Created Files and Folders ========

     

    (If an entry is included in the fixlist, the file\folder will be moved.)

     

    2014-11-11 19:42 - 2014-11-11 19:49 - 00020868 _____ () C:\Users\Dave\Downloads\FRST.txt

    2014-11-11 19:42 - 2014-11-11 19:43 - 00000000 ____D () C:\FRST

    2014-11-11 19:41 - 2014-11-11 19:41 - 02116096 _____ (Farbar) C:\Users\Dave\Downloads\FRST64.exe

    2014-11-11 19:39 - 2014-11-11 19:39 - 00025371 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141111193818

    2014-11-10 20:38 - 2014-11-10 20:38 - 00854448 _____ () C:\Users\Dave\Desktop\SecurityCheck.exe

    2014-11-10 20:36 - 2014-11-10 20:36 - 00602112 _____ (OldTimer Tools) C:\Users\Dave\Desktop\OTL.com

    2014-11-10 20:33 - 2014-11-10 20:34 - 00688992 _____ (Swearware) C:\Users\Dave\Downloads\dds (1).com

    2014-11-10 20:32 - 2014-11-10 20:32 - 00688992 _____ (Swearware) C:\Users\Dave\Downloads\dds.scr

    2014-11-10 20:30 - 2014-11-10 20:30 - 00688992 _____ (Swearware) C:\Users\Dave\Downloads\dds.com

    2014-11-10 20:21 - 2014-11-10 20:21 - 00003282 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-1002

    2014-11-10 20:20 - 2014-11-10 20:20 - 00003334 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002

    2014-11-10 20:16 - 2014-11-11 19:39 - 00124421 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141110201537

    2014-11-09 21:32 - 2014-11-09 21:32 - 00000000 ____D () C:\Users\Dave\Downloads\Scan

    2014-11-09 21:18 - 2014-11-10 20:16 - 00033834 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141109211734

    2014-11-09 20:16 - 2014-11-11 19:39 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys

    2014-11-09 20:15 - 2014-11-09 20:15 - 00001078 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

    2014-11-09 20:15 - 2014-11-09 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

    2014-11-09 20:14 - 2014-11-09 20:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware

    2014-11-09 20:14 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys

    2014-11-09 20:14 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys

    2014-11-09 20:14 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys

    2014-11-09 20:12 - 2014-11-09 20:13 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Dave\Downloads\mbam-setup-2.0.3.1025.exe

    2014-11-09 20:10 - 2014-11-09 20:10 - 00001515 _____ () C:\Users\Dave\Desktop\JRT.txt

    2014-11-09 19:55 - 2014-11-09 19:55 - 01706808 _____ (Thisisu) C:\Users\Dave\Downloads\JRT (1).exe

    2014-11-09 19:47 - 2014-11-09 19:47 - 00108693 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141109194611

    2014-11-09 19:13 - 2014-11-09 19:13 - 00038679 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141109191234

    2014-11-09 19:05 - 2014-11-09 19:06 - 01706808 _____ (Thisisu) C:\Users\Dave\Downloads\JRT.exe

    2014-11-09 19:04 - 2014-11-09 19:44 - 00000000 ____D () C:\AdwCleaner

    2014-11-09 19:03 - 2014-11-09 19:03 - 02140160 _____ () C:\Users\Dave\Downloads\adwcleaner_4.101 (1).exe

    2014-11-09 18:51 - 2014-11-09 18:51 - 00025377 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141109185022

    2014-11-09 18:46 - 2014-11-09 16:58 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe

    2014-11-09 18:09 - 2014-11-09 18:53 - 00000000 ____D () C:\zoek

    2014-11-09 17:02 - 2014-11-09 18:53 - 00027017 _____ () C:\zoek-results.log

    2014-11-09 16:58 - 2014-11-09 18:33 - 00000000 ____D () C:\zoek_backup

    2014-11-09 16:41 - 2014-11-09 16:59 - 00000000 ____D () C:\Users\Dave\Downloads\zoek

    2014-11-09 16:40 - 2014-11-09 16:41 - 04124640 _____ () C:\Users\Dave\Downloads\zoek.zip

    2014-11-09 04:41 - 2014-11-09 04:41 - 01023708 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141109044052

    2014-11-08 04:41 - 2014-11-09 04:41 - 01738235 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141108044053

    2014-11-07 14:57 - 2014-11-08 04:41 - 00994658 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141107145630

    2014-11-06 19:57 - 2014-11-07 14:57 - 00102692 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141106195626

    2014-11-05 21:42 - 2014-11-06 19:57 - 00003634 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141105214132

    2014-11-05 19:15 - 2014-11-05 19:15 - 00176385 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141105191432

    2014-11-04 03:14 - 2014-11-05 19:15 - 01378478 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141104031446

    2014-11-03 03:14 - 2014-11-04 03:14 - 01738366 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141103031446

    2014-11-02 20:16 - 2014-11-03 03:14 - 00504737 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141102201553

    2014-11-02 08:53 - 2014-11-02 08:51 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe

    2014-11-02 08:52 - 2014-11-02 08:52 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll

    2014-11-02 08:52 - 2014-11-02 08:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

    2014-11-02 08:52 - 2014-11-02 08:51 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe

    2014-11-02 08:52 - 2014-11-02 08:51 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe

    2014-11-02 08:51 - 2014-11-02 08:51 - 00000000 ____D () C:\Program Files (x86)\Java

    2014-11-02 07:48 - 2014-11-02 07:48 - 00901277 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141102074757

    2014-11-02 00:49 - 2014-11-02 07:48 - 00505736 _____ () C:\WINDOWS\SysWOW64\rsslogs.20141102014845

    2014-10-25 21:14 - 2014-10-25 21:14 - 00641609 _____ () C:\Users\Dave\Downloads\201410259516330395001.3gp

    2014-10-24 18:32 - 2014-10-24 18:32 - 00001755 _____ () C:\Users\Public\Desktop\iTunes.lnk

    2014-10-24 18:28 - 2014-10-24 18:32 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7

    2014-10-24 17:34 - 2014-10-24 17:34 - 00001817 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk

    2014-10-19 07:40 - 2014-10-19 07:40 - 13781330 _____ () C:\Users\Dave\Downloads\20141018_194348.mp4

    2014-10-15 20:12 - 2014-09-29 15:45 - 00706016 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe

    2014-10-15 20:12 - 2014-09-29 15:45 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

    2014-10-14 19:40 - 2014-09-27 15:25 - 04183040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys

    2014-10-14 19:39 - 2014-09-18 19:25 - 23631360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

    2014-10-14 19:39 - 2014-09-18 18:44 - 17484800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

    2014-10-14 19:38 - 2014-09-25 15:50 - 13619200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

    2014-10-14 19:38 - 2014-09-25 15:46 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll

    2014-10-14 19:38 - 2014-09-25 15:46 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll

    2014-10-14 19:38 - 2014-09-25 15:43 - 11807232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

    2014-10-14 19:38 - 2014-09-25 15:32 - 02017280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl

    2014-10-14 19:38 - 2014-09-25 15:31 - 02108416 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl

    2014-10-14 19:38 - 2014-09-18 18:41 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

    2014-10-14 19:38 - 2014-09-18 18:40 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll

    2014-10-14 19:38 - 2014-09-18 18:38 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll

    2014-10-14 19:38 - 2014-09-18 18:36 - 05829632 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

    2014-10-14 19:38 - 2014-09-18 18:25 - 04201472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

    2014-10-14 19:38 - 2014-09-18 18:25 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll

    2014-10-14 19:38 - 2014-09-18 18:02 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

    2014-10-14 19:38 - 2014-09-18 18:00 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll

    2014-10-14 19:38 - 2014-09-18 17:59 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll

    2014-10-14 19:38 - 2014-09-18 17:58 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll

    2014-10-14 19:38 - 2014-09-18 17:55 - 02187264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

    2014-10-14 19:38 - 2014-09-18 17:42 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll

    2014-10-14 19:38 - 2014-09-18 17:42 - 00710656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe

    2014-10-14 19:38 - 2014-09-18 17:42 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll

    2014-10-14 19:38 - 2014-09-18 17:33 - 02309632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll

    2014-10-14 19:38 - 2014-09-18 17:20 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll

    2014-10-14 19:38 - 2014-09-18 17:20 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll

    2014-10-14 19:38 - 2014-09-18 17:14 - 01447936 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll

    2014-10-14 19:38 - 2014-09-18 16:59 - 01810944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll

    2014-10-14 19:38 - 2014-09-18 16:59 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll

    2014-10-14 19:38 - 2014-09-18 16:53 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

    2014-10-14 19:38 - 2014-09-18 16:52 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll

    2014-10-14 19:36 - 2014-09-07 20:15 - 00054752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe

    2014-10-14 19:36 - 2014-09-07 18:46 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll

    2014-10-14 19:36 - 2014-09-07 18:46 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll

    2014-10-14 19:36 - 2014-09-07 17:08 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe

    2014-10-14 19:36 - 2014-09-07 17:07 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll

    2014-10-14 19:36 - 2014-09-07 17:05 - 03448320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll

    2014-10-14 19:36 - 2014-09-07 17:04 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll

    2014-10-14 19:36 - 2014-09-07 17:04 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll

    2014-10-14 19:36 - 2014-09-07 17:03 - 01702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll

    2014-10-14 19:36 - 2014-09-07 17:03 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll

    2014-10-14 19:36 - 2014-09-07 16:59 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll

    2014-10-14 19:36 - 2014-09-07 16:59 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe

    2014-10-14 19:36 - 2014-09-07 16:56 - 00672256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll

    2014-10-14 19:36 - 2014-09-07 16:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll

    2014-10-14 19:36 - 2014-09-03 17:10 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll

    2014-10-14 19:36 - 2014-09-03 16:57 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll

    2014-10-14 19:36 - 2014-09-03 16:49 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll

    2014-10-14 19:34 - 2014-10-09 15:16 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll

    2014-10-14 19:34 - 2014-10-08 15:09 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll

    2014-10-14 19:34 - 2014-09-18 18:24 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll

    2014-10-14 19:34 - 2014-09-12 23:29 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll

    2014-10-14 19:34 - 2014-09-12 22:49 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll

    2014-10-14 19:34 - 2014-08-15 21:08 - 21195616 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll

    2014-10-14 19:34 - 2014-08-15 21:08 - 01507648 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll

    2014-10-14 19:34 - 2014-08-15 21:01 - 01710184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll

    2014-10-14 19:34 - 2014-08-15 20:58 - 01112512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll

    2014-10-14 19:34 - 2014-08-15 20:57 - 02498880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys

    2014-10-14 19:34 - 2014-08-15 20:57 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS

    2014-10-14 19:34 - 2014-08-15 20:16 - 18722600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

    2014-10-14 19:34 - 2014-08-15 20:16 - 01205976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll

    2014-10-14 19:34 - 2014-08-15 20:03 - 01467384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll

    2014-10-14 19:34 - 2014-08-15 18:31 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll

    2014-10-14 19:34 - 2014-08-15 18:04 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll

    2014-10-14 19:34 - 2014-08-15 17:58 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll

    2014-10-14 19:34 - 2014-08-15 17:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll

    2014-10-14 19:34 - 2014-08-15 17:46 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll

    2014-10-14 19:34 - 2014-08-15 17:45 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll

    2014-10-14 19:34 - 2014-08-15 17:43 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll

    2014-10-14 19:34 - 2014-08-15 17:43 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll

    2014-10-14 19:34 - 2014-08-15 17:31 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll

    2014-10-14 19:34 - 2014-08-15 17:31 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll

    2014-10-14 19:34 - 2014-08-15 17:29 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll

    2014-10-14 19:34 - 2014-08-15 17:23 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll

    2014-10-14 19:34 - 2014-08-15 17:22 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll

    2014-10-14 19:34 - 2014-08-15 17:22 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll

    2014-10-14 19:34 - 2014-08-15 17:19 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll

    2014-10-14 19:34 - 2014-08-15 17:18 - 04758528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll

    2014-10-14 19:34 - 2014-08-15 17:17 - 08757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll

    2014-10-14 19:34 - 2014-08-15 17:14 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll

    2014-10-14 19:34 - 2014-08-15 17:13 - 06649344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll

    2014-10-14 19:34 - 2014-08-15 17:13 - 05902848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll

    2014-10-14 19:34 - 2014-08-15 17:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll

    2014-10-14 19:34 - 2014-08-15 17:11 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll

    2014-10-14 19:34 - 2014-08-15 17:10 - 01120768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe

    2014-10-14 19:34 - 2014-08-15 17:08 - 05777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll

    2014-10-14 19:34 - 2014-08-15 17:07 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll

    2014-10-14 19:34 - 2014-07-31 16:22 - 00388729 _____ () C:\WINDOWS\system32\ApnDatabase.xml

    2014-10-14 19:33 - 2014-09-03 17:12 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll

    2014-10-14 19:33 - 2014-09-03 17:01 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll

    2014-10-14 19:23 - 2014-09-12 23:02 - 02779648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll

    2014-10-14 19:23 - 2014-09-12 22:30 - 03117568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll

    2014-10-14 19:23 - 2014-08-28 16:56 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll

    2014-10-14 19:23 - 2014-08-28 16:47 - 02321920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll

    2014-10-14 19:22 - 2014-08-28 18:58 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll

     

    ==================== One Month Modified Files and Folders =======

     

    (If an entry is included in the fixlist, the file\folder will be moved.)

     

    2014-11-11 19:52 - 2013-03-26 19:20 - 00000350 _____ () C:\WINDOWS\Tasks\HP Photo Creations Communicator.job

    2014-11-11 19:45 - 2012-12-25 18:55 - 00003914 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6734F1F0-3039-47CD-A28F-2E62C34206E1}

    2014-11-11 19:39 - 2014-01-22 01:30 - 01172533 _____ () C:\WINDOWS\WindowsUpdate.log

    2014-11-11 19:38 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\system32\sru

    2014-11-10 21:31 - 2013-01-04 16:51 - 00000330 _____ () C:\WINDOWS\Tasks\PrintProjects Communicator.job

    2014-11-10 21:14 - 2012-12-25 12:14 - 00000908 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

    2014-11-10 21:13 - 2013-01-20 12:35 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job

    2014-11-10 20:21 - 2012-12-25 19:01 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2989837996-1790684633-2971567215-1002

    2014-11-10 20:17 - 2014-01-22 06:14 - 00000000 __RDO () C:\Users\Dave\SkyDrive

    2014-11-09 21:17 - 2013-11-14 00:20 - 00030068 _____ () C:\WINDOWS\PFRO.log

    2014-11-09 21:17 - 2013-08-22 07:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT

    2014-11-09 20:14 - 2013-10-26 22:07 - 00000000 ____D () C:\ProgramData\Malwarebytes

    2014-11-09 19:11 - 2013-08-22 06:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI

    2014-11-09 18:57 - 2013-11-14 00:28 - 00956540 _____ () C:\WINDOWS\system32\PerfStringBackup.INI

    2014-11-09 18:50 - 2014-08-08 10:32 - 00000008 __RSH () C:\ProgramData\ntuser.pol

    2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google

    2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo

    2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google

    2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo

    2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Dave\AppData\Local\Comodo

    2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google

    2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo

    2014-11-09 18:28 - 2012-12-25 12:13 - 00000000 ____D () C:\Users\Dave\AppData\Local\Google

    2014-11-09 18:12 - 2013-08-22 08:36 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy

    2014-11-09 18:12 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy

    2014-11-09 16:31 - 2014-03-01 19:54 - 00002980 _____ () C:\WINDOWS\System32\Tasks\LAUNCH CDPCO

    2014-11-07 16:59 - 2013-01-17 21:51 - 00003154 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForDave

    2014-11-07 16:59 - 2013-01-17 21:51 - 00000342 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForDave.job

    2014-11-06 20:03 - 2014-09-24 19:17 - 00003356 _____ () C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002

    2014-11-05 20:16 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\AppReadiness

    2014-11-05 19:23 - 2013-01-16 18:08 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log

    2014-11-05 19:22 - 2013-01-16 18:08 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt

    2014-11-04 20:42 - 2014-02-18 20:35 - 00387072 ___SH () C:\Users\Dave\Downloads\Thumbs.db

    2014-11-02 00:47 - 2014-03-02 14:28 - 00000532 _____ () C:\WINDOWS\system32\ASOROSet.bin

    2014-11-02 00:47 - 2013-08-22 06:25 - 83886080 _____ () C:\WINDOWS\system32\config\SOFTWARE.bak

    2014-11-02 00:47 - 2013-08-22 06:25 - 00024576 _____ () C:\WINDOWS\system32\config\SECURITY.bak

    2014-11-02 00:46 - 2013-08-22 06:25 - 00061440 _____ () C:\WINDOWS\system32\config\SAM.bak

    2014-10-30 04:25 - 2014-01-24 10:53 - 00275080 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

    2014-10-28 18:55 - 2013-08-21 10:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection

    2014-10-24 18:32 - 2014-05-19 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes

    2014-10-24 18:32 - 2014-02-28 19:07 - 00000000 ____D () C:\Program Files\iTunes

    2014-10-24 18:32 - 2014-02-28 19:07 - 00000000 ____D () C:\Program Files (x86)\iTunes

    2014-10-24 18:28 - 2014-02-28 19:07 - 00000000 ____D () C:\Program Files\iPod

    2014-10-24 18:28 - 2013-06-21 20:50 - 00000000 ____D () C:\Program Files\Common Files\Apple

    2014-10-24 17:35 - 2014-02-28 18:43 - 00000000 ____D () C:\Program Files (x86)\QuickTime

    2014-10-24 17:34 - 2014-02-28 18:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime

    2014-10-18 10:44 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\system32\NDF

    2014-10-16 23:28 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\rescache

    2014-10-15 20:10 - 2013-08-22 07:44 - 01797088 _____ () C:\WINDOWS\system32\FNTCACHE.DAT

    2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ___RD () C:\WINDOWS\ToastData

    2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\WinStore

    2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\MediaViewer

    2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\FileManager

    2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\Camera

    2014-10-15 20:02 - 2012-07-26 00:59 - 00000000 ____D () C:\WINDOWS\CbsTemp

    2014-10-15 19:49 - 2014-07-13 20:34 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel

    2014-10-14 20:15 - 2013-08-17 00:14 - 00000000 ____D () C:\WINDOWS\system32\MRT

    2014-10-14 20:05 - 2012-12-26 21:49 - 103265616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

    2014-10-13 17:02 - 2012-12-26 19:31 - 00289656 _____ (IBM Corp.) C:\WINDOWS\system32\Drivers\RapportHades64.sys

    2014-10-13 17:02 - 2012-12-26 19:30 - 00534104 _____ (IBM Corp.) C:\WINDOWS\system32\Drivers\RapportKE64.sys

     

    Some content of TEMP:

    ====================

    C:\Users\Dave\AppData\Local\Temp\Quarantine.exe

    C:\Users\Dave\AppData\Local\Temp\sqlite3.dll

     

     

    ==================== Bamital & volsnap Check =================

     

    (There is no automatic fix for files that do not pass verification.)

     

    C:\Windows\System32\winlogon.exe => File is digitally signed

    C:\Windows\System32\wininit.exe => File is digitally signed

    C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.

    C:\Windows\explorer.exe => File is digitally signed

    C:\Windows\SysWOW64\explorer.exe => File is digitally signed

    C:\Windows\System32\svchost.exe => File is digitally signed

    C:\Windows\SysWOW64\svchost.exe => File is digitally signed

    C:\Windows\System32\services.exe => File is digitally signed

    C:\Windows\System32\User32.dll => File is digitally signed

    C:\Windows\SysWOW64\User32.dll => File is digitally signed

    C:\Windows\System32\userinit.exe => File is digitally signed

    C:\Windows\SysWOW64\userinit.exe => File is digitally signed

    C:\Windows\System32\rpcss.dll => File is digitally signed

    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

     

     

    LastRegBack: 2014-11-09 19:44

     

    ==================== End Of Log ============================

  6. Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2014

    Ran by Dave at 2014-11-11 20:03:30

    Running from C:\Users\Dave\Downloads

    Boot Mode: Normal

    ==========================================================

     

     

    ==================== Security Center ========================

     

    (If an entry is included in the fixlist, it will be removed.)

     

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

     

    ==================== Installed Programs ======================

     

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

     

    64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden

    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)

    Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)

    Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)

    Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.)

    aiofw (x32 Version: 4.2.6.8 - Eastman Kodak Company) Hidden

    aioprnt (Version: 4.2.7.4 - Eastman Kodak Company) Hidden

    aioscnnr (x32 Version: 4.2.6.0 - Your Company Name) Hidden

    AMD Catalyst Install Manager (HKLM\...\{63ADEC24-A374-80A8-E89B-BE401C787F75}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)

    Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)

    Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)

    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)

    AVG 2013 (HKLM\...\AVG) (Version: 2013.0.3392 - AVG Technologies)

    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)

    BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden

    C309a (x32 Version: 140.0.846.000 - Hewlett-Packard) Hidden

    center (x32 Version: 4.2.6.8 - Eastman Kodak Company) Hidden

    Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

    CorelDRAW 10 (HKLM-x32\...\CorelDRAW 10) (Version:  - )

    CorelDRAW 10 (x32 Version: 10 - Corel) Hidden

    CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1.5407 - CyberLink Corp.)

    CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)

    CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.1.1926 - CyberLink Corp.)

    CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.)

    CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.)

    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

    Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden

    DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden

    DocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) Hidden

    Dropbox (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)

    Dropbox (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)

    Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)

    Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden

    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)

    Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)

    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden

    Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden

    GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden

    H&R Block Deluxe + Efile 2012 (HKLM-x32\...\{89D20029-0578-4D8D-979A-695C8D868868}) (Version: 12.04.7803 - HRB Technology, LLC.)

    H&R Block Deluxe + Efile 2013 (HKLM-x32\...\{AD9F55C5-93F8-4CAB-A311-77C195912CA4}) (Version: 13.04.5801 - HRB Technology, LLC.)

    Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden

    HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)

    HP Documentation (HKLM-x32\...\{D23CA718-0356-41F2-8E6A-B5C6CD383EF7}) (Version: 1.1.0.0 - Hewlett-Packard)

    HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)

    HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)

    HP MyRoom (HKLM-x32\...\{9C35EDE5-4B0F-45E7-A438-314BA889948E}) (Version: 9.0.0.0 - Hewlett-Packard Company)

    HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.11502 - HP)

    HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6 (HKLM\...\{F089B734-1356-484F-A7B8-1B78F1616A15}) (Version: 14.0 - HP)

    HP Quick Launch (HKLM-x32\...\{4ED7050C-9332-4FB2-AB07-E94F25A53D39}) (Version: 3.0.3 - Hewlett-Packard Company)

    HP Registration Service (HKLM\...\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard)

    HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)

    HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)

    HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)

    HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)

    HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard)

    HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.5.1 - Hewlett-Packard Company)

    HPDetect (HKLM-x32\...\{CCCDD476-98F9-4B06-91DB-23F27CEC3BE1}) (Version: 1.0.0.0 - HP)

    HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden

    HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden

    HRBlockDirect version 1.1.2.0 (HKLM-x32\...\{631EFC00-5A7A-4A90-9578-039EDA92DE0F}_is1) (Version: 1.1.2.0 - HRBlock)

    iCloud (HKLM\...\{6096C0CC-7E19-4355-87F0-627EC5AA146D}) (Version: 4.0.3.56 - Apple Inc.)

    IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6423.0 - IDT)

    iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)

    Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)

    KODAK AiO Home Center (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 4.2.7.7 - Eastman Kodak Company)

    ksDIP (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden

    Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)

    MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden

    Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)

    Microsoft Office XP Media Content (HKLM-x32\...\{90300409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2619.0 - Microsoft Corporation)

    Microsoft Office XP Professional (HKLM-x32\...\{91110409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)

    Microsoft OneDrive (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)

    Microsoft OneDrive (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)

    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)

    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)

    MyCleanPC PC Optimizer (HKLM-x32\...\{6AAEB4CB-0573-41ec-89B0-0FE0D5134A8B}_is1) (Version: 2.0.648.15539 - USTechSupport)

    Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden

    OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)

    OpenOffice.org 3.4.1 (HKLM-x32\...\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)

    Pdf995 (installed by H&R Block) (HKLM-x32\...\Pdf995) (Version:  - )

    PdfEdit995 (installed by H&R Block) (HKLM-x32\...\PdfEdit995) (Version:  - )

    PreReq (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden

    PrintProjects (HKLM-x32\...\PrintProjects) (Version: 1.0.0.12842 - RocketLife Inc.)

    PS_AIO_05_C309_Software_Min (x32 Version: 140.0.855.000 - Hewlett-Packard) Hidden

    QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)

    Ralink RT5390R 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.2.0 - Ralink)

    Rapport (x32 Version: 3.5.1404.21 - Trusteer) Hidden

    RealDownloader (x32 Version: 17.0.8 - RealNetworks, Inc.) Hidden

    RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden

    RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden

    RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden

    RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.8 - RealNetworks)

    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)

    Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.28123 - Realtek Semiconductor Corp.)

    RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden

    SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)

    SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)

    Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden

    Skypeâ„¢ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)

    SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden

    Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden

    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden

    Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated)

    The Weather Channel App (HKLM-x32\...\{167158CE-1637-4167-8A1C-C2549EEA966A}) (Version: 1.00.0000 - The Weather Channel)

    Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden

    TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden

    Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1404.21 - Trusteer)

    UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden

    US Tech Support Framework (HKLM-x32\...\{4734A746-A503-4B8E-A4FA-7B7C84A18D79}) (Version: 2.1.0.4741 - US Tech Support LLC)

    WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden

    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)

     

    ==================== Custom CLSID (selected items): ==========================

     

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

     

     

    ==================== Restore Points  =========================

     

    02-11-2014 06:28:59 MyCleanPCPCOptimizer_BeforeFixingIssues

    02-11-2014 15:49:06 Installed Java 7 Update 71

    04-11-2014 03:19:30 Activeris AntiMalware

    09-11-2014 07:29:56 MyCleanPCPCOptimizer_BeforeFixingIssues

    10-11-2014 00:02:47 zoek.exe restore point

     

    ==================== Hosts content: ==========================

     

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

     

    2012-07-25 22:26 - 2013-11-02 08:48 - 00000098 ____A C:\WINDOWS\system32\Drivers\etc\hosts

    127.0.0.1       localhost

    ::1       localhost

     

    ==================== Scheduled Tasks (whitelisted) =============

     

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

     

    Task: {0CE77290-6C90-4736-8A58-ADA98B3D4E12} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-24] (Synaptics Incorporated)

    Task: {16A4324C-A396-460A-BB02-5C5463E8CF52} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-2989837996-1790684633-2971567215-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe

    Task: {2F479EB9-097F-4D4E-AAEE-3BB23DACCCF2} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-03-26] ()

    Task: {31039BA7-AB5C-4759-AD4D-DFEBBD5223C0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)

    Task: {372FF955-5904-477D-B8E2-D6ACC04F4DD5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-09-22] (Hewlett-Packard)

    Task: {384730F8-58C1-4DF6-97C0-F1F4079B17A2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-10-14] (Microsoft Corporation)

    Task: {3C28E809-DD74-4E2D-8800-2A1359D2FF2E} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)

    Task: {45677C94-4A54-493B-A37F-06620638B55C} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)

    Task: {4ADA22F5-E7E9-4EE7-9FAB-29776C108B45} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-03-15] (RealNetworks, Inc.)

    Task: {729E0FE4-EA3F-4B2E-9E54-665A6EB6729D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)

    Task: {8D94B28D-7FF3-4333-AF99-E815A96CBAB7} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-03-20] (RealNetworks, Inc.)

    Task: {91760CEA-8DCD-4D98-A587-809BC244CD34} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-09-22] (Hewlett-Packard)

    Task: {95FD93E0-88E4-4373-BE4C-61CC5001D987} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2013-11-04] (Hewlett-Packard Company)

    Task: {9B4764CB-0DB0-47A2-9B8A-E23FF553C9ED} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)

    Task: {A41E952D-CE82-42D6-A8C1-8A70C4D97971} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)

    Task: {B78FBC55-3ACA-4BAE-B1D5-364936955538} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)

    Task: {C2389E22-D793-4EB6-BC58-7BF1B3B5AEBF} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink)

    Task: {C258507F-A465-4E0C-A6F4-7EB34EC86A59} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)

    Task: {C3C594CE-E07F-4415-B1F3-4B556B528F08} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)

    Task: {C5BEE337-92EC-48E5-9C6B-E99BCF5B859F} - System32\Tasks\PrintProjects Communicator => C:\ProgramData\PrintProjects\Communicator.exe [2013-12-21] ()

    Task: {C7DF08C9-42F4-424C-800D-1EE5F9C9CE92} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)

    Task: {CC909D9E-E254-4E3C-9807-BF59C9AD6C3D} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-03-20] (RealNetworks, Inc.)

    Task: {CFBAE89D-2978-4694-B039-D1C96BB5AC41} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup

    Task: {E06C2A65-1770-463B-9155-9683771261F1} - System32\Tasks\LAUNCH CDPCO => C:\Program Files (x86)\USTechSupport\PC Optimizer\USTSPCO.exe

    Task: {F41AFF04-916A-4ACF-B121-8B926E2467A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)

    Task: {F6306C56-C5E2-402B-AAEB-5402514EC1C6} - System32\Tasks\HPCeeScheduleForDave => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)

    Task: {FABDB386-48DE-4D30-B843-40CB0CE82A31} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    Task: {FAE1F865-9DFE-4285-A82D-5721E836B5F8} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-07] (CyberLink)

    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    Task: C:\WINDOWS\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe

    Task: C:\WINDOWS\Tasks\HPCeeScheduleForDave.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

    Task: C:\WINDOWS\Tasks\PrintProjects Communicator.job => C:\ProgramData\PrintProjects\Communicator.exe

    Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

     

    ==================== Loaded Modules (whitelisted) =============

     

    2014-02-05 13:14 - 2012-04-26 15:51 - 00040448 _____ () C:\WINDOWS\System32\pdf995mon64.dll

    2012-08-06 12:09 - 2012-08-06 12:09 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll

    2014-03-15 02:18 - 2014-03-15 02:18 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

    2014-03-20 20:13 - 2014-03-20 20:13 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

    2014-04-27 18:04 - 2014-04-27 18:04 - 00043520 _____ () C:\Users\Dave\AppData\Local\Packages\53987rbl3.financehelper_z2nrd37h46pd8\AC\Microsoft\CLR_v4.0\NativeImages\Tasks\9e3e7a9b672757fec0f0b3de7245f539\Tasks.ni.dll

    2014-10-16 23:24 - 2014-10-16 23:24 - 01782784 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\3f4dc590466037f015f65bc07d1ea923\Windows.ApplicationModel.ni.dll

    2014-04-27 18:04 - 2014-04-27 18:04 - 00348672 _____ () C:\Users\Dave\AppData\Local\Packages\53987rbl3.financehelper_z2nrd37h46pd8\AC\Microsoft\CLR_v4.0\NativeImages\Notificatioc5a47191#\39274f50b85b30f3b823e5dd99be667c\NotificationsExtensions.ni.dll

    2014-10-16 23:24 - 2014-10-16 23:24 - 00521216 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Data\fae2b750f87849ca11806d20b2504bf2\Windows.Data.ni.dll

    2014-10-16 23:24 - 2014-10-16 23:24 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\4bd80968bf666252841ca7792faaff11\Windows.UI.ni.dll

    2014-09-14 10:01 - 2014-09-14 10:01 - 00088576 _____ () C:\Users\Dave\AppData\Local\Packages\53987rbl3.financehelper_z2nrd37h46pd8\AC\Microsoft\CLR_v4.0\NativeImages\SharedDataLink\846b13847670d6d4ee629471089a53d7\SharedDataLink.ni.dll

    2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

    2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

    2014-03-23 16:04 - 2014-03-23 16:04 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll

    2012-09-15 07:31 - 2012-06-07 20:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll

    2012-06-08 11:34 - 2012-06-08 11:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll

    2014-07-19 09:26 - 2014-07-15 02:24 - 00718664 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll

    2014-07-19 09:26 - 2014-07-15 02:24 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll

    2014-07-19 09:26 - 2014-07-15 02:24 - 08537928 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll

    2014-07-19 09:26 - 2014-07-15 02:24 - 00353096 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll

    2014-07-19 09:26 - 2014-07-15 02:24 - 01732936 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll

    2014-07-19 09:26 - 2014-07-15 02:24 - 14664008 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll

     

    ==================== Alternate Data Streams (whitelisted) =========

     

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

     

    AlternateDataStreams: C:\ProgramData\Temp:373E1720

    AlternateDataStreams: C:\Users\Dave\OneDrive:ms-properties

    AlternateDataStreams: C:\Users\Dave\SkyDrive:ms-properties

     

    ==================== Safe Mode (whitelisted) ===================

     

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

     

     

    ==================== EXE Association (whitelisted) =============

     

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

     

     

    ==================== MSCONFIG/TASK MANAGER disabled items =========

     

    (Currently there is no automatic fix for this section.)

     

    HKLM\...\StartupApproved\StartupFolder: => "Microsoft Office.lnk"

    HKLM\...\StartupApproved\StartupFolder: => "AtHomeConnect.lnk"

    HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"

    HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"

    HKLM\...\StartupApproved\StartupFolder: => "HRBlockDirect.lnk"

    HKLM\...\StartupApproved\StartupFolder: => "RealPlayer Cloud Service UI.lnk"

    HKLM\...\StartupApproved\Run32: => "APSDaemon"

    HKLM\...\StartupApproved\Run32: => "Conime"

    HKLM\...\StartupApproved\Run32: => "QuickTime Task"

    HKLM\...\StartupApproved\Run32: => "Corel Reminder"

    HKLM\...\StartupApproved\Run32: => "AVG_UI"

    HKLM\...\StartupApproved\Run32: => "HP Software Update"

    HKLM\...\StartupApproved\Run32: => "iTunesHelper"

    HKLM\...\StartupApproved\Run32: => "TkBellExe"

    HKLM\...\StartupApproved\Run32: => "ApnTBMon"

    HKLM\...\StartupApproved\Run32: => "BrowserSafeguard"

    HKLM\...\StartupApproved\Run32: => "VNT"

    HKCU\...\StartupApproved\StartupFolder: => "OpenOffice.org 3.4.1.lnk"

    HKCU\...\StartupApproved\StartupFolder: => "Dropbox.lnk"

    HKCU\...\StartupApproved\StartupFolder: => "PalTalk.lnk"

    HKCU\...\StartupApproved\Run: => "Skype"

    HKCU\...\StartupApproved\Run: => "DW7"

     

    ========================= Accounts: ==========================

     

    Administrator (S-1-5-21-2989837996-1790684633-2971567215-500 - Administrator - Disabled)

    Dave (S-1-5-21-2989837996-1790684633-2971567215-1002 - Administrator - Enabled) => C:\Users\Dave

    Guest (S-1-5-21-2989837996-1790684633-2971567215-501 - Limited - Disabled)

    HomeGroupUser$ (S-1-5-21-2989837996-1790684633-2971567215-1010 - Limited - Enabled)

     

    ==================== Faulty Device Manager Devices =============

     

     

    ==================== Event log errors: =========================

     

    Application errors:

    ==================

    Error: (11/11/2014 07:48:39 PM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

     

    Process ID: 300

     

    Start Time: 01cffe21b9838d0e

     

    Termination Time: 4294967295

     

    Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe

     

    Report Id: 60fea05d-6a16-11e4-bf3d-c8cbb8b06c44

     

    Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe

     

    Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1

     

    Error: (11/10/2014 08:28:20 PM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: The program wwahost.exe version 6.3.9600.17031 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

     

    Process ID: 14f8

     

    Start Time: 01cffd5e0d10df01

     

    Termination Time: 4294967295

     

    Application Path: C:\WINDOWS\system32\wwahost.exe

     

    Report Id: 00cf954a-6952-11e4-bf3d-c8cbb8b06c44

     

    Faulting package full name: AD2F1837.HPConnectedPhotopoweredbySnapfish_2.5.6.4614_neutral__v10z8vjag6ke6

     

    Faulting package-relative application ID: App

     

    Error: (11/10/2014 08:23:22 PM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

     

    Process ID: c4

     

    Start Time: 01cffd5e0d1808f7

     

    Termination Time: 4294967295

     

    Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe

     

    Report Id: 00d45714-6952-11e4-bf3d-c8cbb8b06c44

     

    Faulting package full name: 53987RBL3.FinanceHelper_1.1.0.73_neutral__z2nrd37h46pd8

     

    Faulting package-relative application ID: App

     

     

    System errors:

    =============

    Error: (11/09/2014 09:19:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

    Description: The Google Update Service (gupdate) service failed to start due to the following error: 

    %%2

     

    Error: (11/09/2014 09:17:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

    Description: The Kodak AiO Network Discovery Service service failed to start due to the following error: 

    %%1053

     

    Error: (11/09/2014 09:17:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: )

    Description: A timeout was reached (30000 milliseconds) while waiting for the Kodak AiO Network Discovery Service service to connect.

     

     

    Microsoft Office Sessions:

    =========================

    Error: (11/11/2014 07:48:39 PM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: LiveComm.exe17.5.9600.2060530001cffe21b9838d0e4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe60fea05d-6a16-11e4-bf3d-c8cbb8b06c44microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

     

    Error: (11/10/2014 08:28:20 PM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: wwahost.exe6.3.9600.1703114f801cffd5e0d10df014294967295C:\WINDOWS\system32\wwahost.exe00cf954a-6952-11e4-bf3d-c8cbb8b06c44AD2F1837.HPConnectedPhotopoweredbySnapfish_2.5.6.4614_neutral__v10z8vjag6ke6App

     

    Error: (11/10/2014 08:23:22 PM) (Source: Application Hang) (EventID: 1002) (User: )

    Description: backgroundTaskHost.exe6.3.9600.16384c401cffd5e0d1808f74294967295C:\WINDOWS\system32\backgroundTaskHost.exe00d45714-6952-11e4-bf3d-c8cbb8b06c4453987RBL3.FinanceHelper_1.1.0.73_neutral__z2nrd37h46pd8App

     

     

    CodeIntegrity Errors:

    ===================================

      Date: 2014-11-10 20:40:36.675

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-11-10 20:40:35.762

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:40.640

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:39.996

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:39.375

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:38.166

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:37.503

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:36.848

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:31.260

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

      Date: 2014-10-26 19:35:30.495

      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

     

     

    ==================== Memory info =========================== 

     

    Processor: AMD E-300 APU with Radeon HD Graphics

    Percentage of memory in use: 52%

    Total physical RAM: 3682.26 MB

    Available physical RAM: 1736.68 MB

    Total Pagefile: 4578.26 MB

    Available Pagefile: 1816.53 MB

    Total Virtual: 131072 MB

    Available Virtual: 131071.75 MB

     

    ==================== Drives ================================

     

    Drive c: () (Fixed) (Total:275.65 GB) (Free:217.97 GB) NTFS ==>[system with boot components (obtained from reading drive)]

    Drive d: (RECOVERY) (Fixed) (Total:21.33 GB) (Free:2.57 GB) NTFS ==>[system with boot components (obtained from reading drive)]

     

    ==================== MBR & Partition Table ==================

     

    ========================================================

    Disk: 0 (Size: 298.1 GB) (Disk ID: C2C9F703)

     

    Partition: GPT Partition Type.

     

    ==================== End Of Log ============================

  7. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Junkware Removal Tool (JRT) by Thisisu

    Version: 6.3.7 (11.08.2014:1)

    OS: Windows 8.1 x64

    Ran by Dave on Sun 11/09/2014 at 19:56:14.64

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

     

     

     

     

    ~~~ Services

     

    Successfully stopped: [service] ustspcodiskoptimizer 

    Successfully deleted: [service] ustspcodiskoptimizer 

    Successfully stopped: [service] ustsscheduler 

    Successfully deleted: [service] ustsscheduler 

     

     

     

    ~~~ Registry Values

     

     

     

    ~~~ Registry Keys

     

    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181102}

     

     

     

    ~~~ Files

     

     

     

    ~~~ Folders

     

    Successfully deleted: [Folder] "C:\ProgramData\pchealthboost"

    Successfully deleted: [Folder] "C:\ProgramData\ustechsupport"

    Successfully deleted: [Folder] "C:\Users\Dave\AppData\Roaming\ustechsupport"

    Successfully deleted: [Folder] "C:\Program Files (x86)\pc healthboost"

    Successfully deleted: [Folder] "C:\Program Files (x86)\ustechsupport"

    Successfully deleted: [Folder] "C:\Program Files (x86)\Common Files\ustechsupport"

    Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mycleanpc"

     

     

     

    ~~~ Event Viewer Logs were cleared

     

     

     

     

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Scan was completed on Sun 11/09/2014 at 20:10:15.20

    End of JRT log

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  8. # AdwCleaner v4.101 - Report created 09/11/2014 at 19:44:32

    # Updated 09/11/2014 by Xplode

    # Database : 2014-11-07.1 [Live]

    # Operating System : Windows 8.1  (64 bits)

    # Username : Dave - LAPTOP

    # Running from : C:\Users\Dave\Downloads\adwcleaner_4.101 (1).exe

    # Option : Clean

     

    ***** [ Services ] *****

     

     

    ***** [ Files / Folders ] *****

     

     

    ***** [ Scheduled Tasks ] *****

     

     

    ***** [ Shortcuts ] *****

     

     

    ***** [ Registry ] *****

     

    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094

    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536

     

    ***** [ Browsers ] *****

     

    -\\ Internet Explorer v11.0.9600.17344

     

    Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]

    Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [search Page]

    Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]

    Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [start Page]

     

    -\\ Mozilla Firefox v

     

     

    -\\ Google Chrome v36.0.1985.125

     











    [C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : blmchfpimpbbdmgpcieclabeafkljbhm

    [C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kdidombaedgpfiiedeimiebkmbilgmlc

    [C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : licjnkifamhpbaefhdpacpmihicfbomb

    [C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : niapdbllcanepiiimjjndipklodoedlc

    [C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma






    [C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo

    [C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg

    [C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : hphibigbodkkohoglgfkddblldpfohjl

    [C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej

    [C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl

    [C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc

    [C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc

     

    *************************

     

    AdwCleaner[R3].txt - [293 octets] - [09/11/2014 19:04:29]

    AdwCleaner[R4].txt - [286 octets] - [09/11/2014 19:10:11]

    AdwCleaner[R5].txt - [7011 octets] - [09/11/2014 19:19:05]

    AdwCleaner[R6].txt - [7849 octets] - [09/11/2014 19:37:16]

    AdwCleaner[s2].txt - [2165 octets] - [09/11/2014 19:35:24]

    AdwCleaner[s3].txt - [7336 octets] - [09/11/2014 19:44:32]

     

    ########## EOF - C:\AdwCleaner\AdwCleaner[s3].txt - [7396 octets] ##########
  9.  

    Zoek.exe v5.0.0.0 Updated 09-November-2014

    Tool run by Dave on Sun 11/09/2014 at 16:58:58.24.

    Microsoft Windows 8.1 6.3.9600  x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Dave\Downloads\zoek\zoek.exe [scan all users]   [Quick Scan] [Auto Clean]

     

    ==== System Restore Info ======================

     

    11/9/2014 5:03:55 PM Zoek.exe System Restore Point Created Succesfully.

     

    ==== Empty Folders Check ======================

     

    C:\PROGRA~2\predm deleted successfully

    C:\PROGRA~2\VNT deleted successfully

    C:\PROGRA~2\COMMON~1\supportdotcom deleted successfully

    C:\PROGRA~2\COMMON~1\SWF Studio deleted successfully

    C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully

    C:\PROGRA~3\cosstminn deleted successfully

    C:\PROGRA~3\Oracle deleted successfully

    C:\Users\Dave\AppData\Roaming\Activeris deleted successfully

    C:\Users\Dave\AppData\Local\CrashDumps deleted successfully

    C:\Users\Dave\AppData\Local\VisualBeeExe deleted successfully

    C:\Users\Dave\AppData\Local\WordOv deleted successfully

     

    ==== Deleting CLSID Registry Keys ======================

     

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6} deleted successfully

     

    ==== Deleting CLSID Registry Values ======================

     

     

    ==== Deleting Services ======================

     

     

    ==== Deleting Files \ Folders ======================

     

    C:\Users\Dave\AppData\LocalLow\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted

    C:\PROGRA~2\cosstminn deleted

    C:\PROGRA~2\Mozilla Firefox\browser\nsprotector.js deleted

    C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml deleted

    C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\sweettunes_search.xml deleted

    C:\PROGRA~2\The Weather Channel deleted

    C:\PROGRA~2\Yahoo! deleted

    C:\PROGRA~2\Optimizer Pro deleted

    C:\PROGRA~2\MyPC Backup deleted

    C:\PROGRA~2\AskPartnerNetwork deleted

    C:\Users\Dave\AppData\Roaming\WB.CFG deleted

    C:\Users\Dave\AppData\Roaming\Yahoo! deleted

    C:\PROGRA~3\AskPartnerNetwork deleted

    C:\PROGRA~3\APN deleted

    C:\PROGRA~3\VisualBee deleted

    C:\PROGRA~3\AVG SafeGuard toolbar deleted

    C:\Users\Dave\AppData\Local\BrowserSafeguard deleted

    C:\Users\Dave\AppData\Local\Systweak deleted

    C:\Users\Dave\AppData\Local\AVG SafeGuard toolbar deleted

    C:\Users\Dave\AppData\Local\emaze deleted

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx deleted

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data-journal deleted

    C:\Users\TEMP\AppData\Local\AVG SafeGuard toolbar deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted

    C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk deleted

    C:\WINDOWS\SysNative\roboot64.exe deleted

    C:\Users\Dave\AppData\LocalLow\AVG SafeGuard toolbar deleted

    C:\Users\TEMP\AppData\LocalLow\AVG SafeGuard toolbar deleted

    C:\WINDOWS\tasks\Groovorio Updater.job deleted

    C:\windows\SysNative\tasks\USTSPCO-USTSPCOOneClickCare deleted

    C:\WINDOWS\tasks\USTSPCO-USTSPCOOneClickCare.job deleted

    C:\components deleted

    C:\WINDOWS\SysNative\config\systemprofile\Searches deleted

    C:\windows\SysNative\GroupPolicy\Machine deleted

    C:\windows\SysNative\GroupPolicy\User deleted

    C:\windows\SysNative\GroupPolicy\GPT.INI deleted

    C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted

    C:\WINDOWS\SysWow64\searchplugins deleted

    C:\WINDOWS\SysWow64\Extensions deleted

    C:\Users\Dave\Documents\Optimizer Pro deleted

    "C:\PROGRA~3\ab34c546d7769ac4\{CE681A67-9477-CBE6-EB9D-FE534875F98D}.20140808113335" deleted

    "C:\PROGRA~3\ab34c546d7769ac4" deleted

    "C:\Users\Dave\AppData\Roaming\Temp" deleted

     

    ==== Files Recently Created / Modified ======================

     

    ====== C:\WINDOWS ====

    ====== C:\Users\Dave\AppData\Local\Temp ====

    ====== Java Cache =====

    ====== C:\WINDOWS\SysWOW64 =====

    2014-11-02 15:53:26 B9F9FD6188CC732F19DB69CAE5CC597C 272808 ----a-w- C:\WINDOWS\SysWOW64\javaws.exe

    2014-11-02 15:52:27 8FA677D5F2AFE2A3F111C50D68A93542 98216 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll

    2014-11-02 15:52:27 3594C0ABBFFE10B3CF95714B8B3C89A4 175528 ----a-w- C:\WINDOWS\SysWOW64\javaw.exe

    2014-11-02 15:52:27 095826BCBBFA5C09C72463A82612B23C 175528 ----a-w- C:\WINDOWS\SysWOW64\java.exe

    ====== C:\WINDOWS\SysWOW64\drivers =====

    ====== C:\WINDOWS\Sysnative =====

    ====== C:\WINDOWS\Sysnative\drivers =====

    2014-10-15 02:34:50 87F3713E620F62D243A82B3CB66CBDDE 2498880 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys

    2014-10-15 02:34:37 329FEB41BBE82FBBD9BD69547BA1CB82 428864 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS

    ====== C:\WINDOWS\Tasks ======

    ====== C:\WINDOWS\Temp ======

    ======= C:\Program Files =====

    ======= C:\PROGRA~2 =====

    2014-11-02 15:51:48 -------- d-----w- C:\PROGRA~2\Java

    ======= C: =====

    ====== C:\Users\Dave\AppData\Roaming ======

    ====== C:\Users\Dave ======

    2014-11-02 18:25:11 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp

    2014-11-02 15:52:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

    2014-10-25 01:28:36 -------- d-----w- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7

     

    ====== C: exe-files ==

    === C: other files ==

     

    ==== Startup Registry Enabled ======================

     

    [HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Run]

    "TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"

    "CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R"

    "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"

    "HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"

    "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    "HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe"

    "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe -osboot"

    "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime"

    "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

     

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

    "TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"

     

    ==== Startup Registry Enabled x64 ======================

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe "

    "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

    "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update"

     

    ==== Startup Folders ======================

     

    2014-05-04 18:29:12 1096 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

    2013-01-07 19:21:07 1239 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk

    2013-03-17 22:43:48 2099 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

    2012-12-28 01:12:20 2015 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk

    2014-04-05 21:43:33 1236 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk

     

    ==== Task Scheduler Jobs ======================

     

    C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/09/2014 01:14 PM]

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe []

    C:\WINDOWS\tasks\HP Photo Creations Communicator.job --a-------- C:\ProgramData\HP Photo Creations\Communicator.exe [03/26/2013 08:02 PM]

    C:\WINDOWS\tasks\HPCeeScheduleForDave.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [07/15/2011 04:43 AM]

    C:\WINDOWS\tasks\PrintProjects Communicator.job --a-------- C:\ProgramData\PrintProjects\Communicator.exe [12/21/2013 03:42 PM]

    C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [08/24/2012 02:38 AM]

     

    ==== Other Scheduled Tasks ======================

     

    "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]

    "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe]

    "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

    "C:\WINDOWS\SysNative\tasks\HP Photo Creations Communicator" [C:\ProgramData\HP Photo Creations\Communicator.exe]

    "C:\WINDOWS\SysNative\tasks\HPCeeScheduleForDave" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe]

    "C:\WINDOWS\SysNative\tasks\LAUNCH CDPCO" [C:\Program Files (x86)\USTechSupport\PC Optimizer\USTSPCO.exe]

    "C:\WINDOWS\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe]

    "C:\WINDOWS\SysNative\tasks\PrintProjects Communicator" [C:\ProgramData\PrintProjects\Communicator.exe]

    "C:\WINDOWS\SysNative\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe]

    "C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]

    "C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]

    "C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe]

    "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{46B47638-2502-497D-8CC1-2C969B303C86}" [C:\Windows\system32\msfeedssync.exe]

    "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{49D05411-CAF0-410C-AA14-1BED537C90A2}" [C:\Windows\system32\msfeedssync.exe]

    "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{6734F1F0-3039-47CD-A28F-2E62C34206E1}" [C:\Windows\system32\msfeedssync.exe]

    "C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]

     

    ==== Firefox Extensions Registry ======================

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]

    "{0FAA5C82-A094-4541-8811-D3361F972A81}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [04/05/2014 02:46 PM]

     

    ==== Firefox Extensions ======================

     

    ProfilePath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default

    - Undetermined - %ProfilePath%\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}

     

    ==== Firefox Plugins ======================

     

    Profilepath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\rt286xcf.default

    3D3CAF586124C4E8102764C8B3063BB6 - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director

    1B05342DC6A8896A90952AF2084620F5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll - RocketLife Secure Plug-In Layer

     

     

    ==== Fake Chromium Profiles Check ======================

     

    Fake profile C:\Users\Administrator\AppData\Local\Torch deleted

    Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted

    Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deleted

    Fake profile C:\Users\Dave\AppData\Local\Torch deleted

    Fake profile C:\Users\Dave\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\Dave\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\Dave\AppData\Local\Chromatic Browser deleted

    Fake profile C:\Users\Guest\AppData\Local\Torch deleted

    Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted

    Fake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\Guest\AppData\Local\Chromatic Browser deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted

     

    ==== Chromium Look ======================

     

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

    blklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]

    blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]

    idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[03/15/2014 02:22 AM]

    mmlkabjddkpgkgfhdhpimhcbonapngoh - C:\Users\Dave\AppData\Local\CRE\mmlkabjddkpgkgfhdhpimhcbonapngoh.crx[]

    pelmeidfhdlhlbjimpabfcbnnojbboma - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx[]

    pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]

     

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions

    blklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]

    blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]

    pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]

     

    Google Drive - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    cosstminn - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfg

    Google Search - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Google Wallet - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    Google Docs - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Chrome In-App Payments service - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    InternetHelper3 - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp

     

    ==== Chromium Startpages ======================

     

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Preferences



     

     

    ==== Chromium Fix ======================

     

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage-journal deleted successfully

    C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pnjnnnhampgflieglcelomcofocioegp deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfg deleted successfully

     

    ==== Set IE to Default ======================

     

    Old Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]



    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]





    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]





     

    New Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]


    "Start Page"="http://www.google.com"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]





    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]





     

    ==== All HKCU SearchScopes ======================

     

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

    {012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"

     

    ==== Deleting CLSID Registry Keys ======================

     

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

    HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

     

    ==== Deleting CLSID Registry Values ======================

     

     

    ==== Reset IE Proxy ======================

     

    Value(s) before fix:

    "ProxyServer"="http=127.0.0.1:13918;https=127.0.0.1:13918"

    "ProxyOverride"="<-loopback>"

    "ProxyEnable"=dword:00000001

     

    Value(s) after fix:

    "ProxyEnable"=dword:00000000

     

    ==== Deleting Registry Keys ======================

     

    HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mmlkabjddkpgkgfhdhpimhcbonapngoh deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfully

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfully

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully

     

    ==== Empty IE Cache ======================

     

    C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully

    C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Users\Default User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

     

    ==== Empty FireFox Cache ======================

     

    No FireFox Cache found

     

    ==== Empty Chrome Cache ======================

     

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

     

    ==== Empty All Flash Cache ======================

     

    Flash Cache Emptied Successfully

     

    ==== Empty All Java Cache ======================

     

    Java Cache cleared successfully

     

    ==== C:\zoek_backup content ======================

     

    C:\zoek_backup (files=1070 folders=347 52396145 bytes)

     

    ==== Empty Temp Folders ======================

     

    C:\Users\Dave\AppData\Local\Temp will be emptied at reboot

    C:\Users\Default\AppData\Local\Temp emptied successfully

    C:\Users\Default User\AppData\Local\Temp emptied successfully

    C:\Users\TEMP\AppData\Local\Temp emptied successfully

    C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully

    C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

    C:\WINDOWS\Temp will be emptied at reboot

     

    ==== After Reboot ======================

     

    ==== Empty Temp Folders ======================

     

    C:\WINDOWS\Temp successfully emptied

    C:\Users\Dave\AppData\Local\Temp successfully emptied

     

    ==== Empty Recycle Bin ======================

     

    C:\$RECYCLE.BIN successfully emptied

     

    ==== EOF on Sun 11/09/2014 at 18:53:48.72 ======================
  10.  

    Zoek.exe v5.0.0.0 Updated 09-November-2014

    Tool run by Dave on Sun 11/09/2014 at 16:58:58.24.

    Microsoft Windows 8.1 6.3.9600  x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Dave\Downloads\zoek\zoek.exe [scan all users]   [Quick Scan] [Auto Clean]

     

    ==== System Restore Info ======================

     

    11/9/2014 5:03:55 PM Zoek.exe System Restore Point Created Succesfully.

     

    ==== Empty Folders Check ======================

     

    C:\PROGRA~2\predm deleted successfully

    C:\PROGRA~2\VNT deleted successfully

    C:\PROGRA~2\COMMON~1\supportdotcom deleted successfully

    C:\PROGRA~2\COMMON~1\SWF Studio deleted successfully

    C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully

    C:\PROGRA~3\cosstminn deleted successfully

    C:\PROGRA~3\Oracle deleted successfully

    C:\Users\Dave\AppData\Roaming\Activeris deleted successfully

    C:\Users\Dave\AppData\Local\CrashDumps deleted successfully

    C:\Users\Dave\AppData\Local\VisualBeeExe deleted successfully

    C:\Users\Dave\AppData\Local\WordOv deleted successfully

     

    ==== Deleting CLSID Registry Keys ======================

     

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6} deleted successfully

     

    ==== Deleting CLSID Registry Values ======================

     

     

    ==== Deleting Services ======================

     

     

    ==== Deleting Files \ Folders ======================

     

    C:\Users\Dave\AppData\LocalLow\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted

    C:\PROGRA~2\cosstminn deleted

    C:\PROGRA~2\Mozilla Firefox\browser\nsprotector.js deleted

    C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml deleted

    C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\sweettunes_search.xml deleted

    C:\PROGRA~2\The Weather Channel deleted

    C:\PROGRA~2\Yahoo! deleted

    C:\PROGRA~2\Optimizer Pro deleted

    C:\PROGRA~2\MyPC Backup deleted

    C:\PROGRA~2\AskPartnerNetwork deleted

    C:\Users\Dave\AppData\Roaming\WB.CFG deleted

    C:\Users\Dave\AppData\Roaming\Yahoo! deleted

    C:\PROGRA~3\AskPartnerNetwork deleted

    C:\PROGRA~3\APN deleted

    C:\PROGRA~3\VisualBee deleted

    C:\PROGRA~3\AVG SafeGuard toolbar deleted

    C:\Users\Dave\AppData\Local\BrowserSafeguard deleted

    C:\Users\Dave\AppData\Local\Systweak deleted

    C:\Users\Dave\AppData\Local\AVG SafeGuard toolbar deleted

    C:\Users\Dave\AppData\Local\emaze deleted

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx deleted

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data-journal deleted

    C:\Users\TEMP\AppData\Local\AVG SafeGuard toolbar deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted

    C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk deleted

    C:\WINDOWS\SysNative\roboot64.exe deleted

    C:\Users\Dave\AppData\LocalLow\AVG SafeGuard toolbar deleted

    C:\Users\TEMP\AppData\LocalLow\AVG SafeGuard toolbar deleted

    C:\WINDOWS\tasks\Groovorio Updater.job deleted

    C:\windows\SysNative\tasks\USTSPCO-USTSPCOOneClickCare deleted

    C:\WINDOWS\tasks\USTSPCO-USTSPCOOneClickCare.job deleted

    C:\components deleted

    C:\WINDOWS\SysNative\config\systemprofile\Searches deleted

    C:\windows\SysNative\GroupPolicy\Machine deleted

    C:\windows\SysNative\GroupPolicy\User deleted

    C:\windows\SysNative\GroupPolicy\GPT.INI deleted

    C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted

    C:\WINDOWS\SysWow64\searchplugins deleted

    C:\WINDOWS\SysWow64\Extensions deleted

    C:\Users\Dave\Documents\Optimizer Pro deleted

    "C:\PROGRA~3\ab34c546d7769ac4\{CE681A67-9477-CBE6-EB9D-FE534875F98D}.20140808113335" deleted

    "C:\PROGRA~3\ab34c546d7769ac4" deleted

    "C:\Users\Dave\AppData\Roaming\Temp" deleted

     

    ==== Files Recently Created / Modified ======================

     

    ====== C:\WINDOWS ====

    ====== C:\Users\Dave\AppData\Local\Temp ====

    ====== Java Cache =====

    ====== C:\WINDOWS\SysWOW64 =====

    2014-11-02 15:53:26 B9F9FD6188CC732F19DB69CAE5CC597C 272808 ----a-w- C:\WINDOWS\SysWOW64\javaws.exe

    2014-11-02 15:52:27 8FA677D5F2AFE2A3F111C50D68A93542 98216 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll

    2014-11-02 15:52:27 3594C0ABBFFE10B3CF95714B8B3C89A4 175528 ----a-w- C:\WINDOWS\SysWOW64\javaw.exe

    2014-11-02 15:52:27 095826BCBBFA5C09C72463A82612B23C 175528 ----a-w- C:\WINDOWS\SysWOW64\java.exe

    ====== C:\WINDOWS\SysWOW64\drivers =====

    ====== C:\WINDOWS\Sysnative =====

    ====== C:\WINDOWS\Sysnative\drivers =====

    2014-10-15 02:34:50 87F3713E620F62D243A82B3CB66CBDDE 2498880 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys

    2014-10-15 02:34:37 329FEB41BBE82FBBD9BD69547BA1CB82 428864 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS

    ====== C:\WINDOWS\Tasks ======

    ====== C:\WINDOWS\Temp ======

    ======= C:\Program Files =====

    ======= C:\PROGRA~2 =====

    2014-11-02 15:51:48 -------- d-----w- C:\PROGRA~2\Java

    ======= C: =====

    ====== C:\Users\Dave\AppData\Roaming ======

    ====== C:\Users\Dave ======

    2014-11-02 18:25:11 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp

    2014-11-02 15:52:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

    2014-10-25 01:28:36 -------- d-----w- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7

     

    ====== C: exe-files ==

    === C: other files ==

     

    ==== Startup Registry Enabled ======================

     

    [HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Run]

    "TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"

    "CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R"

    "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"

    "HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"

    "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    "HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe"

    "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe -osboot"

    "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime"

    "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

     

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

    "TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"

     

    ==== Startup Registry Enabled x64 ======================

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe "

    "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

    "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update"

     

    ==== Startup Folders ======================

     

    2014-05-04 18:29:12 1096 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

    2013-01-07 19:21:07 1239 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk

    2013-03-17 22:43:48 2099 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

    2012-12-28 01:12:20 2015 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk

    2014-04-05 21:43:33 1236 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk

     

    ==== Task Scheduler Jobs ======================

     

    C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/09/2014 01:14 PM]

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe []

    C:\WINDOWS\tasks\HP Photo Creations Communicator.job --a-------- C:\ProgramData\HP Photo Creations\Communicator.exe [03/26/2013 08:02 PM]

    C:\WINDOWS\tasks\HPCeeScheduleForDave.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [07/15/2011 04:43 AM]

    C:\WINDOWS\tasks\PrintProjects Communicator.job --a-------- C:\ProgramData\PrintProjects\Communicator.exe [12/21/2013 03:42 PM]

    C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [08/24/2012 02:38 AM]

     

    ==== Other Scheduled Tasks ======================

     

    "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]

    "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe]

    "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]

    "C:\WINDOWS\SysNative\tasks\HP Photo Creations Communicator" [C:\ProgramData\HP Photo Creations\Communicator.exe]

    "C:\WINDOWS\SysNative\tasks\HPCeeScheduleForDave" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe]

    "C:\WINDOWS\SysNative\tasks\LAUNCH CDPCO" [C:\Program Files (x86)\USTechSupport\PC Optimizer\USTSPCO.exe]

    "C:\WINDOWS\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe]

    "C:\WINDOWS\SysNative\tasks\PrintProjects Communicator" [C:\ProgramData\PrintProjects\Communicator.exe]

    "C:\WINDOWS\SysNative\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe]

    "C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]

    "C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]

    "C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe]

    "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{46B47638-2502-497D-8CC1-2C969B303C86}" [C:\Windows\system32\msfeedssync.exe]

    "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{49D05411-CAF0-410C-AA14-1BED537C90A2}" [C:\Windows\system32\msfeedssync.exe]

    "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{6734F1F0-3039-47CD-A28F-2E62C34206E1}" [C:\Windows\system32\msfeedssync.exe]

    "C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]

    "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]

     

    ==== Firefox Extensions Registry ======================

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]

    "{0FAA5C82-A094-4541-8811-D3361F972A81}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [04/05/2014 02:46 PM]

     

    ==== Firefox Extensions ======================

     

    ProfilePath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default

    - Undetermined - %ProfilePath%\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}

     

    ==== Firefox Plugins ======================

     

    Profilepath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\rt286xcf.default

    3D3CAF586124C4E8102764C8B3063BB6 - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director

    1B05342DC6A8896A90952AF2084620F5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll - RocketLife Secure Plug-In Layer

     

     

    ==== Fake Chromium Profiles Check ======================

     

    Fake profile C:\Users\Administrator\AppData\Local\Torch deleted

    Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted

    Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deleted

    Fake profile C:\Users\Dave\AppData\Local\Torch deleted

    Fake profile C:\Users\Dave\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\Dave\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\Dave\AppData\Local\Chromatic Browser deleted

    Fake profile C:\Users\Guest\AppData\Local\Torch deleted

    Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted

    Fake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\Guest\AppData\Local\Chromatic Browser deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted

    Fake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted

     

    ==== Chromium Look ======================

     

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

    blklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]

    blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]

    idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[03/15/2014 02:22 AM]

    mmlkabjddkpgkgfhdhpimhcbonapngoh - C:\Users\Dave\AppData\Local\CRE\mmlkabjddkpgkgfhdhpimhcbonapngoh.crx[]

    pelmeidfhdlhlbjimpabfcbnnojbboma - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx[]

    pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]

     

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions

    blklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]

    blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]

    pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]

     

    Google Drive - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    cosstminn - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfg

    Google Search - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Google Wallet - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    Google Docs - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Chrome In-App Payments service - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    InternetHelper3 - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp

     

    ==== Chromium Startpages ======================

     

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Preferences



     

     

    ==== Chromium Fix ======================

     

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage-journal deleted successfully

    C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pnjnnnhampgflieglcelomcofocioegp deleted successfully

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfg deleted successfully

     

    ==== Set IE to Default ======================

     

    Old Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]



    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]





    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]





     

    New Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]


    "Start Page"="http://www.google.com"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]





    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]





     

    ==== All HKCU SearchScopes ======================

     

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

    {012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"

     

    ==== Deleting CLSID Registry Keys ======================

     

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

    HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully

     

    ==== Deleting CLSID Registry Values ======================

     

     

    ==== Reset IE Proxy ======================

     

    Value(s) before fix:

    "ProxyServer"="http=127.0.0.1:13918;https=127.0.0.1:13918"

    "ProxyOverride"="<-loopback>"

    "ProxyEnable"=dword:00000001

     

    Value(s) after fix:

    "ProxyEnable"=dword:00000000

     

    ==== Deleting Registry Keys ======================

     

    HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mmlkabjddkpgkgfhdhpimhcbonapngoh deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfully

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfully

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully

     

    ==== Empty IE Cache ======================

     

    C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully

    C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\Users\Default User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

    C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

     

    ==== Empty FireFox Cache ======================

     

    No FireFox Cache found

     

    ==== Empty Chrome Cache ======================

     

    C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

     

    ==== Empty All Flash Cache ======================

     

    Flash Cache Emptied Successfully

     

    ==== Empty All Java Cache ======================

     

    Java Cache cleared successfully

     

    ==== C:\zoek_backup content ======================

     

    C:\zoek_backup (files=1070 folders=347 52396145 bytes)

     

    ==== Empty Temp Folders ======================

     

    C:\Users\Dave\AppData\Local\Temp will be emptied at reboot

    C:\Users\Default\AppData\Local\Temp emptied successfully

    C:\Users\Default User\AppData\Local\Temp emptied successfully

    C:\Users\TEMP\AppData\Local\Temp emptied successfully

    C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully

    C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

    C:\WINDOWS\Temp will be emptied at reboot

     

    ==== After Reboot ======================

     

    ==== Empty Temp Folders ======================

     

    C:\WINDOWS\Temp successfully emptied

    C:\Users\Dave\AppData\Local\Temp successfully emptied

     

    ==== Empty Recycle Bin ======================

     

    C:\$RECYCLE.BIN successfully emptied

     

    ==== EOF on Sun 11/09/2014 at 18:53:48.72 ======================
  11. All processes killed

    ========== OTL ==========

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.

    HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

    Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

    Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.

    Registry value HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.

    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.

    Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect deleted successfully.

    Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect not found.


    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\cdo\ deleted successfully.

    File Protocol\Handler\cdo - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.

    File Protocol\Handler\msdaipp - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.

    File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.

    File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap\ deleted successfully.

    File Protocol\Handler\mso-offdap - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.

    File Protocol\Handler\skype4com - No CLSID value found not found.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.

    File Protocol\Handler\wlpg - No CLSID value found not found.

    64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

    Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages:livessp deleted successfully.

    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\ not found.

    ========== COMMANDS ==========

     

    [EMPTYJAVA]

     

    User: All Users

     

    User: Dave

     

    User: Default

     

    User: Default User

     

    User: Public

     

    User: TEMP

     

    Total Java Files Cleaned = 0.00 mb

     

     

    [EMPTYFLASH]

     

    User: All Users

     

    User: Dave

    ->Flash cache emptied: 8876 bytes

     

    User: Default

     

    User: Default User

     

    User: Public

     

    User: TEMP

     

    Total Flash Files Cleaned = 0.00 mb

     

     

    [EMPTYTEMP]

     

    User: All Users

     

    User: Dave

    ->Temp folder emptied: 5006567 bytes

    ->Temporary Internet Files folder emptied: 5584144 bytes

    ->FireFox cache emptied: 0 bytes

    ->Google Chrome cache emptied: 287090024 bytes

    ->Flash cache emptied: 0 bytes

     

    User: Default

    ->Temp folder emptied: 0 bytes

    ->Temporary Internet Files folder emptied: 0 bytes

     

    User: Default User

    ->Temp folder emptied: 0 bytes

    ->Temporary Internet Files folder emptied: 0 bytes

     

    User: Public

     

    User: TEMP

    ->Temp folder emptied: 40362572 bytes

    ->Temporary Internet Files folder emptied: 128 bytes

    ->FireFox cache emptied: 28999173 bytes

    ->Google Chrome cache emptied: 10785735 bytes

     

    %systemdrive% .tmp files removed: 0 bytes

    %systemroot% .tmp files removed: 0 bytes

    %systemroot%\System32 .tmp files removed: 0 bytes

    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes

    %systemroot%\System32\drivers .tmp files removed: 0 bytes

    Windows Temp folder emptied: 331746736 bytes

    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes

    RecycleBin emptied: 0 bytes

     

    Total Files Cleaned = 677.00 mb

     

    C:\Windows\System32\drivers\etc\Hosts moved successfully.

    HOSTS file reset successfully

    Restore point Set: OTL Restore Point

     

    OTL by OldTimer - Version 3.2.69.0 log created on 11022013_094523

     

    Files\Folders moved on Reboot...

    File move failed. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca2c not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca2e not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca2f not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca30 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca31 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca32 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca33 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca34 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca37 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca45 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca46 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca47 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca48 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca49 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca4a not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca4b not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca4c not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc39 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3a not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3b not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3c not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3d not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3e not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3f not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc40 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc41 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc42 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc43 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc44 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc45 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc46 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc47 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc48 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc49 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4a not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4b not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4c not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4d not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4e not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4f not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc50 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc51 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc52 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc53 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc54 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc55 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc56 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc57 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc58 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc59 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc5a not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc5b not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc5c not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf26 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf27 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf28 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf29 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2a not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2b not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2c not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2d not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2e not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2f not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf30 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf31 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf32 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf33 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf34 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf35 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf36 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf37 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf38 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf39 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3a not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3b not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3c not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3d not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3e not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3f not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf40 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf41 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf42 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf43 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf44 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf45 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf46 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf47 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf48 not found!

    File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf49 not found!

     

    PendingFileRenameOperations files...

     

    Registry entries deleted on Reboot...
  12. OTL Extras logfile created on: 10/27/2013 10:14:54 PM - Run 1

    OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dave\Downloads

    64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation

    Internet Explorer (Version = 9.10.9200.16721)

    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

     

    3.60 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 63.95% Memory free

    4.22 Gb Paging File | 2.75 Gb Available in Paging File | 65.12% Paging File free

    Paging file location(s): ?:\pagefile.sys [binary data]

     

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

    Drive C: | 276.00 Gb Total Space | 216.80 Gb Free Space | 78.55% Space Free | Partition Type: NTFS

    Drive D: | 21.33 Gb Total Space | 2.62 Gb Free Space | 12.28% Space Free | Partition Type: NTFS

     

    Computer Name: LAPTOP | User Name: Dave | Logged in as Administrator.

    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 180 Days

     

    ========== Extra Registry (SafeList) ==========

     

     

    ========== File Associations ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

     

    ========== Shell Spawning ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

    batfile [open] -- "%1" %*

    cmdfile [open] -- "%1" %*

    comfile [open] -- "%1" %*

    exefile [open] -- "%1" %*

    helpfile [open] -- Reg Error: Key error.

    htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

    piffile [open] -- "%1" %*

    regfile [merge] -- Reg Error: Key error.

    scrfile [config] -- "%1"

    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

    scrfile [open] -- "%1" /S

    txtfile [edit] -- Reg Error: Key error.

    Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"

    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [explore] -- Reg Error: Value error.

    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

    batfile [open] -- "%1" %*

    cmdfile [open] -- "%1" %*

    comfile [open] -- "%1" %*

    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

    exefile [open] -- "%1" %*

    helpfile [open] -- Reg Error: Key error.

    htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

    piffile [open] -- "%1" %*

    regfile [merge] -- Reg Error: Key error.

    scrfile [config] -- "%1"

    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

    scrfile [open] -- "%1" /S

    txtfile [edit] -- Reg Error: Key error.

    Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"

    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Folder [explore] -- Reg Error: Value error.

    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)

    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

     

    ========== Security Center Settings ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    "cval" = 1

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    "VistaSp1" = CE 37 E6 AF FF 6A CD 01  [binary data]

    "AntiVirusOverride" = 0

    "AntiSpywareOverride" = 0

    "FirewallOverride" = 0

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

     

    ========== Firewall Settings ==========

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    "EnableFirewall" = 1

    "DisableNotifications" = 0

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

    "EnableFirewall" = 1

    "DisableNotifications" = 0

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

    "EnableFirewall" = 1

    "DisableNotifications" = 0

     

    ========== Authorized Applications List ==========

     

     

    ========== Vista Active Open Ports Exception List ==========

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

    "{43B3AACF-45EB-4B05-AA02-B3077FFCDE9C}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery | 

    "{51D9E665-683E-4856-ADC8-D9292260C609}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 

    "{6B288D59-35D7-4560-8063-5E2D274490CA}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 

    "{910AE036-C75B-4250-9F09-A9448E203513}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe | 

    "{B803DC99-019C-400E-8B42-BCF98DD0CBC3}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery | 

     

    ========== Vista Active Application Exception List ==========

     

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

    "{03DBB28F-E233-4534-972D-69CF6C13A413}" = dir=in | name=hp+ | 

    "{07531A7F-0AE1-49FF-B287-397F55CA06B4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | 

    "{07AAE2C5-14EE-4CDF-84DB-02FC86A4A54C}" = dir=out | name=netflix | 

    "{0DD3F581-C76D-4528-A0EF-67F710C2E826}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | 

    "{0FD14463-2202-4FA6-9129-9BFD7779AB93}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe | 


    "{151668CE-44AB-44CF-9EE6-15195BB90226}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 

    "{191487FE-D290-4C6D-BE29-896BB8402A76}" = dir=out | name=windows_ie_ac_001 | 

    "{19711016-E1A8-48F7-BB52-ABFB014C8FCC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe | 

    "{198DB91B-EDB0-42ED-B38C-1B759757FC72}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | 

    "{1C0E78D2-1D6D-45D2-AD96-F50715921004}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe | 

    "{1F270FBB-6CBB-4DBA-8B78-EE7BDD64FFFB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | 

    "{20582113-2722-47BD-82E9-DD4AF1B24525}" = dir=out | name=easy diy | 


    "{26016C1A-DC13-4A7A-B87D-7B35A6BD15EF}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe | 

    "{267FB111-1BE4-4BC4-A8E4-7DE19B86329C}" = dir=out | name=ebay | 

    "{26E34F31-158D-4098-BF23-BE810C493A86}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 

    "{28BD95FB-FCD5-4BB2-8A21-272E74BBB609}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe | 

    "{2CC191C4-E30C-4F8F-A177-79DEDF5C85D1}" = dir=out | name=iheartradio | 

    "{2E225E47-F63B-4BCB-9A3D-00D39F537A42}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | 

    "{36ECDF71-DC35-466B-8B5C-0B17108DD969}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | 

    "{37DB58ED-91B7-4532-884D-9D9528B6C226}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | 

    "{381C99C7-DC03-4A2A-BECC-B26826D14E88}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | 

    "{3850A51C-1A27-489F-9EA1-D872216A076D}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 

    "{3A57F579-7DE1-4B05-99FA-AD54182A832C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | 

    "{43184DE2-7AED-4BCB-9A40-C9A580C2B612}" = dir=out | name=hp printer control | 



    "{44B8C1FC-99FB-4C51-B30C-FBA4017793DC}" = dir=in | name=hp printer control | 

    "{476B597A-E6B7-437F-9091-2D4C1DA0C5B3}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe | 


    "{4F9777AB-DB6C-4CF3-B207-BA1DB676B171}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe | 

    "{546608D9-4876-4F81-8BE8-58CC4BF78D42}" = dir=in | name=ebay | 


    "{59C27785-55AE-40E7-983C-919377142F37}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | 

    "{6B371E8F-FFC4-4EAD-BBA6-6B48456CE480}" = dir=out | name=hp registration | 

    "{6B5C7923-3D9E-4111-AF91-8D364EA55128}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | 


    "{781B4773-97FE-4F90-883D-1C9DA4C1948D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 

    "{78C9C4E2-3A66-4322-8804-06EC7FF38E8E}" = dir=out | name=norton studio | 


    "{82EC8B0A-751F-454C-A5BD-E8A39F8F7831}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe | 

    "{837481C4-6BE3-4724-93DE-04344545E1BD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe | 

    "{87D56309-C907-4C96-945B-71A72AA371B9}" = dir=out | name=hp connected photo powered by snapfish | 

    "{8A0F0DBE-48D9-4A52-B212-2AF7B1462902}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe | 

    "{8DE79230-48B9-4691-A167-9C8AC4F65C19}" = dir=in | name=hp connected photo powered by snapfish | 

    "{90142915-B93E-41C2-9F1A-9D272D70F90D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 

    "{91D585D5-C91F-42C4-9111-126554242621}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | 

    "{91E1FA52-1AC5-43D9-9ED7-12318E3648CF}" = dir=out | name=getting started with windows 8 | 

    "{934CFA53-948E-4868-8CD5-F12B9FC6BDB2}" = dir=out | name=finance helper | 




    "{9D26F191-F22A-4E94-B64C-5BFD0E9E282F}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe | 

    "{9F802A4A-A96B-4965-9C19-1B48DA693464}" = dir=out | name=work it out | 

    "{A10B8D24-5239-44DA-B105-FBDD917A39C1}" = dir=out | name=microsoft solitaire collection | 


    "{AB35DE72-4497-4541-A06D-A39BA2EF5DB7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | 

    "{B03CADAD-F714-4A36-B91F-DB49D0F75948}" = dir=out | name=pinball fx2 | 

    "{B94560A9-131A-4CA8-8BC0-F49745D77A16}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe | 





    "{CF960A71-2A1C-4184-BC65-7C3B00F1955A}" = dir=in | name=pinball fx2 | 

    "{D074B610-22D4-42B3-9A6C-471DC129952D}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 


    "{D77152BF-8A9E-4CD9-9179-B0DC5CD975FD}" = dir=in | app=c:\users\dave\appdata\local\temp\7zs00d5\setup\hpznui40.exe | 

    "{DC56DC94-2D87-496C-AEF8-17F9652D991C}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 

    "{DE25D9F1-4D02-4BFC-8057-DB37FA61FF65}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | 

    "{E22C0720-45A7-42C8-865D-54F55AADEA4E}" = dir=out | name=microsoft mahjong | 

    "{E6FFBC3C-DB39-499E-831E-E2E100C3763F}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe | 


    "{ED1DDEB0-C97C-4EB1-85CC-1144FA582B72}" = dir=out | name=hp+ | 


    "{EDA11C8E-7185-4EE7-A505-1B884A0E750A}" = dir=out | name=kindle | 

    "{F567D314-85D4-42BF-9EEB-A84F29E00BEE}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 

    "{FBDA0F67-9F61-4A3F-B726-236DA16A646B}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe | 

     

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

     

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

    "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector

    "{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt

    "{0FA995CC-C849-4755-B14B-5404CC75DC24}" = Energy Star

    "{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables

    "{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}" = Apple Mobile Device Support

    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

    "{4FF9E8AA-D554-4CE7-89F9-B69DAA5A1E98}" = AVG 2013

    "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime

    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

    "{63ADEC24-A374-80A8-E89B-BE401C787F75}" = AMD Catalyst Install Manager

    "{6B02D047-A56D-4994-B1F1-53DA6B9885AB}" = AVG 2013

    "{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64

    "{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter

    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour

    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting

    "{A535111D-95C8-487F-869E-CE4C239972D2}" = iTunes

    "{A79A9231-0A5A-9384-21D0-DB753C2BE59B}" = AMD Fuel

    "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319

    "{E3047FA0-2D6B-4BD6-8CD4-599955F1CE9D}" = Microsoft Mouse and Keyboard Center

    "{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}" = HP Registration Service

    "{E82EC5DF-28FD-C8F4-ED08-B88728158260}" = ccc-utility64

    "{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}" = iCloud

    "{F089B734-1356-484F-A7B8-1B78F1616A15}" = HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6

    "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer

    "AVG" = AVG 2013

    "HP Imaging Device Functions" = HP Imaging Device Functions 14.0

    "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0

    "HPExtendedCapabilities" = HP Customer Participation Program 14.0

    "HPOCR" = OCR Software by I.R.I.S. 14.0

    "Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center

    "Shop for HP Supplies" = Shop for HP Supplies

    "SynTPDeinstKey" = Synaptics Pointing Device Driver

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

    "{0123AB93-E7A4-7F40-83B6-41EC2CF84B3F}" = CCC Help Dutch

    "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

    "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan

    "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements

    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

    "{0C3B99D2-35D0-6993-3C4B-A759419A8678}" = CCC Help Korean

    "{0C57987A-A03A-4B95-A309-D23F78F406CA}" = HP Utility Center

    "{0DCCD5F4-29E7-4AA0-8C1D-F8E1503B91F4}" = Catalyst Control Center - Branding

    "{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP

    "{1225C0F8-AB1A-BE3A-CD0C-DB8CA1613940}" = CCC Help Greek

    "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery

    "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant

    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker

    "{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport

    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

    "{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10

    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1

    "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox

    "{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8

    "{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App

    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery

    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery

    "{3C41A693-28E1-4335-A738-528B09DB600C}" = CCC Help Thai

    "{3C458872-A5BB-89F3-933C-2406F6D9E6F8}" = CCC Help Finnish

    "{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support

    "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skypeâ„¢ 6.1

    "{4ED7050C-9332-4FB2-AB07-E94F25A53D39}" = HP Quick Launch

    "{528AB81B-D65A-4AB0-A2B6-82B51A087D01}" = HP Recovery Manager

    "{52A3FC19-6F84-F293-08C6-80A1D2F7477F}" = CCC Help Swedish

    "{56BA241F-580C-43D2-8403-947241AAE633}" = center

    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack

    "{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status

    "{5CD2FE1D-A3DB-F273-2798-EFAACF8492A5}" = CCC Help Portuguese

    "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM

    "{631EFC00-5A7A-4A90-9578-039EDA92DE0F}_is1" = AtHomeConnect version 1.0.1.0

    "{675D093B-815D-47FD-AB2C-192EC751E8E2}" = HP Software Framework

    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

    "{6A66D912-541C-54C6-43E6-17AF24700B91}" = CCC Help German

    "{6C8FF546-B0C0-0935-2F5E-7DC2DA727CFD}" = CCC Help Czech

    "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.0.0

    "{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App

    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

    "{734846E6-3E7A-04AC-0612-638A1D8A63F8}" = CCC Help Russian

    "{747F3993-036E-5F4F-1B82-7DA844B73966}" = Catalyst Control Center Localization All

    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime

    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

    "{793ED091-3F14-4968-3864-5C8A7727A5DA}" = CCC Help Chinese Standard

    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform

    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver

    "{89D20029-0578-4D8D-979A-695C8D868868}" = H&R Block Deluxe + Efile 2012

    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

    "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg

    "{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390R 802.11bgn Wi-Fi Adapter

    "{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content

    "{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional

    "{9285EABA-D88C-4A8A-6E9D-5F55BF03E46F}" = Catalyst Control Center InstallProxy

    "{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax

    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker

    "{93EB60BA-458D-FBE6-E466-CD170080E719}" = CCC Help Polish

    "{941DE69D-6CEE-4171-8F1F-3D7E352AA498}" = HP Wireless Button Driver

    "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office

    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

    "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc

    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

    "{9C0F4CBD-8543-96CC-46F1-75E57B1B22A6}" = Catalyst Control Center Graphics Previews Common

    "{9C35EDE5-4B0F-45E7-A438-314BA889948E}" = HP MyRoom

    "{9E50DEC9-081B-441F-B647-98DBEA8B01DD}" = CorelDRAW 10

    "{9EF69B68-6DFE-F916-2D6E-E486D21A26C2}" = CCC Help Spanish

    "{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1

    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer

    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer

    "{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime

    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer

    "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply

    "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.05)

    "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update

    "{B1E7FE70-3B18-5BA2-8032-2547FC636A50}" = CCC Help Japanese

    "{B424890D-64FC-E0D1-4A17-4B512CA45CD9}" = CCC Help Italian

    "{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime

    "{B8019B54-F9BE-490A-9619-6D06F18F129F}" = HP Support Assistant

    "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2

    "{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter

    "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations

    "{BE64A239-E22E-9D77-AA57-36AE0443EC2F}" = CCC Help Chinese Traditional

    "{C045ED98-5FDB-45A0-AB48-C4B7560E7816}" = C309a

    "{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader

    "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint

    "{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader

    "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget

    "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp

    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

    "{CF8C33C1-C978-527D-E0AF-530882DEB146}" = AMD VISION Engine Control Center

    "{D23CA718-0356-41F2-8E6A-B5C6CD383EF7}" = HP Documentation

    "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch

    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common

    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

    "{D5DC9541-12F0-59CF-9430-1136D5A58BD0}" = CCC Help Hungarian

    "{D7FBE7DC-A18F-4DFF-80BB-A478E4E09CF7}" = CCC Help Danish

    "{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq

    "{DC3C5C4A-1869-A99C-3AE4-55E0191105F0}" = CCC Help Norwegian

    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources

    "{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw

    "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD

    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

    "{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center

    "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio

    "{EB2CDF95-92D4-AC57-63B1-4E7F0BD8F9B8}" = CCC Help French

    "{ECA42F46-D80E-AD40-18FB-4BF64491CEE3}" = CCC Help English

    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219

    "{FA0E7183-6B11-4899-B25F-2C490543967E}" = PS_AIO_05_C309_Software_Min

    "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm

    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials

    "{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr

    "{FF282A38-D10B-E302-FBAD-5903C9DD9A5B}" = CCC Help Turkish

    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

    "Adobe Shockwave Player" = Adobe Shockwave Player 11.6

    "AVG SafeGuard toolbar" = AVG SafeGuard toolbar

    "CorelDRAW 10" = CorelDRAW 10

    "Google Chrome" = Google Chrome

    "HP Photo Creations" = HP Photo Creations

    "IECT3311875" = SweetTunes Toolbar for IE

    "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

    "InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10

    "InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8

    "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint

    "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD

    "InternetHelper3 Chrome Toolbar" = InternetHelper3 Chrome Toolbar

    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300

    "McAfee Security Scan" = McAfee Security Scan Plus

    "PrintProjects" = PrintProjects

    "Rapport_msi" = Trusteer Endpoint Protection

    "RealPlayer 16.0" = RealPlayer

    "The Weather Channel App" = The Weather Channel App

    "WildTangent hp Master Uninstall" = HP Games

    "WildTangent wildgames Master Uninstall" = WildTangent Games

    "WinLiveSuite" = Windows Live Essentials

    "WTA-34a0f46f-2586-4346-812c-3e18d190d88a" = Luxor Evolved

    "WTA-3e034c4a-10db-4d90-986c-4ad842d30c78" = Polar Bowler

    "WTA-43d91043-ebc0-4697-8d3d-d2bc3c24954c" = Farm Frenzy

    "WTA-4685aa80-dc5b-4935-83fa-befd7b91e9f5" = Chuzzle Deluxe

    "WTA-4a27aa2d-9c25-4db9-98ad-36510c794c7f" = Cradle Of Egypt Collector's Edition

    "WTA-4a30ae7a-f08b-4f44-a12c-09edc11ad2a6" = Governor of Poker 2 Premium Edition

    "WTA-52d040ec-7135-4eec-9cd4-cdf2230564a1" = Mahjongg Dimensions Deluxe: Tiles in Time

    "WTA-5506661c-81d3-49e4-b2f9-072576c15d91" = Roads of Rome 3

    "WTA-5c01f4e4-2494-4342-bf09-6b5fba8368f5" = John Deere Drive Green

    "WTA-5e80cd2a-d654-401d-b385-74b579628353" = Jewel Match 3

    "WTA-715442b8-3be5-4073-9b0e-f41506dd2310" = Hoyle Card Games

    "WTA-7c7027da-bc2b-4364-af24-485d85da4b7b" = Final Drive Fury

    "WTA-83705bd4-8013-45e7-b430-3806a7dc4745" = Mortimer Beckett and the Crimson Thief Premium Edition

    "WTA-8ba64964-a6d3-492c-9d8f-02006b962c0c" = Vacation Questâ„¢ - Australia

    "WTA-9431f875-5fc4-41b0-8bbb-5a2107f43f7b" = Penguins!

    "WTA-973dfb2b-f35d-4000-af3a-be238aa6ef88" = Bejeweled 3

    "WTA-a86c3f90-cf5b-4c9f-8c9a-690d3045ff3d" = Peggle Nights

    "WTA-b08e9137-7fa1-480b-8f21-a404a4877e38" = Mystery P.I. - Curious Case of Counterfeit Cove

    "WTA-bd80f60a-4ecd-4a36-a634-a563d4b1e9de" = Polar Golfer

    "WTA-d76db04b-4e71-4bac-880c-969c2616d43d" = Tales of Lagoona

    "WTA-d8e241f0-1a03-4a4a-94d2-f0379e66bc9a" = FATE: The Cursed King

    "WTA-d9f2e693-20fd-4edf-99dd-54fc5c9567f9" = Build-a-lot 4 - Power Source

    "WTA-df35cdb0-0d63-4dfb-afa8-94429c4cf1f3" = Zuma's Revenge

    "WTA-e173b0c7-0897-4cc2-910e-53ef978247b4" = Cradle of Rome 2

    "WTA-fa24b63a-3a29-4c8b-9aeb-e1577cb8a12f" = 4 Elements II

    "WTA-fb2ce78a-3b49-4539-8948-b141dca7fa98" = FlatOut 2

     

    ========== HKEY_USERS Uninstall List ==========

     

    [HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

    "@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe" = SanDiskSecureAccess_Manager.exe

     

    ========== Last 20 Event Log Errors ==========

     

    [ Application Events ]

    Error - 7/30/2013 11:11:16 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/30/2013 11:11:16 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/30/2013 11:12:09 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/30/2013 11:12:09 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/30/2013 3:56:56 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/30/2013 3:56:56 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/30/2013 10:30:31 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/30/2013 10:30:31 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)

     active for over two minutes. This places considerable burden on the network.

     

    Error - 7/31/2013 1:01:18 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Task Scheduling Error: Continuously busy for more than a second

     

    Error - 7/31/2013 1:01:18 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Task Scheduling Error: m->NextScheduledEvent 15506

     

    Error - 7/31/2013 1:01:18 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100

    Description = Task Scheduling Error: m->NextScheduledSPRetry 15506

     

    [ System Events ]

    Error - 10/5/2013 2:19:25 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034

    Description = The Rapport Management Service service terminated unexpectedly.  It

     has done this 1 time(s).

     

    Error - 10/7/2013 9:54:59 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024

    Description = The AVGIDSAgent service terminated with the following service-specific

     error:   %%3758213659

     

    Error - 10/7/2013 9:55:27 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034

    Description = The AVG WatchDog service terminated unexpectedly.  It has done this

     1 time(s).

     

    Error - 10/8/2013 11:15:49 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024

    Description = The AVGIDSAgent service terminated with the following service-specific

     error:   %%3758213659

     

    Error - 10/8/2013 11:16:20 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034

    Description = The AVG WatchDog service terminated unexpectedly.  It has done this

     1 time(s).

     

    Error - 10/10/2013 5:19:29 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024

    Description = The AVGIDSAgent service terminated with the following service-specific

     error:   %%3758213659

     

    Error - 10/10/2013 5:20:01 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034

    Description = The AVG WatchDog service terminated unexpectedly.  It has done this

     1 time(s).

     

    Error - 10/10/2013 5:22:17 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034

    Description = The Rapport Management Service service terminated unexpectedly.  It

     has done this 1 time(s).

     

    Error - 10/15/2013 3:43:39 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024

    Description = The AVGIDSAgent service terminated with the following service-specific

     error:   %%3758213659

     

    Error - 10/15/2013 3:44:11 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034

    Description = The AVG WatchDog service terminated unexpectedly.  It has done this

     1 time(s).

     

     

    < End of report >
  13. OTL logfile created on: 10/27/2013 10:14:54 PM - Run 1

    OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dave\Downloads

    64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation

    Internet Explorer (Version = 9.10.9200.16721)

    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

     

    3.60 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 63.95% Memory free

    4.22 Gb Paging File | 2.75 Gb Available in Paging File | 65.12% Paging File free

    Paging file location(s): ?:\pagefile.sys [binary data]

     

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

    Drive C: | 276.00 Gb Total Space | 216.80 Gb Free Space | 78.55% Space Free | Partition Type: NTFS

    Drive D: | 21.33 Gb Total Space | 2.62 Gb Free Space | 12.28% Space Free | Partition Type: NTFS

     

    Computer Name: LAPTOP | User Name: Dave | Logged in as Administrator.

    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 180 Days

     

    ========== Processes (SafeList) ==========

     

    PRC - [2013/10/27 22:12:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Downloads\OTL (1).com

    PRC - [2013/10/08 18:02:45 | 000,844,752 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    PRC - [2013/10/07 19:13:49 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

    PRC - [2013/09/10 23:18:16 | 002,476,312 | ---- | M] (Trusteer Ltd.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe

    PRC - [2013/09/10 23:18:16 | 001,435,928 | ---- | M] (Trusteer Ltd.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe

    PRC - [2013/08/14 15:19:24 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

    PRC - [2013/05/11 04:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    PRC - [2012/10/12 15:16:50 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe

    PRC - [2012/07/09 14:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    PRC - [2012/06/07 21:34:06 | 000,111,120 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe

    PRC - [2012/03/28 19:34:30 | 000,091,432 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe

    PRC - [2012/02/15 00:39:36 | 030,705,792 | ---- | M] (Gemalto N.V.) -- C:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe

    PRC - [2009/08/05 13:49:44 | 000,284,016 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe

     

     

    ========== Modules (No Company Name) ==========

     

    MOD - [2013/10/08 18:02:43 | 000,415,184 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppgooglenaclpluginchrome.dll

    MOD - [2013/10/08 18:02:41 | 004,055,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll

    MOD - [2013/10/08 18:01:50 | 000,698,832 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll

    MOD - [2013/10/08 18:01:49 | 000,099,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll

    MOD - [2013/10/08 18:01:47 | 001,604,560 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll

    MOD - [2013/08/21 11:14:59 | 000,991,984 | ---- | M] () -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportMS.dll

    MOD - [2012/06/27 15:09:06 | 000,557,056 | ---- | M] () -- C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll

    MOD - [2012/06/08 12:34:06 | 000,016,400 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll

    MOD - [2012/06/07 21:34:06 | 000,627,216 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll

    MOD - [2012/02/14 17:37:52 | 011,796,096 | ---- | M] () -- C:\Users\Dave\AppData\Roaming\SanDisk\My Vaults\dmBackup.dll

     

     

    ========== Services (SafeList) ==========

     

    SRV:64bit: - [2013/08/15 23:39:26 | 002,371,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)

    SRV:64bit: - [2013/07/01 18:44:21 | 000,016,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)

    SRV:64bit: - [2013/06/24 16:54:45 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)

    SRV:64bit: - [2013/06/01 03:19:58 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)

    SRV:64bit: - [2013/05/29 20:47:42 | 000,322,048 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)

    SRV:64bit: - [2013/05/04 00:58:02 | 000,470,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)

    SRV:64bit: - [2013/05/04 00:57:05 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)

    SRV:64bit: - [2013/04/08 22:48:42 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)

    SRV:64bit: - [2013/03/01 20:45:07 | 000,171,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)

    SRV:64bit: - [2013/03/01 20:45:05 | 000,180,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)

    SRV:64bit: - [2013/01/09 17:23:16 | 001,964,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)

    SRV:64bit: - [2013/01/09 17:22:35 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)

    SRV:64bit: - [2012/11/05 22:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)

    SRV:64bit: - [2012/09/20 00:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)

    SRV:64bit: - [2012/08/06 13:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)

    SRV:64bit: - [2012/08/02 03:06:02 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

    SRV:64bit: - [2012/07/25 21:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)

    SRV:64bit: - [2012/07/25 21:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)

    SRV:64bit: - [2012/07/25 21:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)

    SRV:64bit: - [2012/07/25 21:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)

    SRV:64bit: - [2012/07/25 21:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)

    SRV:64bit: - [2012/07/25 21:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)

    SRV:64bit: - [2012/07/25 21:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)

    SRV:64bit: - [2012/07/25 21:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)

    SRV:64bit: - [2012/07/25 21:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)

    SRV:64bit: - [2012/07/25 21:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)

    SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)

    SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)

    SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)

    SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)

    SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)

    SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)

    SRV - [2013/10/08 19:13:28 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

    SRV - [2013/09/10 23:18:16 | 001,435,928 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)

    SRV - [2013/08/14 15:19:24 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)

    SRV - [2013/07/23 19:09:28 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd)

    SRV - [2013/07/04 15:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)

    SRV - [2013/05/11 04:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)

    SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

    SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)

    SRV - [2013/02/05 09:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)

    SRV - [2013/01/08 13:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)

    SRV - [2012/11/05 22:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)

    SRV - [2012/08/10 18:53:44 | 000,085,504 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)

    SRV - [2012/07/25 21:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)

    SRV - [2012/07/25 21:18:41 | 000,408,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)

    SRV - [2012/07/25 21:17:52 | 000,060,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)

    SRV - [2012/07/13 19:02:16 | 002,451,456 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)

    SRV - [2012/07/09 14:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)

    SRV - [2011/08/18 01:29:52 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)

    SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)

    SRV - [2009/08/05 13:49:44 | 000,284,016 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe -- (Kodak AiO Network Discovery Service)

     

     

    ========== Driver Services (SafeList) ==========

     

    DRV:64bit: - [2013/09/10 23:18:30 | 000,266,928 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RapportHades64.sys -- (RapportHades64)

    DRV:64bit: - [2013/09/10 23:18:28 | 000,295,696 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RapportKE64.sys -- (RapportKE64)

    DRV:64bit: - [2013/08/15 23:41:13 | 000,058,200 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)

    DRV:64bit: - [2013/07/20 01:51:00 | 000,311,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgloga.sys -- (Avgloga)

    DRV:64bit: - [2013/07/20 01:50:56 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\Drivers\avgidsdrivera.sys -- (AVGIDSDriver)

    DRV:64bit: - [2013/07/20 01:50:56 | 000,071,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgidsha.sys -- (AVGIDSHA)

    DRV:64bit: - [2013/07/20 01:50:50 | 000,206,648 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\SysNative\Drivers\avgldx64.sys -- (Avgldx64)

    DRV:64bit: - [2013/07/10 01:32:38 | 000,045,880 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgrkx64.sys -- (Avgrkx64)

    DRV:64bit: - [2013/07/09 02:04:07 | 000,120,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)

    DRV:64bit: - [2013/07/09 01:28:50 | 000,248,632 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgwfpa.sys -- (Avgwfpa)

    DRV:64bit: - [2013/07/01 19:41:47 | 000,447,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)

    DRV:64bit: - [2013/07/01 19:41:47 | 000,337,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)

    DRV:64bit: - [2013/07/01 19:41:47 | 000,213,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)

    DRV:64bit: - [2013/07/01 18:44:14 | 000,036,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)

    DRV:64bit: - [2013/07/01 16:08:49 | 000,247,216 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)

    DRV:64bit: - [2013/07/01 01:45:28 | 000,116,536 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgmfx64.sys -- (Avgmfx64)

    DRV:64bit: - [2013/06/29 00:15:54 | 000,195,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)

    DRV:64bit: - [2013/06/10 15:17:46 | 000,096,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)

    DRV:64bit: - [2013/05/31 21:08:57 | 000,037,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)

    DRV:64bit: - [2013/05/29 20:47:43 | 000,542,208 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\stwrt64.sys -- (STHDA)

    DRV:64bit: - [2013/05/13 15:36:06 | 000,050,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\point64.sys -- (Point64)

    DRV:64bit: - [2013/05/06 08:32:28 | 000,076,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\dc3d.sys -- (dc3d)

    DRV:64bit: - [2013/05/04 01:34:15 | 000,284,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)

    DRV:64bit: - [2013/04/15 07:02:04 | 002,482,960 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\netr28x.sys -- (netr28x)

    DRV:64bit: - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mbam.sys -- (MBAMProtector)

    DRV:64bit: - [2013/03/02 04:57:46 | 000,077,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)

    DRV:64bit: - [2013/03/02 04:45:20 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)

    DRV:64bit: - [2013/03/02 04:39:38 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)

    DRV:64bit: - [2013/01/29 18:15:04 | 000,029,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\nuidfltr.sys -- (NuidFltr)

    DRV:64bit: - [2013/01/09 19:53:32 | 000,028,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)

    DRV:64bit: - [2012/11/26 21:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)

    DRV:64bit: - [2012/11/19 22:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)

    DRV:64bit: - [2012/11/05 21:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)

    DRV:64bit: - [2012/10/26 05:17:44 | 000,020,912 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\avgboota.sys -- (Avgboota)

    DRV:64bit: - [2012/10/12 02:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)

    DRV:64bit: - [2012/10/11 01:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)

    DRV:64bit: - [2012/10/10 21:51:49 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\serscan.sys -- (StillCam)

    DRV:64bit: - [2012/09/20 01:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)

    DRV:64bit: - [2012/09/20 01:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)

    DRV:64bit: - [2012/08/24 03:38:28 | 000,448,312 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\SynTP.sys -- (SynTP)

    DRV:64bit: - [2012/08/24 03:38:28 | 000,043,832 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys -- (SmbDrvI)

    DRV:64bit: - [2012/08/24 03:38:26 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Smb_driver_AMDASF.sys -- (SmbDrv)

    DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)

    DRV:64bit: - [2012/08/03 15:07:30 | 000,020,288 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\WirelessButtonDriver64.sys -- (WirelessButtonDriver)

    DRV:64bit: - [2012/08/02 04:54:18 | 010,280,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)

    DRV:64bit: - [2012/08/02 02:09:30 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)

    DRV:64bit: - [2012/07/25 23:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

    DRV:64bit: - [2012/07/25 23:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)

    DRV:64bit: - [2012/07/25 23:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)

    DRV:64bit: - [2012/07/25 23:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)

    DRV:64bit: - [2012/07/25 23:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)

    DRV:64bit: - [2012/07/25 23:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)

    DRV:64bit: - [2012/07/25 23:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)

    DRV:64bit: - [2012/07/25 23:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)

    DRV:64bit: - [2012/07/25 23:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)

    DRV:64bit: - [2012/07/25 23:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)

    DRV:64bit: - [2012/07/25 23:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)

    DRV:64bit: - [2012/07/25 23:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)

    DRV:64bit: - [2012/07/25 23:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)

    DRV:64bit: - [2012/07/25 23:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)

    DRV:64bit: - [2012/07/25 23:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)

    DRV:64bit: - [2012/07/25 23:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)

    DRV:64bit: - [2012/07/25 23:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)

    DRV:64bit: - [2012/07/25 22:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)

    DRV:64bit: - [2012/07/25 22:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)

    DRV:64bit: - [2012/07/25 21:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)

    DRV:64bit: - [2012/07/25 20:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice)

    DRV:64bit: - [2012/07/25 20:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)

    DRV:64bit: - [2012/07/25 20:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)

    DRV:64bit: - [2012/07/25 20:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)

    DRV:64bit: - [2012/07/25 20:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)

    DRV:64bit: - [2012/07/25 20:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)

    DRV:64bit: - [2012/07/25 20:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)

    DRV:64bit: - [2012/07/25 20:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)

    DRV:64bit: - [2012/07/25 20:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)

    DRV:64bit: - [2012/07/25 20:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)

    DRV:64bit: - [2012/07/25 20:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)

    DRV:64bit: - [2012/07/25 20:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)

    DRV:64bit: - [2012/07/25 20:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)

    DRV:64bit: - [2012/07/25 20:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)

    DRV:64bit: - [2012/07/25 20:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)

    DRV:64bit: - [2012/07/25 20:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)

    DRV:64bit: - [2012/07/25 20:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)

    DRV:64bit: - [2012/07/25 20:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)

    DRV:64bit: - [2012/07/25 20:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)

    DRV:64bit: - [2012/07/25 20:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)

    DRV:64bit: - [2012/07/25 20:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)

    DRV:64bit: - [2012/07/25 20:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)

    DRV:64bit: - [2012/07/23 15:35:12 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\amd_sata.sys -- (amd_sata)

    DRV:64bit: - [2012/07/23 15:35:12 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\amd_xata.sys -- (amd_xata)

    DRV:64bit: - [2012/07/04 12:41:58 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RtsPStor.sys -- (RSPCIESTOR)

    DRV:64bit: - [2012/06/25 11:24:50 | 000,092,536 | ---- | M] (CyberLink) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\CLVirtualDrive.sys -- (CLVirtualDrive)

    DRV:64bit: - [2012/06/18 20:07:50 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\usbfilter.sys -- (usbfilter)

    DRV:64bit: - [2012/06/12 23:41:22 | 000,683,664 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168)

    DRV:64bit: - [2012/06/02 08:32:26 | 010,627,744 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\igdkmd64.sys -- (igfx)

    DRV - [2013/09/10 23:18:30 | 000,265,872 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys -- (RapportEI64)

    DRV - [2013/09/10 23:18:28 | 000,384,432 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys -- (RapportPG64)

    DRV - [2013/08/21 11:14:57 | 000,589,872 | ---- | M] () [Kernel | System | Running] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys -- (RapportCerberus_56758)

     

     

    ========== Standard Registry (SafeList) ==========

     

     

    ========== Internet Explorer ==========

     

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}

    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPNTDFJS

    IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1

    IE - HKLM\..\SearchScopes,DefaultScope = 

    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

    IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}

     

     

    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = 

    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

     

    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = 

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

     

    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = 

     

    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = 

     

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes,DefaultScope = 

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPNTDFJS

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}

    IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

     

     

    ========== FireFox ==========

     

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()

    FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found

    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

    FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)

    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)

    FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)

    FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)

    FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)

    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)

    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)

    FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()

    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

     

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/10/07 19:17:00 | 000,000,000 | ---D | M]

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/10/07 19:17:00 | 000,000,000 | ---D | M]

     

    [2013/10/08 21:54:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default\extensions

    [2013/10/08 21:54:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}

     

    ========== Chrome  ==========

     

    CHR - default_search_provider: Google (Enabled)

    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}

    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},

    CHR - homepage: http://www.google.com

    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll

    CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

    CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll

    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll

    CHR - plugin: Norton Confidential (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.0.0.72_0\npcoplgn.dll

    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll

    CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dll

    CHR - Extension: Google Drive = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\

    CHR - Extension: YouTube = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\

    CHR - Extension: Google Search = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\

    CHR - Extension: RealDownloader = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_0\

    CHR - Extension: Gmail = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

     

    O1 HOSTS File: ([2012/07/25 23:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts

    O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)

    O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)

    O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)

    O3 - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.

    O4:64bit: - HKLM..\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)

    O4 - HKLM..\Run: []  File not found

    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

    O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)

    O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)

    O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)

    O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)

    O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

    O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)

    O4 - HKU\.DEFAULT..\Run: [searchProtect] \SearchProtect\bin\cltmng.exe File not found

    O4 - HKU\S-1-5-18..\Run: [searchProtect] \SearchProtect\bin\cltmng.exe File not found

    O4 - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002..\Run: [sanDiskSecureAccess_Manager.exe] C:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe (Gemalto N.V.)

    O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

    O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)

    O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)

    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)

    O1364bit: - gopher Prefix: missing

    O13 - gopher Prefix: missing

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 67.215.21.202 72.21.70.3

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}: DhcpNameServer = 67.215.21.202 72.21.70.3

    O18:64bit: - Protocol\Handler\cdo - No CLSID value found

    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found

    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found

    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found

    O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found

    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found

    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

    O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)

    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

    O30 - LSA: Security Packages - (livessp) -  File not found

    O32 - HKLM CDRom: AutoRun - 1

    O33 - MountPoints2\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\Shell - "" = AutoRun

    O33 - MountPoints2\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\Shell\AutoRun\command - "" = "F:\LaunchU3.exe" -a

    O34 - HKLM BootExecute: (autocheck autochk *)

    O35:64bit: - HKLM\..comfile [open] -- "%1" %*

    O35:64bit: - HKLM\..exefile [open] -- "%1" %*

    O35 - HKLM\..comfile [open] -- "%1" %*

    O35 - HKLM\..exefile [open] -- "%1" %*

    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

    O37 - HKLM\...com [@ = comfile] -- "%1" %*

    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

     

    ========== Files/Folders - Created Within 180 Days ==========

     

    [2013/10/27 21:08:57 | 000,000,000 | ---D | C] -- C:\Users\Dave\Desktop\Scans

    [2013/10/27 20:03:07 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Avg2013

    [2013/10/26 23:07:30 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Malwarebytes

    [2013/10/26 23:07:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

    [2013/10/26 23:07:04 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

    [2013/10/26 23:07:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

    [2013/10/26 22:13:00 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT

    [2013/10/26 22:05:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner

    [2013/10/15 13:44:43 | 000,694,232 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe

    [2013/10/15 13:44:43 | 000,078,296 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    [2013/10/12 21:39:54 | 001,374,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdc.dll

    [2013/10/12 21:39:53 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wvc.dll

    [2013/10/12 21:39:45 | 001,245,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdc.dll

    [2013/10/12 21:39:44 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx

    [2013/10/12 21:39:42 | 000,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx

    [2013/10/12 21:39:41 | 000,437,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wvc.dll

    [2013/10/12 21:36:01 | 010,116,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll

    [2013/10/12 21:35:57 | 008,858,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll

    [2013/10/12 21:35:56 | 001,125,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll

    [2013/10/12 21:35:51 | 002,304,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll

    [2013/10/12 21:35:51 | 002,035,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll

    [2013/10/12 21:35:51 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSync.dll

    [2013/10/12 21:35:51 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll

    [2013/10/12 21:35:50 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSync.dll

    [2013/10/12 21:35:50 | 000,225,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mbsmsapi.dll

    [2013/10/12 21:35:49 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mbsmsapi.dll

    [2013/10/12 21:35:48 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncInfo.dll

    [2013/10/10 15:53:07 | 000,652,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll

    [2013/10/10 15:53:02 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UXInit.dll

    [2013/10/10 15:53:01 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll

    [2013/10/10 15:52:59 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll

    [2013/10/10 15:52:58 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UXInit.dll

    [2013/10/10 15:52:57 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll

    [2013/10/10 15:52:57 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll

    [2013/10/10 15:52:52 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll

    [2013/10/10 15:52:52 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe

    [2013/10/10 15:52:52 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll

    [2013/10/10 15:52:50 | 000,915,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uxtheme.dll

    [2013/10/10 15:52:50 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll

    [2013/10/10 15:52:41 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll

    [2013/10/10 15:51:05 | 003,959,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll

    [2013/10/10 15:51:02 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll

    [2013/10/10 15:48:41 | 000,054,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys

    [2013/10/10 15:48:40 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys

    [2013/10/10 15:48:40 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys

    [2013/10/10 15:48:25 | 000,362,496 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll

    [2013/10/10 15:48:25 | 000,300,032 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll

    [2013/10/10 15:48:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll

    [2013/10/10 15:48:25 | 000,035,328 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll

    [2013/10/10 15:48:15 | 000,498,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys

    [2013/10/10 15:48:15 | 000,021,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys

    [2013/10/10 15:48:10 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll

    [2013/10/10 15:48:10 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll

    [2013/10/10 15:48:09 | 000,337,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS

    [2013/10/10 15:48:08 | 000,447,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS

    [2013/10/10 15:48:08 | 000,213,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UCX01000.SYS

    [2013/10/07 19:19:07 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Programs

    [2013/10/07 19:18:15 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\WordOv

    [2013/10/07 19:18:13 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\RealNetworks

    [2013/10/07 19:16:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RealNetworks

    [2013/10/07 19:16:45 | 000,000,000 | ---D | C] -- C:\ProgramData\RealNetworks

    [2013/10/07 19:14:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared

    [2013/10/07 19:14:31 | 000,201,872 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll

    [2013/10/07 19:14:08 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll

    [2013/10/07 19:14:08 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll

    [2013/10/07 19:13:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks

    [2013/10/07 19:13:56 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll

    [2013/10/07 19:13:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real

    [2013/10/07 19:11:24 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Real

    [2013/10/07 19:10:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Real

    [2013/10/04 13:18:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes

    [2013/10/04 13:17:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod

    [2013/10/04 13:17:04 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes

    [2013/10/04 13:17:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes

    [2013/10/04 13:17:04 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

    [2013/09/25 18:58:09 | 000,000,000 | ---D | C] -- C:\Users\Dave\New folder (2)

    [2013/09/25 18:56:05 | 000,000,000 | ---D | C] -- C:\Users\Dave\New folder

    [2013/09/25 18:54:30 | 000,000,000 | ---D | C] -- C:\Users\Dave\Work

    [2013/09/20 22:57:50 | 000,209,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationUI.exe

    [2013/09/20 22:57:49 | 002,371,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSService.dll

    [2013/09/20 22:57:49 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll

    [2013/09/20 22:57:44 | 000,688,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSShared.dll

    [2013/09/20 22:57:44 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSetupUI.dll

    [2013/09/20 22:57:43 | 000,562,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSShared.dll

    [2013/09/20 22:57:42 | 000,773,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll

    [2013/09/20 22:57:41 | 000,368,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppwinob.dll

    [2013/09/20 22:57:41 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppc.dll

    [2013/09/20 22:57:40 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppc.dll

    [2013/09/20 22:57:39 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll

    [2013/09/20 22:57:38 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll

    [2013/09/20 22:57:37 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSSync.dll

    [2013/09/20 22:57:34 | 001,621,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll

    [2013/09/20 22:57:33 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSSync.dll

    [2013/09/20 22:57:33 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll

    [2013/09/20 22:57:32 | 000,059,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe

    [2013/09/20 22:57:32 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll

    [2013/09/20 22:57:31 | 000,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll

    [2013/09/20 22:57:30 | 000,204,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSClient.dll

    [2013/09/20 22:57:29 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.dll

    [2013/09/20 22:57:29 | 000,058,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dam.sys

    [2013/09/20 22:57:29 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll

    [2013/09/20 22:57:28 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSClient.dll

    [2013/09/20 22:57:27 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\storewuauth.dll

    [2013/09/20 22:57:26 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll

    [2013/09/20 22:57:26 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll

    [2013/09/20 22:57:25 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll

    [2013/09/20 22:57:23 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll

    [2013/09/20 22:57:22 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupcln.dll

    [2013/09/20 22:57:22 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe

    [2013/09/20 22:57:22 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe

    [2013/09/20 22:57:21 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll

    [2013/09/20 22:57:20 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll

    [2013/09/20 22:57:19 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setupcln.dll

    [2013/09/20 22:52:13 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tssdisai.dll

    [2013/09/20 19:32:12 | 000,000,000 | ---D | C] -- C:\temp

    [2013/09/20 19:31:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC HealthBoost

    [2013/09/20 19:31:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC HealthBoost

    [2013/09/20 19:30:34 | 000,000,000 | ---D | C] -- C:\ProgramData\PCHealthBoost

    [2013/09/20 19:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2014

    [2013/09/20 19:02:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CodeMeter

    [2013/09/20 19:01:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GetData

    [2013/09/11 09:02:26 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Macromedia

    [2013/09/11 09:00:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Mozilla

    [2013/09/11 09:00:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Mozilla

    [2013/09/11 09:00:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla

    [2013/09/11 08:59:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox

    [2013/08/27 11:10:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG

    [2013/08/21 11:12:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection

    [2013/08/19 17:18:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center

    [2013/08/19 17:17:40 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Mouse and Keyboard Center

    [2013/08/19 17:14:50 | 002,273,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll

    [2013/08/19 17:14:48 | 002,839,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll

    [2013/08/19 17:14:46 | 001,025,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll

    [2013/08/19 17:14:46 | 000,778,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll

    [2013/08/19 17:14:45 | 001,300,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll

    [2013/08/19 17:14:44 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL

    [2013/08/19 17:14:43 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanconn.dll

    [2013/08/19 17:14:43 | 000,327,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys

    [2013/08/19 17:14:42 | 000,439,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFault.exe

    [2013/08/19 17:14:42 | 000,263,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll

    [2013/08/19 17:14:42 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll

    [2013/08/19 17:14:42 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmmbase.dll

    [2013/08/19 17:14:42 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmm.dll

    [2013/08/19 17:14:41 | 000,385,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFault.exe

    [2013/08/19 17:14:41 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winmmbase.dll

    [2013/08/19 17:14:38 | 000,195,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys

    [2013/08/19 17:14:38 | 000,125,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpsd.sys

    [2013/08/19 17:14:38 | 000,120,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\msgpioclx.sys

    [2013/08/19 17:14:37 | 000,370,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wwanadvui.dll

    [2013/08/19 17:14:37 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll

    [2013/08/19 17:14:37 | 000,096,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys

    [2013/08/19 17:14:37 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmcsp.dll

    [2013/08/19 17:14:36 | 000,543,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanmm.dll

    [2013/08/19 17:14:36 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.dll

    [2013/08/19 17:14:36 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL

    [2013/08/19 17:14:36 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\openfiles.exe

    [2013/08/19 17:14:35 | 000,888,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll

    [2013/08/19 17:14:35 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll

    [2013/08/19 17:14:35 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\openfiles.exe

    [2013/08/19 17:14:34 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationApi.dll

    [2013/08/19 17:14:34 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LocationApi.dll

    [2013/08/19 17:12:38 | 000,000,000 | ---D | C] -- C:\1570ac898210a48ebc25d182f807

    [2013/08/17 01:14:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT

    [2013/08/16 12:37:31 | 000,247,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdFilter.sys

    [2013/08/16 12:37:31 | 000,036,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdBoot.sys

    [2013/08/14 23:09:25 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll

    [2013/08/14 15:12:06 | 001,889,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll

    [2013/08/14 15:12:05 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll

    [2013/08/14 15:12:04 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apprepapi.dll

    [2013/08/14 15:12:04 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apprepsync.dll

    [2013/08/14 15:12:04 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepapi.dll

    [2013/08/14 15:12:04 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepsync.dll

    [2013/07/26 19:11:44 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk SecureAccess Manager

    [2013/07/26 19:11:41 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\SanDisk

    [2013/07/26 19:08:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\SanDisk SecureAccess

    [2013/07/20 01:51:00 | 000,311,608 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys

    [2013/07/20 01:50:56 | 000,246,072 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys

    [2013/07/20 01:50:56 | 000,071,480 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys

    [2013/07/20 01:50:50 | 000,206,648 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys

    [2013/07/16 18:43:51 | 002,219,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll

    [2013/07/16 18:43:48 | 002,391,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe

    [2013/07/16 18:43:48 | 001,842,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll

    [2013/07/16 18:43:47 | 006,987,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe

    [2013/07/16 18:43:47 | 002,106,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe

    [2013/07/16 18:43:44 | 000,729,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll

    [2013/07/16 18:43:41 | 001,527,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll

    [2013/07/16 18:43:41 | 001,453,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll

    [2013/07/16 18:43:39 | 001,403,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi

    [2013/07/16 18:43:39 | 001,271,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe

    [2013/07/16 18:43:38 | 000,523,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll

    [2013/07/16 18:43:37 | 001,217,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi

    [2013/07/16 18:43:37 | 001,093,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe

    [2013/07/16 18:43:37 | 000,583,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscms.dll

    [2013/07/16 18:43:36 | 001,048,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfasfsrcsnk.dll

    [2013/07/16 18:43:36 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll

    [2013/07/16 18:43:35 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samlib.dll

    [2013/07/16 18:43:34 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfasfsrcsnk.dll

    [2013/07/16 18:43:34 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceSetupManager.dll

    [2013/07/16 18:43:34 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MbaeParserTask.exe

    [2013/07/16 18:43:32 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsutil.dll

    [2013/07/16 18:43:32 | 000,037,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys

    [2013/07/16 10:57:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\Documents\Corel User Files

    [2013/07/16 10:37:15 | 000,000,000 | ---D | C] -- C:\Users\Dave\Documents\Fonts

    [2013/07/13 13:15:18 | 000,000,000 | ---D | C] -- C:\Users\Dave\Documents\Graphics

    [2013/07/11 10:56:53 | 001,838,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll

    [2013/07/11 10:56:50 | 000,595,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll

    [2013/07/11 10:56:50 | 000,496,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll

    [2013/07/11 10:54:23 | 002,842,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL

    [2013/07/11 10:54:22 | 002,620,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL

    [2013/07/10 01:32:38 | 000,045,880 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys

    [2013/07/09 01:28:50 | 000,248,632 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgwfpa.sys

    [2013/07/07 17:22:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus

    [2013/07/07 17:20:48 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan

    [2013/07/07 17:20:45 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee

    [2013/07/07 17:20:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee Security Scan

    [2013/07/07 17:19:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe

    [2013/07/07 17:19:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe

    [2013/07/07 17:17:51 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Adobe

    [2013/07/01 01:45:28 | 000,116,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys

    [2013/06/21 21:55:05 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Apple Computer

    [2013/06/21 21:54:16 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys

    [2013/06/21 21:50:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud

    [2013/06/21 21:50:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple

    [2013/06/21 21:46:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime

    [2013/06/21 21:45:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime

    [2013/06/21 21:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer

    [2013/06/16 15:19:44 | 001,257,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll

    [2013/06/15 23:15:14 | 000,888,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autochk.exe

    [2013/06/15 23:15:13 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll

    [2013/06/15 23:15:13 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll

    [2013/06/15 23:15:12 | 000,793,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe

    [2013/06/15 11:20:12 | 013,644,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll

    [2013/06/15 11:20:06 | 010,788,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll

    [2013/06/15 11:20:02 | 001,131,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll

    [2013/06/15 11:19:54 | 000,470,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netprofmsvc.dll

    [2013/06/15 11:19:48 | 000,014,848 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\rars.rs

    [2013/06/15 11:19:48 | 000,014,848 | ---- | C] (Microsoft) -- C:\Windows\SysNative\rars.rs

    [2013/06/15 11:19:47 | 000,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BCP47Langs.dll

    [2013/06/15 11:19:47 | 000,330,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll

    [2013/06/15 11:19:47 | 000,328,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ubpm.dll

    [2013/06/15 11:19:47 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ubpm.dll

    [2013/06/15 11:19:46 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.dll

    [2013/06/15 11:19:46 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netplwiz.dll

    [2013/06/15 11:19:45 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Magnify.exe

    [2013/06/15 11:19:44 | 000,560,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfmp4srcsnk.dll

    [2013/06/15 11:19:44 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psmsrv.dll

    [2013/06/15 11:19:41 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll

    [2013/06/15 11:19:40 | 000,501,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairing.dll

    [2013/06/15 11:19:40 | 000,284,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys

    [2013/06/15 11:19:39 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\intl.cpl

    [2013/06/15 11:19:39 | 000,120,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuthHost.exe

    [2013/06/15 11:19:38 | 000,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Magnify.exe

    [2013/06/15 11:19:37 | 000,449,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairing.dll

    [2013/06/15 11:19:37 | 000,122,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\biwinrt.dll

    [2013/06/15 11:19:36 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\biwinrt.dll

    [2013/06/15 11:19:35 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\intl.cpl

    [2013/06/15 11:19:35 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bisrv.dll

    [2013/06/15 11:19:34 | 000,411,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfmp4srcsnk.dll

    [2013/06/15 11:19:34 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\BCP47Langs.dll

    [2013/06/15 11:19:32 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\muifontsetup.dll

    [2013/06/15 11:19:32 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\muifontsetup.dll

    [2013/06/12 15:40:07 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptdlg.dll

    [2013/06/12 15:40:07 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptdlg.dll

    [2013/06/12 08:40:52 | 001,255,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe

    [2013/06/12 08:40:51 | 001,013,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe

    [2013/06/12 08:40:51 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll

    [2013/06/12 08:40:45 | 000,733,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll

    [2013/05/29 20:53:04 | 006,085,632 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll

    [2013/05/29 20:53:04 | 001,821,184 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\IDTNC64.cpl

    [2013/05/29 20:53:04 | 001,664,000 | ---- | C] (IDT, Inc.) -- C:\Windows\sttray64.exe

    [2013/05/29 20:52:52 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SRSLabs

    [2013/05/29 20:49:36 | 000,255,488 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\staco64.dll

    [2013/05/29 20:49:28 | 000,542,208 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys

    [2013/05/29 20:49:26 | 002,188,800 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll

    [2013/05/29 20:49:26 | 000,671,744 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll

    [2013/05/29 20:49:26 | 000,499,200 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll

    [2013/05/23 23:08:49 | 000,000,000 | -H-D | C] -- C:\$SysReset

    [2013/05/17 09:17:06 | 003,552,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll

    [2013/05/17 09:17:05 | 014,267,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll

    [2013/05/17 09:17:01 | 011,878,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll

    [2013/05/17 09:16:58 | 002,107,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll

    [2013/05/17 09:16:55 | 002,767,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll

    [2013/05/17 09:16:53 | 001,593,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll

    [2013/05/17 09:16:49 | 001,829,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll

    [2013/05/17 09:16:47 | 001,444,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAudDecMFT.dll

    [2013/05/17 09:16:37 | 001,113,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAudDecMFT.dll

    [2013/05/17 09:16:36 | 000,306,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd_02_10ec.dll

    [2013/05/17 09:16:35 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll

    [2013/05/17 09:16:34 | 000,298,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rsaenh.dll

    [2013/05/17 09:16:33 | 000,446,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll

    [2013/05/17 09:16:33 | 000,373,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe

    [2013/05/17 09:16:31 | 000,489,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll

    [2013/05/17 09:16:30 | 000,435,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll

    [2013/05/17 09:16:30 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe

    [2013/05/17 09:16:30 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmredir.dll

    [2013/05/17 09:16:28 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.dll

    [2013/05/17 09:16:28 | 000,253,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe

    [2013/05/17 09:16:27 | 000,804,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RecoveryDrive.exe

    [2013/05/17 09:16:27 | 000,456,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpncore.dll

    [2013/05/17 09:16:21 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dmvdsitf.dll

    [2013/05/17 09:16:20 | 000,503,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll

    [2013/05/17 09:16:20 | 000,468,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MFMediaEngine.dll

    [2013/05/17 09:16:20 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fhengine.dll

    [2013/05/17 09:16:19 | 000,659,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll

    [2013/05/17 09:16:19 | 000,411,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.dll

    [2013/05/17 09:16:19 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll

    [2013/05/17 09:16:19 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEndpointBuilder.dll

    [2013/05/17 09:16:18 | 000,123,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll

    [2013/05/17 09:16:17 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Robocopy.exe

    [2013/05/17 09:16:17 | 000,077,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdvm.dll

    [2013/05/17 09:16:16 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iuilp.dll

    [2013/05/17 09:16:16 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe

    [2013/05/17 09:16:16 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Robocopy.exe

    [2013/05/17 09:16:15 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll

    [2013/05/17 09:16:15 | 000,155,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmvdsitf.dll

    [2013/05/17 09:16:15 | 000,086,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdnet.dll

    [2013/05/17 09:16:14 | 000,745,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll

    [2013/05/17 09:16:14 | 000,414,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GenuineCenter.dll

    [2013/05/17 09:16:14 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFMediaEngine.dll

    [2013/05/17 09:16:13 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssprxy.dll

    [2013/05/17 09:16:13 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll

    [2013/05/17 09:16:13 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fmifs.dll

    [2013/05/17 09:16:13 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fmifs.dll

    [2013/05/17 09:16:13 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msshooks.dll

    [2013/05/17 09:16:13 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msshooks.dll

    [2013/05/15 19:48:08 | 002,382,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\esent.dll

    [2013/05/15 19:48:06 | 002,851,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\esent.dll

    [2013/05/15 08:50:08 | 000,112,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe

    [2013/05/13 15:36:12 | 000,354,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vccorlib110.dll

    [2013/05/13 15:36:06 | 000,050,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\point64.sys

    [2013/05/06 08:32:28 | 002,274,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\coin94.dll

    [2013/05/06 08:32:28 | 000,076,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dc3d.sys

    [2013/05/01 03:59:12 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\Windows\SysWow64\QuickTimeVR.qtx

    [2013/05/01 03:59:12 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\Windows\SysWow64\QuickTime.qts

    [1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]

     

    ========== Files - Modified Within 180 Days ==========

     

    [2013/10/27 22:13:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job

    [2013/10/27 22:11:17 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

    [2013/10/27 21:52:26 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job

    [2013/10/27 21:47:01 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

    [2013/10/27 21:41:59 | 000,001,050 | ---- | M] () -- C:\Users\Dave\Desktop\JRT - Shortcut.lnk

    [2013/10/27 21:36:01 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\PrintProjects Communicator.job

    [2013/10/27 20:22:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

    [2013/10/27 20:20:39 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys

    [2013/10/27 20:20:38 | 3088,900,096 | -HS- | M] () -- C:\hiberfil.sys

    [2013/10/27 19:26:01 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForDave.job

    [2013/10/26 23:07:09 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

    [2013/10/26 22:25:45 | 001,653,808 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

    [2013/10/07 19:14:31 | 000,201,872 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll

    [2013/10/07 19:14:08 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll

    [2013/10/07 19:14:08 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll

    [2013/10/07 19:13:57 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll

    [2013/10/04 13:18:10 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk

    [2013/10/01 20:57:21 | 000,003,734 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml

    [2013/10/01 20:57:03 | 000,046,368 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys

    [2013/10/01 19:38:13 | 000,694,232 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe

    [2013/10/01 19:38:13 | 000,078,296 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    [2013/10/01 12:14:12 | 000,000,068 | ---- | M] () -- C:\Users\Dave\AppData\Roaming\WB.CFG

    [2013/09/22 17:27:49 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll

    [2013/09/22 16:55:16 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe

    [2013/09/22 16:54:55 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll

    [2013/09/22 16:54:51 | 003,959,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll

    [2013/09/22 16:54:51 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll

    [2013/09/20 23:25:14 | 000,941,114 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

    [2013/09/20 23:25:14 | 000,783,894 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

    [2013/09/20 23:25:14 | 000,158,368 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

    [2013/09/10 23:18:30 | 000,266,928 | ---- | M] (Trusteer Ltd.) -- C:\Windows\SysNative\drivers\RapportHades64.sys

    [2013/09/10 23:18:28 | 000,295,696 | ---- | M] (Trusteer Ltd.) -- C:\Windows\SysNative\drivers\RapportKE64.sys

    [2013/08/15 23:41:13 | 000,058,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dam.sys

    [2013/08/15 23:39:26 | 002,371,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSService.dll

    [2013/08/15 23:39:26 | 000,059,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe

    [2013/08/15 23:32:48 | 000,209,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationUI.exe

    [2013/08/15 23:22:22 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe

    [2013/08/15 23:21:55 | 001,621,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll

    [2013/08/15 23:21:55 | 000,252,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll

    [2013/08/15 23:21:55 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll

    [2013/08/15 23:21:55 | 000,099,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll

    [2013/08/15 23:21:55 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll

    [2013/08/15 23:21:55 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll

    [2013/08/15 23:21:53 | 000,773,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll

    [2013/08/15 23:21:43 | 000,688,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSShared.dll

    [2013/08/15 23:21:43 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSSync.dll

    [2013/08/15 23:21:42 | 000,204,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSClient.dll

    [2013/08/15 23:21:42 | 000,198,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.dll

    [2013/08/15 23:21:42 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll

    [2013/08/15 23:21:22 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\storewuauth.dll

    [2013/08/15 23:21:18 | 001,164,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll

    [2013/08/15 23:21:18 | 000,368,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppwinob.dll

    [2013/08/15 23:21:12 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\setupcln.dll

    [2013/08/15 23:21:00 | 000,120,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppc.dll

    [2013/08/15 23:20:30 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WinSetupUI.dll

    [2013/08/15 16:43:21 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe

    [2013/08/15 16:43:07 | 000,628,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll

    [2013/08/15 16:43:07 | 000,126,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll

    [2013/08/15 16:43:07 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll

    [2013/08/15 16:43:07 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll

    [2013/08/15 16:43:03 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSShared.dll

    [2013/08/15 16:43:03 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSSync.dll

    [2013/08/15 16:43:02 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSClient.dll

    [2013/08/15 16:43:02 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll

    [2013/08/15 16:43:02 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll

    [2013/08/15 16:43:02 | 000,083,968 | ---- | M] () -- C:\Windows\SysWow64\OEMLicense.dll

    [2013/08/15 16:42:52 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\setupcln.dll

    [2013/08/15 16:42:47 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\sppc.dll

    [2013/08/09 23:21:51 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSync.dll

    [2013/08/09 23:21:51 | 000,128,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncInfo.dll

    [2013/08/09 21:58:51 | 000,356,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSync.dll

    [2013/08/06 23:15:02 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tssdisai.dll

    [2013/08/03 00:40:49 | 000,462,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx

    [2013/08/03 00:40:17 | 000,566,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wvc.dll

    [2013/08/03 00:40:01 | 001,374,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wdc.dll

    [2013/08/02 23:14:15 | 000,399,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx

    [2013/08/02 23:13:57 | 000,437,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wvc.dll

    [2013/08/02 23:13:43 | 001,245,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wdc.dll

    [2013/08/02 18:02:49 | 356,661,235 | ---- | M] () -- C:\Windows\MEMORY.DMP

    [2013/08/02 00:28:29 | 010,116,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll

    [2013/08/02 00:28:20 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll

    [2013/08/02 00:26:53 | 002,304,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll

    [2013/08/01 23:08:18 | 008,858,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll

    [2013/08/01 23:06:50 | 002,035,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll

    [2013/07/30 17:30:05 | 000,386,923 | ---- | M] () -- C:\Windows\SysNative\ApnDatabase.xml

    [2013/07/26 21:58:39 | 002,207,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\PrintConfig.dll

    [2013/07/26 19:53:41 | 000,001,312 | ---- | M] () -- C:\Users\Public\Desktop\The Weather Channel App.lnk

    [2013/07/24 17:10:08 | 000,158,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mbsmsapi.dll

    [2013/07/24 17:06:39 | 000,225,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mbsmsapi.dll

    [2013/07/20 01:51:00 | 000,311,608 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys

    [2013/07/20 01:50:56 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys

    [2013/07/20 01:50:56 | 000,071,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys

    [2013/07/20 01:50:50 | 000,206,648 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys

    [2013/07/19 16:13:34 | 000,124,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll

    [2013/07/19 16:13:15 | 000,102,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll

    [2013/07/13 00:18:21 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll

    [2013/07/13 00:16:06 | 001,889,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll

    [2013/07/13 00:15:53 | 000,124,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\apprepapi.dll

    [2013/07/13 00:15:53 | 000,098,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\apprepsync.dll

    [2013/07/12 22:23:03 | 000,087,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepapi.dll

    [2013/07/12 22:23:03 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepsync.dll

    [2013/07/12 19:51:22 | 000,000,017 | ---- | M] () -- C:\Users\Dave\AppData\Local\resmon.resmoncfg

    [2013/07/10 01:32:38 | 000,045,880 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys

    [2013/07/09 02:04:07 | 000,120,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\msgpioclx.sys

    [2013/07/09 01:28:50 | 000,248,632 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgwfpa.sys

    [2013/07/09 00:18:21 | 000,439,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WerFault.exe

    [2013/07/08 22:25:45 | 000,385,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFault.exe

    [2013/07/08 21:57:19 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\LocationApi.dll

    [2013/07/08 16:46:00 | 000,543,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wwanmm.dll

    [2013/07/08 16:46:00 | 000,414,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wwanconn.dll

    [2013/07/08 16:46:00 | 000,370,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Wwanadvui.dll

    [2013/07/08 16:45:16 | 000,312,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\LocationApi.dll

    [2013/07/07 17:22:56 | 000,002,046 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk

    [2013/07/07 17:22:56 | 000,002,046 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

    [2013/07/05 18:16:17 | 001,025,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll

    [2013/07/05 18:15:29 | 000,652,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll

    [2013/07/02 18:23:43 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.dll

    [2013/07/02 18:23:12 | 000,778,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll

    [2013/07/02 18:22:47 | 002,839,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll

    [2013/07/02 18:22:26 | 001,300,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll

    [2013/07/02 18:11:23 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll

    [2013/07/02 18:10:53 | 002,273,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll

    [2013/07/01 19:41:47 | 000,447,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS

    [2013/07/01 19:41:47 | 000,337,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS

    [2013/07/01 19:41:47 | 000,213,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UCX01000.SYS

    [2013/07/01 18:44:14 | 000,036,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdBoot.sys

    [2013/07/01 16:08:49 | 000,247,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdFilter.sys

    [2013/07/01 01:45:28 | 000,116,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys

    [2013/06/30 19:42:09 | 000,498,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys

    [2013/06/30 19:42:09 | 000,021,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys

    [2013/06/30 16:30:14 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\openfiles.exe

    [2013/06/30 16:29:22 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\openfiles.exe

    [2013/06/29 00:15:54 | 000,195,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys

    [2013/06/29 00:15:47 | 000,125,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpsd.sys

    [2013/06/28 23:43:16 | 000,327,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys

    [2013/06/28 21:08:18 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys

    [2013/06/28 21:07:13 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys

    [2013/06/25 14:54:11 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_dc3d_01011.Wdf

    [2013/06/24 16:54:45 | 000,263,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll

    [2013/06/24 16:54:45 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wcmcsp.dll

    [2013/06/21 23:45:57 | 000,054,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys

    [2013/06/18 23:36:21 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winmmbase.dll

    [2013/06/18 23:36:21 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winmm.dll

    [2013/06/18 16:38:00 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\winmmbase.dll

    [2013/06/11 17:26:20 | 000,230,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll

    [2013/06/10 15:17:46 | 000,096,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys

    [2013/06/10 13:16:07 | 000,888,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll

    [2013/06/10 13:15:38 | 000,381,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL

    [2013/06/10 13:10:58 | 000,702,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll

    [2013/06/10 13:10:37 | 000,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL

    [2013/06/01 05:34:21 | 002,391,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe

    [2013/06/01 05:26:31 | 006,987,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe

    [2013/06/01 04:24:46 | 002,106,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe

    [2013/06/01 03:25:52 | 000,364,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll

    [2013/06/01 03:25:03 | 000,496,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll

    [2013/06/01 03:24:09 | 001,453,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll

    [2013/06/01 03:24:09 | 000,850,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfasfsrcsnk.dll

    [2013/06/01 03:23:46 | 001,842,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll

    [2013/06/01 03:22:47 | 000,080,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MbaeParserTask.exe

    [2013/06/01 03:22:33 | 000,523,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll

    [2013/06/01 03:22:09 | 000,190,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vdsutil.dll

    [2013/06/01 03:21:39 | 000,729,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll

    [2013/06/01 03:21:39 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\samlib.dll

    [2013/06/01 03:21:34 | 000,595,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll

    [2013/06/01 03:20:45 | 000,583,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mscms.dll

    [2013/06/01 03:20:34 | 001,527,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll

    [2013/06/01 03:20:34 | 001,048,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfasfsrcsnk.dll

    [2013/06/01 03:20:04 | 002,219,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll

    [2013/06/01 03:19:58 | 000,207,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceSetupManager.dll

    [2013/05/31 21:08:57 | 000,037,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys

    [2013/05/30 17:24:29 | 001,257,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll

    [2013/05/29 20:47:43 | 006,085,632 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll

    [2013/05/29 20:47:43 | 001,664,000 | ---- | M] (IDT, Inc.) -- C:\Windows\sttray64.exe

    [2013/05/29 20:47:43 | 000,542,208 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys

    [2013/05/29 20:47:43 | 000,499,200 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll

    [2013/05/29 20:47:42 | 002,188,800 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll

    [2013/05/29 20:47:42 | 000,671,744 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll

    [2013/05/29 20:47:42 | 000,255,488 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\staco64.dll

    [2013/05/29 20:47:37 | 001,821,184 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNC64.cpl

    [2013/05/26 17:17:30 | 000,035,328 | ---- | M] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll

    [2013/05/26 16:59:03 | 000,046,080 | ---- | M] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll

    [2013/05/24 21:15:19 | 000,362,496 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll

    [2013/05/24 20:32:52 | 000,300,032 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll

    [2013/05/24 16:09:20 | 001,403,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi

    [2013/05/24 16:09:20 | 001,271,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe

    [2013/05/24 16:09:20 | 001,217,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi

    [2013/05/24 16:09:20 | 001,093,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe

    [2013/05/23 17:02:30 | 001,314,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll

    [2013/05/15 16:37:03 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\UXInit.dll

    [2013/05/15 16:35:49 | 000,053,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UXInit.dll

    [2013/05/14 20:25:59 | 000,888,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\autochk.exe

    [2013/05/14 20:25:44 | 000,542,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll

    [2013/05/14 20:24:10 | 000,793,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe

    [2013/05/14 20:24:01 | 000,482,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll

    [2013/05/13 15:36:12 | 000,828,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msvcr110.dll

    [2013/05/13 15:36:12 | 000,661,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msvcp110.dll

    [2013/05/13 15:36:12 | 000,354,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vccorlib110.dll

    [2013/05/13 15:36:06 | 000,050,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\point64.sys

    [2013/05/06 08:32:28 | 002,274,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\coin94.dll

    [2013/05/06 08:32:28 | 000,076,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dc3d.sys

    [2013/05/04 01:58:17 | 000,120,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AuthHost.exe

    [2013/05/04 01:34:15 | 000,284,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys

    [2013/05/04 00:59:36 | 000,812,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Magnify.exe

    [2013/05/04 00:59:21 | 002,842,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL

    [2013/05/04 00:59:08 | 013,644,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll

    [2013/05/04 00:58:54 | 000,328,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ubpm.dll

    [2013/05/04 00:58:48 | 000,330,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll

    [2013/05/04 00:58:28 | 000,093,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\psmsrv.dll

    [2013/05/04 00:58:02 | 000,470,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netprofmsvc.dll

    [2013/05/04 00:58:01 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netplwiz.dll

    [2013/05/04 00:57:59 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\muifontsetup.dll

    [2013/05/04 00:57:46 | 000,560,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfmp4srcsnk.dll

    [2013/05/04 00:57:15 | 000,501,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairing.dll

    [2013/05/04 00:57:05 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\bisrv.dll

    [2013/05/04 00:57:05 | 000,122,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\biwinrt.dll

    [2013/05/04 00:57:04 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\BCP47Langs.dll

    [2013/05/04 00:57:00 | 001,131,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll

    [2013/05/04 00:57:00 | 000,708,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.dll

    [2013/05/04 00:56:53 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\intl.cpl

    [2013/05/03 22:58:14 | 000,758,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Magnify.exe

    [2013/05/03 22:57:58 | 002,620,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL

    [2013/05/03 22:57:49 | 010,788,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll

    [2013/05/03 22:57:39 | 000,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ubpm.dll

    [2013/05/03 22:57:04 | 000,151,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll

    [2013/05/03 22:57:02 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\muifontsetup.dll

    [2013/05/03 22:56:48 | 000,411,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfmp4srcsnk.dll

    [2013/05/03 22:56:14 | 000,449,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairing.dll

    [2013/05/03 22:56:06 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\biwinrt.dll

    [2013/05/03 22:56:05 | 000,309,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\BCP47Langs.dll

    [2013/05/03 22:55:58 | 000,389,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\intl.cpl

    [2013/05/03 22:51:38 | 000,014,848 | ---- | M] (Microsoft) -- C:\Windows\SysNative\rars.rs

    [2013/05/03 22:10:47 | 000,014,848 | ---- | M] (Microsoft) -- C:\Windows\SysWow64\rars.rs

    [2013/05/01 03:59:12 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\Windows\SysWow64\QuickTimeVR.qtx

    [2013/05/01 03:59:12 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\Windows\SysWow64\QuickTime.qts

    [1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]

     

    ========== Files Created - No Company Name ==========

     

    [2013/10/27 21:41:59 | 000,001,050 | ---- | C] () -- C:\Users\Dave\Desktop\JRT - Shortcut.lnk

    [2013/10/26 23:07:09 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

    [2013/10/26 22:25:45 | 001,653,808 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT

    [2013/10/12 21:35:48 | 000,386,923 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml

    [2013/10/04 13:18:10 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk

    [2013/09/27 22:05:34 | 000,003,734 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml

    [2013/09/27 12:09:03 | 000,000,068 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\WB.CFG

    [2013/09/20 22:57:19 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll

    [2013/07/12 19:51:22 | 000,000,017 | ---- | C] () -- C:\Users\Dave\AppData\Local\resmon.resmoncfg

    [2013/07/07 17:20:44 | 000,002,046 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk

    [2013/07/07 17:20:44 | 000,002,046 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

    [2013/07/07 17:20:00 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk

    [2013/06/25 14:54:11 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_dc3d_01011.Wdf

    [2013/03/17 16:59:51 | 000,001,067 | ---- | C] () -- C:\Windows\hpomdl35.dat.temp

    [2013/03/17 16:33:22 | 000,225,825 | ---- | C] () -- C:\Windows\hpoins35.dat

    [2013/03/17 16:33:22 | 000,001,067 | ---- | C] () -- C:\Windows\hpomdl35.dat

    [2012/12/27 19:13:50 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI

    [2012/08/17 18:11:41 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin

    [2012/08/03 16:40:09 | 000,916,510 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

    [2012/08/02 02:53:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat

    [2012/08/02 02:53:50 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat

    [2012/07/26 02:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat

    [2012/07/26 02:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT

    [2012/07/26 01:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat

    [2012/07/25 19:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll

    [2012/07/25 14:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin

    [2012/07/25 14:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

    [2012/07/25 14:22:54 | 000,982,240 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin

    [2012/07/25 14:22:54 | 000,439,308 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin

    [2012/07/25 14:22:54 | 000,092,356 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin

    [2012/06/02 08:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

     

    ========== ZeroAccess Check ==========

     

    [2012/08/17 18:26:03 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

     

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

     

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

     

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

     

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

     

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    "" = C:\Windows\SysNative\shell32.dll -- [2013/08/02 00:28:20 | 019,758,080 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Apartment

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    "" = %SystemRoot%\system32\shell32.dll -- [2013/08/01 23:08:10 | 017,561,088 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Apartment

     

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64

    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/25 21:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Free

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

    "" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/25 21:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Free

     

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64

    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/25 21:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Both

     

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

     

    ========== Purity Check ==========

     

     

     

    < End of report >
  14. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Junkware Removal Tool (JRT) by Thisisu

    Version: 6.0.7 (10.15.2013:3)

    OS: Windows 8 x64

    Ran by Dave on Sun 10/27/2013 at 21:42:28.06

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

     

     

     

     

    ~~~ Services

     

     

     

    ~~~ Registry Values

     

     

     

    ~~~ Registry Keys

     

    Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181102}

    Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181102}

     

     

     

    ~~~ Files

     

     

     

    ~~~ Folders

     

    Failed to delete: [Folder] "C:\ProgramData\pchealthboost"

    Failed to delete: [Folder] "C:\Program Files (x86)\pc healthboost"

     

     

     

    ~~~ Event Viewer Logs were cleared

     

     

     

     

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Scan was completed on Sun 10/27/2013 at 22:02:51.55

    End of JRT log

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  15. .

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

    IF REQUESTED, ZIP IT UP & ATTACH IT

    .

    DDS (Ver_2012-11-20.01)

    .

    Microsoft Windows 8

    Boot Device: \Device\HarddiskVolume2

    Install Date: 12/25/2012 6:49:48 PM

    System Uptime: 10/27/2013 8:20:24 PM (1 hours ago)

    .

    Motherboard: Hewlett-Packard |  | 169A

    Processor: AMD E-300 APU with Radeon HD Graphics | Socket FT1 | 1300/100mhz

    .

    ==== Disk Partitions =========================

    .

    C: is FIXED (NTFS) - 276 GiB total, 216.8 GiB free.

    D: is FIXED (NTFS) - 21 GiB total, 2.619 GiB free.

    E: is CDROM ()

    .

    ==== Disabled Device Manager Items =============

    .

    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}

    Description: Photosmart C309a series

    Device ID: ROOT\MULTIFUNCTION\0000

    Manufacturer: HP

    Name: Photosmart C309a series

    PNP Device ID: ROOT\MULTIFUNCTION\0000

    Service: 

    .

    ==== System Restore Points ===================

    .

    RP76: 10/10/2013 8:15:54 PM - HPSF Restore Point

    RP77: 10/13/2013 12:10:26 PM - Installed Rapport

    RP78: 10/27/2013 1:20:31 AM - Scheduled Checkpoint

    .

    ==== Installed Programs ======================

    .

    4 Elements II

    64 Bit HP CIO Components Installer

    Adobe Flash Player 11 Plugin

    Adobe Reader XI (11.0.05)

    Adobe Shockwave Player 11.6

    aiofw

    aioprnt

    aioscnnr

    AMD APP SDK Runtime

    AMD Catalyst Install Manager

    AMD Fuel

    AMD VISION Engine Control Center

    Apple Application Support

    Apple Mobile Device Support

    Apple Software Update

    AtHomeConnect version 1.0.1.0

    AVG 2013

    AVG SafeGuard toolbar

    Bejeweled 3

    Bonjour

    BufferChm

    Build-a-lot 4 - Power Source

    C309a

    Catalyst Control Center - Branding

    Catalyst Control Center Graphics Previews Common

    Catalyst Control Center InstallProxy

    Catalyst Control Center Localization All

    ccc-utility64

    CCC Help Chinese Standard

    CCC Help Chinese Traditional

    CCC Help Czech

    CCC Help Danish

    CCC Help Dutch

    CCC Help English

    CCC Help Finnish

    CCC Help French

    CCC Help German

    CCC Help Greek

    CCC Help Hungarian

    CCC Help Italian

    CCC Help Japanese

    CCC Help Korean

    CCC Help Norwegian

    CCC Help Polish

    CCC Help Portuguese

    CCC Help Russian

    CCC Help Spanish

    CCC Help Swedish

    CCC Help Thai

    CCC Help Turkish

    center

    Chuzzle Deluxe

    CorelDRAW 10

    Cradle Of Egypt Collector's Edition

    Cradle of Rome 2

    CyberLink LabelPrint

    CyberLink Media Suite 10

    CyberLink Power2Go 8

    CyberLink PowerDVD

    CyberLink YouCam

    D3DX10

    Destinations

    DeviceDiscovery

    DocProc

    Energy Star

    Farm Frenzy

    FATE: The Cursed King

    Fax

    Final Drive Fury

    FlatOut 2

    Google Chrome

    Google Update Helper

    Governor of Poker 2 Premium Edition

    GPBaseService2

    H&R Block Deluxe + Efile 2012

    Hewlett-Packard ACLM.NET v1.2.0.0

    Hoyle Card Games

    HP Customer Experience Enhancements

    HP Customer Participation Program 14.0

    HP Documentation

    HP Games

    HP Imaging Device Functions 14.0

    HP MyRoom

    HP Photo Creations

    HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6

    HP Postscript Converter

    HP Quick Launch

    HP Recovery Manager

    HP Registration Service

    HP Software Framework

    HP Solution Center 14.0

    HP Support Assistant

    HP Update

    HP Utility Center

    HP Wireless Button Driver

    HPPhotoGadget

    HPProductAssistant

    HPSSupply

    iCloud

    IDT Audio

    InternetHelper3 Chrome Toolbar

    iTunes

    Jewel Match 3

    John Deere Drive Green

    KODAK AiO Home Center

    ksDIP

    Luxor Evolved

    Mahjongg Dimensions Deluxe: Tiles in Time

    Malwarebytes Anti-Malware version 1.75.0.1300

    MarketResearch

    McAfee Security Scan Plus

    Microsoft Application Error Reporting

    Microsoft Mouse and Keyboard Center

    Microsoft Office

    Microsoft Office XP Media Content

    Microsoft Office XP Professional

    Microsoft SQL Server 2005 Compact Edition [ENU]

    Microsoft Visual C++ 2005 Redistributable

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319

    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219

    Mortimer Beckett and the Crimson Thief Premium Edition

    MSVCRT

    Mystery P.I. - Curious Case of Counterfeit Cove

    Network64

    OCR Software by I.R.I.S. 14.0

    OpenOffice.org 3.4.1

    Peggle Nights

    Penguins!

    Polar Bowler

    Polar Golfer

    PreReq

    PrintProjects

    PS_AIO_05_C309_Software_Min

    QuickTime

    Ralink RT5390R 802.11bgn Wi-Fi Adapter

    Rapport

    RealDownloader

    RealNetworks - Microsoft Visual C++ 2008 Runtime

    RealNetworks - Microsoft Visual C++ 2010 Runtime

    RealPlayer

    Realtek Ethernet Controller Driver

    Realtek PCIE Card Reader

    RealUpgrade 1.1

    Roads of Rome 3

    SanDiskSecureAccess_Manager.exe

    Scan

    Shop for HP Supplies

    Skypeâ„¢ 6.1

    SolutionCenter

    Status

    SweetTunes Toolbar for IE

    swMSM

    Synaptics Pointing Device Driver

    Tales of Lagoona

    The Weather Channel App

    Toolbox

    TrayApp

    Trusteer Endpoint Protection

    Update Installer for WildTangent Games App

    Vacation Questâ„¢ - Australia

    Visual Studio 2010 x64 Redistributables

    WebReg

    WildTangent Games

    WildTangent Games App

    Windows Live Communications Platform

    Windows Live Essentials

    Windows Live Installer

    Windows Live Language Selector

    Windows Live Movie Maker

    Windows Live Photo Common

    Windows Live Photo Gallery

    Windows Live PIMT Platform

    Windows Live SOXE

    Windows Live SOXE Definitions

    Windows Live UX Platform

    Windows Live UX Platform Language Pack

    Windows Live Writer

    Windows Live Writer Resources

    Zuma's Revenge

    .

    ==== Event Viewer Messages From Past Week ========

    .

    10/27/2013 8:22:00 PM, Error: Service Control Manager [7034]  - The AVG WatchDog service terminated unexpectedly.  It has done this 1 time(s).

    10/27/2013 8:21:09 PM, Error: Service Control Manager [7024]  - 

    10/27/2013 8:05:17 PM, Error: Service Control Manager [7022]  - The AVG WatchDog service hung on starting.

    .

    ==== End Of File ===========================
  16. DDS (Ver_2012-11-20.01) - NTFS_AMD64 

    Internet Explorer: 10.0.9200.16537

    Run by Dave at 21:03:04 on 2013-10-27

    Microsoft Windows 8  6.2.9200.0.1252.1.1033.18.3682.2372 [GMT -6:00]

    .

    AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}

    AV: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}

    .

    ============== Running Processes ===============

    .

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe

    C:\Windows\system32\dwm.exe

    C:\Windows\system32\atiesrxx.exe

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\atieclxx.exe

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Program Files\IDT\WDM\STacSV64.exe

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

    C:\Windows\system32\svchost.exe -k apphost

    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

    C:\Windows\system32\dashost.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Windows\System32\svchost.exe -k HPZ12

    C:\Windows\System32\svchost.exe -k HPZ12

    C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

    C:\Windows\system32\svchost.exe -k imgsvc

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe

    C:\Windows\system32\taskhostex.exe

    c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe

    C:\Windows\Explorer.EXE

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe

    C:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe

    C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe

    C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe

    C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Windows\system32\svchost.exe -k HPService

    C:\Windows\system32\SearchIndexer.exe

    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE

    C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe

    C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

    C:\Windows\System32\RuntimeBroker.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

    C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    C:\Windows\system32\svchost.exe -k SDRSVC

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\svchost.exe -k defragsvc

    C:\Windows\system32\SearchProtocolHost.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Windows\System32\cscript.exe

    .

    ============== Pseudo HJT Report ===============

    .


    mWinlogon: Userinit = userinit.exe,

    BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll

    BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll

    BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll

    uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

    uRun: [sanDiskSecureAccess_Manager.exe] C:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe

    mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

    mRun: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R

    mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"

    mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY

    mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot

    dRun: [searchProtect] \SearchProtect\bin\cltmng.exe

    StartupFolder: C:\Users\Dave\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ATHOME~1.LNK - C:\Program Files (x86)\AtHomeConnect\AtHomeConnect.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE

    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000

    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe

    TCP: NameServer = 67.215.21.202 72.21.70.3

    TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06} : DHCPNameServer = 67.215.21.202 72.21.70.3

    TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}\375707562783 : DHCPNameServer = 68.87.77.130 68.87.72.130

    TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}\44166796466214C6F6E69716 : DHCPNameServer = 69.145.248.4 69.146.17.2 69.144.49.29

    TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}\C696E6B6379737 : DHCPNameServer = 67.215.21.202 72.21.70.3

    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL

    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    SSODL: WebCheck - <orphaned>

    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

    mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings

    x64-Run: [synTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe

    x64-Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe

    x64-Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - <orphaned>

    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

    x64-SSODL: WebCheck - <orphaned>

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 amd_sata;amd_sata;C:\Windows\System32\Drivers\amd_sata.sys [2012-7-23 79528]

    R0 amd_xata;amd_xata;C:\Windows\System32\Drivers\amd_xata.sys [2012-7-23 26280]

    R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\Drivers\avgidsha.sys [2013-7-20 71480]

    R0 Avgloga;AVG Logging Driver;C:\Windows\System32\Drivers\avgloga.sys [2013-7-20 311608]

    R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\Drivers\avgmfx64.sys [2013-7-1 116536]

    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\Drivers\avgrkx64.sys [2013-7-10 45880]

    R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\Drivers\avgidsdrivera.sys [2013-7-20 246072]

    R1 Avgwfpa;AVG Firewall Driver;C:\Windows\System32\Drivers\avgwfpa.sys [2013-7-9 248632]

    R1 CLVirtualDrive;CLVirtualDrive;C:\Windows\System32\Drivers\CLVirtualDrive.sys [2012-9-15 92536]

    R1 RapportCerberus_56758;RapportCerberus_56758;C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [2013-8-21 589872]

    R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-9-10 265872]

    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-8-2 239616]

    R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]

    R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-8-10 85504]

    R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-7-9 35232]

    R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-9-15 2451456]

    R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe [2009-8-5 284016]

    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-10-26 418376]

    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-10-26 701512]

    R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-9-10 1435928]

    R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-8-14 39056]

    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-10-26 25928]

    R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2013-4-15 2482960]

    R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\Drivers\RtsPStor.sys [2012-9-15 339600]

    R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-9-15 683664]

    R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\Drivers\usbfilter.sys [2012-9-15 57000]

    R3 WirelessButtonDriver;HP Wireless Button Driver Service;C:\Windows\System32\Drivers\WirelessButtonDriver64.sys [2012-8-3 20288]

    S0 Avgboota;AVG Early Launch Anti-Malware Driver;C:\Windows\System32\Drivers\avgboota.sys [2012-10-26 20912]

    S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\Drivers\avgldx64.sys [2013-7-20 206648]

    S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-7-4 4939312]

    S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-7-23 283136]

    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]

    S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]

    S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-2-5 235216]

    S3 RapportHades64;RapportHades64;C:\Windows\System32\Drivers\RapportHades64.sys [2012-12-26 266928]

    S3 RapportKE64;RapportKE64;C:\Windows\System32\Drivers\RapportKE64.sys [2012-12-26 295696]

    S3 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-9-10 384432]

    S3 SmbDrv;SmbDrv;C:\Windows\System32\Drivers\Smb_driver_AMDASF.sys [2012-9-15 41272]

    S3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2012-9-15 43832]

    .

    =============== File Associations ===============

    .

    FileExt: .txt: textfile="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1" [userChoice]

    .

    =============== Created Last 30 ================

    .

    2013-10-28 02:03:07 -------- d-----w- C:\Users\Dave\AppData\Local\Avg2013

    2013-10-27 05:07:30 -------- d-----w- C:\Users\Dave\AppData\Roaming\Malwarebytes

    2013-10-27 05:07:08 -------- d-----w- C:\ProgramData\Malwarebytes

    2013-10-27 05:07:04 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys

    2013-10-27 05:07:04 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

    2013-10-27 04:13:00 -------- d-----w- C:\Windows\ERUNT

    2013-10-27 04:05:45 -------- d-----w- C:\AdwCleaner

    2013-10-15 19:44:43 78296 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    2013-10-15 19:44:43 694232 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

    2013-10-13 03:39:54 1374208 ----a-w- C:\Windows\System32\wdc.dll

    2013-10-13 03:39:53 566784 ----a-w- C:\Windows\System32\wvc.dll

    2013-10-13 03:39:45 1245696 ----a-w- C:\Windows\SysWow64\wdc.dll

    2013-10-13 03:39:44 462336 ----a-w- C:\Windows\System32\sysmon.ocx

    2013-10-13 03:39:42 399360 ----a-w- C:\Windows\SysWow64\sysmon.ocx

    2013-10-13 03:39:41 437248 ----a-w- C:\Windows\SysWow64\wvc.dll

    2013-10-13 03:36:01 10116608 ----a-w- C:\Windows\System32\twinui.dll

    2013-10-10 21:53:07 652288 ----a-w- C:\Windows\System32\comctl32.dll

    2013-10-10 21:53:07 541696 ----a-w- C:\Windows\SysWow64\comctl32.dll

    2013-10-10 21:53:02 534528 ----a-w- C:\Windows\SysWow64\uxtheme.dll

    2013-10-10 21:53:02 44032 ----a-w- C:\Windows\SysWow64\UXInit.dll

    2013-10-10 21:53:01 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll

    2013-10-10 21:53:01 2706432 ----a-w- C:\Windows\System32\mshtml.tlb

    2013-10-10 21:51:05 3959296 ----a-w- C:\Windows\System32\jscript9.dll

    2013-10-10 21:51:01 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll

    2013-10-10 21:50:58 108032 ----a-w- C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll

    2013-10-08 01:19:07 -------- d-----w- C:\Users\Dave\AppData\Local\Programs

    2013-10-08 01:18:15 -------- d-----w- C:\Users\Dave\AppData\Local\WordOv

    2013-10-08 01:18:13 -------- d-----w- C:\Users\Dave\AppData\Roaming\RealNetworks

    2013-10-08 01:16:56 -------- d-----w- C:\Program Files (x86)\RealNetworks

    2013-10-08 01:16:45 -------- d-----w- C:\ProgramData\RealNetworks

    2013-10-08 01:14:47 -------- d-----w- C:\Program Files (x86)\Common Files\xing shared

    2013-10-04 19:17:05 -------- d-----w- C:\Program Files\iPod

    2013-10-04 19:17:04 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

    2013-10-04 19:17:04 -------- d-----w- C:\Program Files\iTunes

    2013-10-04 19:17:04 -------- d-----w- C:\Program Files (x86)\iTunes

    .

    ==================== Find3M  ====================

    .

    2013-10-08 01:13:30 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll

    2013-10-08 01:13:30 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll

    2013-10-02 02:57:03 46368 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys

    2013-09-22 23:28:06 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll

    2013-09-22 22:55:10 2241024 ----a-w- C:\Windows\System32\wininet.dll

    2013-09-11 05:18:30 266928 ----a-w- C:\Windows\System32\drivers\RapportHades64.sys

    2013-09-11 05:18:28 295696 ----a-w- C:\Windows\System32\drivers\RapportKE64.sys

    2013-08-23 05:11:57 4040192 ----a-w- C:\Windows\System32\win32k.sys

    2013-08-16 05:41:13 58200 ----a-w- C:\Windows\System32\drivers\dam.sys

    2013-08-16 05:39:26 2371728 ----a-w- C:\Windows\System32\WSService.dll

    2013-08-16 05:32:48 209200 ----a-w- C:\Windows\System32\NotificationUI.exe

    2013-08-16 05:22:22 40448 ----a-w- C:\Windows\System32\wuapp.exe

    2013-08-16 05:22:11 4917760 ----a-w- C:\Windows\System32\sppsvc.exe

    2013-08-16 05:20:30 105984 ----a-w- C:\Windows\System32\WinSetupUI.dll

    2013-08-15 22:43:21 35328 ----a-w- C:\Windows\SysWow64\wuapp.exe

    2013-08-15 22:43:07 84992 ----a-w- C:\Windows\SysWow64\wudriver.dll

    2013-08-15 22:43:07 126976 ----a-w- C:\Windows\SysWow64\wuwebv.dll

    2013-08-15 22:43:03 562688 ----a-w- C:\Windows\SysWow64\WSShared.dll

    2013-08-15 22:43:03 159232 ----a-w- C:\Windows\SysWow64\WSSync.dll

    2013-08-15 22:43:02 83968 ----a-w- C:\Windows\SysWow64\OEMLicense.dll

    2013-08-15 22:43:02 167424 ----a-w- C:\Windows\SysWow64\WSClient.dll

    2013-08-15 22:43:02 143872 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll

    2013-08-15 22:43:02 124928 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll

    2013-08-15 22:42:52 76800 ----a-w- C:\Windows\SysWow64\setupcln.dll

    2013-08-15 22:42:47 91648 ----a-w- C:\Windows\SysWow64\sppc.dll

    2013-08-10 05:21:51 448512 ----a-w- C:\Windows\System32\SettingSync.dll

    2013-08-10 05:21:51 128512 ----a-w- C:\Windows\System32\SettingSyncInfo.dll

    2013-08-10 03:58:51 356352 ----a-w- C:\Windows\SysWow64\SettingSync.dll

    2013-08-07 05:15:02 144896 ----a-w- C:\Windows\System32\tssdisai.dll

    2013-08-02 06:26:53 2304512 ----a-w- C:\Windows\System32\authui.dll

    2013-08-02 05:08:18 8858112 ----a-w- C:\Windows\SysWow64\twinui.dll

    2013-08-02 05:06:50 2035712 ----a-w- C:\Windows\SysWow64\authui.dll

    2013-08-01 10:41:31 2233688 ----a-w- C:\Windows\System32\drivers\tcpip.sys

    .

    ============= FINISH: 21:04:25.81 ===============
  17.  Results of screen317's Security Check version 0.99.74  

       x64 (UAC is enabled)  

     Internet Explorer 10  

    ``````````````Antivirus/Firewall Check:`````````````` 

     Windows Firewall Enabled!  

    AVG AntiVirus Free Edition 2013   

    Windows Defender                  

     Antivirus up to date!  (On Access scanning disabled!) 

    `````````Anti-malware/Other Utilities Check:````````` 

     Malwarebytes Anti-Malware version 1.75.0.1300  

     Adobe Flash Player 11.9.900.117  

     Adobe Reader XI  

     Google Chrome 30.0.1599.101  

     Google Chrome 30.0.1599.69  

    ````````Process Check: objlist.exe by Laurent````````  

     Malwarebytes Anti-Malware mbamservice.exe  

     Malwarebytes Anti-Malware mbamgui.exe  

     Malwarebytes' Anti-Malware mbamscheduler.exe   

    `````````````````System Health check````````````````` 

     Total Fragmentation on Drive C:  % 

    ````````````````````End of Log`````````````````````` 
  18. alwarebytes Anti-Malware (Trial) 1.75.0.1300

    www.malwarebytes.org

     

    Database version: v2013.10.27.01

     

    Windows 8 x64 NTFS

    Internet Explorer 10.0.9200.16721

    Dave :: LAPTOP [administrator]

     

    Protection: Enabled

     

    10/27/2013 8:06:08 PM

    mbam-log-2013-10-27 (20-06-08).txt

     

    Scan type: Quick scan

    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

    Scan options disabled: P2P

    Objects scanned: 226101

    Time elapsed: 11 minute(s), 40 second(s)

     

    Memory Processes Detected: 0

    (No malicious items detected)

     

    Memory Modules Detected: 0

    (No malicious items detected)

     

    Registry Keys Detected: 0

    (No malicious items detected)

     

    Registry Values Detected: 0

    (No malicious items detected)

     

    Registry Data Items Detected: 0

    (No malicious items detected)

     

    Folders Detected: 0

    (No malicious items detected)

     

    Files Detected: 0

    (No malicious items detected)

     

    (end)