davew3232
-
Content Count
32 -
Joined
-
Last visited
Content Type
Profiles
Forums
Calendar
Posts posted by davew3232
-
-
Chuck it is taking forever to open pages but once I get on it runs fine I dont have the pop up but getting the web sites to open is way slow
-
All processes killed========== OTL ==========HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66}\ not found.Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\SEARCH\view folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\SEARCH folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\PRICE_GONG folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\NOTIFICATION\images folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa\NOTIFICATION folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\wa folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\options\js folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al\options folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb\al folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content\tb folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875\content folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome\CT3311875 folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\chrome folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea} folder moved successfully.C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions folder moved successfully.Folder C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}\ not found.Registry value HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Run\\TWC.Win7 deleted successfully.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.File Protocol\Handler\msdaipp - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap\ deleted successfully.File Protocol\Handler\mso-offdap - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.File Protocol\Handler\skype4com - No CLSID value found not found.64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.========== COMMANDS ==========[EMPTYJAVA]User: AdministratorUser: All UsersUser: Dave->Java cache emptied: 8196 bytesUser: DefaultUser: Default UserUser: Default.migratedUser: GuestUser: HomeGroupUser$User: PublicUser: TEMPUser: TEMP.LaptopTotal Java Files Cleaned = 0.00 mb[EMPTYFLASH]User: AdministratorUser: All UsersUser: Dave->Flash cache emptied: 57768 bytesUser: Default->Flash cache emptied: 57472 bytesUser: Default User->Flash cache emptied: 0 bytesUser: Default.migratedUser: GuestUser: HomeGroupUser$User: PublicUser: TEMPUser: TEMP.LaptopTotal Flash Files Cleaned = 0.00 mb[EMPTYTEMP]User: AdministratorUser: All UsersUser: Dave->Temp folder emptied: 7309879 bytes->Temporary Internet Files folder emptied: 19222113 bytes->Java cache emptied: 0 bytes->FireFox cache emptied: 0 bytes->Google Chrome cache emptied: 205966422 bytes->Flash cache emptied: 0 bytesUser: Default->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes->Flash cache emptied: 0 bytesUser: Default User->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes->Flash cache emptied: 0 bytesUser: Default.migratedUser: GuestUser: HomeGroupUser$User: PublicUser: TEMP->Temp folder emptied: 0 bytes->FireFox cache emptied: 0 bytes->Google Chrome cache emptied: 0 bytesUser: TEMP.Laptop%systemdrive% .tmp files removed: 0 bytes%systemroot% .tmp files removed: 0 bytes%systemroot%\System32 .tmp files removed: 0 bytes%systemroot%\System32 (64bit) .tmp files removed: 0 bytes%systemroot%\System32\drivers .tmp files removed: 0 bytesWindows Temp folder emptied: 54550 bytes%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytesRecycleBin emptied: 23406152 bytesTotal Files Cleaned = 244.00 mbC:\WINDOWS\System32\drivers\etc\Hosts moved successfully.HOSTS file reset successfullyRestore point Set: OTL Restore PointOTL by OldTimer - Version 3.2.69.0 log created on 11122014_185847Files\Folders moved on Reboot...C:\Users\Dave\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll moved successfully.C:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.PendingFileRenameOperations files...Registry entries deleted on Reboot...
-
Results of screen317's Security Check version 0.99.89x64 (UAC is enabled)Internet Explorer 11``````````````Antivirus/Firewall Check:``````````````Windows Firewall Enabled!Windows DefenderWMI entry may not exist for antivirus; attempting automatic update.`````````Anti-malware/Other Utilities Check:`````````Java 7 Update 71Java version out of Date!Adobe Flash Player 15.0.0.223Adobe Reader XIGoogle Chrome 35.0.1916.153Google Chrome 36.0.1985.125````````Process Check: objlist.exe by Laurent````````Windows Defender MSMpEng.exeMalwarebytes Anti-Malware mbamservice.exeMalwarebytes Anti-Malware mbam.exeMalwarebytes Anti-Malware mbamscheduler.exe`````````````````System Health check`````````````````Total Fragmentation on Drive C: %````````````````````End of Log``````````````````````
-
OTL Extras logfile created on: 11/11/2014 9:08:19 PM - Run 2OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dave\Desktop64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstationInternet Explorer (Version = 9.11.9600.17351)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy3.60 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 63.30% Memory free4.47 Gb Paging File | 3.10 Gb Available in Paging File | 69.22% Paging File freePaging file location(s): ?:\pagefile.sys [binary data]%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)Drive C: | 275.65 Gb Total Space | 217.72 Gb Free Space | 78.98% Space Free | Partition Type: NTFSDrive D: | 21.33 Gb Total Space | 2.57 Gb Free Space | 12.07% Space Free | Partition Type: NTFSComputer Name: LAPTOP | User Name: Dave | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All users | Include 64bit ScansCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days========== Extra Registry (SafeList) ==================== File Associations ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation).url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation).html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)========== Shell Spawning ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*exefile [open] -- "%1" %*helpfile [open] -- Reg Error: Key error.htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [explore] -- Reg Error: Value error.Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)exefile [open] -- "%1" %*helpfile [open] -- Reg Error: Key error.htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [explore] -- Reg Error: Value error.Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.========== Security Center Settings ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"cval" = 164bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]"VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data]"AntiVirusOverride" = 0"AntiSpywareOverride" = 0"FirewallOverride" = 064bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]"UpgradeTime" = Reg Error: Unknown registry data type -- File not found========== Firewall Settings ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]"EnableFirewall" = 1"DisableNotifications" = 0[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall" = 1"DisableNotifications" = 0[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]"EnableFirewall" = 1"DisableNotifications" = 0========== Authorized Applications List ==================== Vista Active Open Ports Exception List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]========== Vista Active Application Exception List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]"{1E8FACDA-593C-4192-8D9D-F9C62B219530}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |"{A0029681-0493-44F1-8AFF-5CA50BA15905}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |"{C2BBED50-011B-40BD-820B-37F8BA448099}" = dir=out | name=ebay |========== HKEY_LOCAL_MACHINE Uninstall List ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt"{0FA995CC-C849-4755-B14B-5404CC75DC24}" = Energy Star"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219"{21E47F47-C9A7-4454-BA48-388327B0EA00}" = RealNetworks - Microsoft Visual C++ 2010 Runtime"{23D2AFC7-C01E-4413-9D9A-0BABF52569BF}" = Microsoft Mouse and Keyboard Center"{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}" = iTunes"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161"{6096C0CC-7E19-4355-87F0-627EC5AA146D}" = iCloud"{63ADEC24-A374-80A8-E89B-BE401C787F75}" = AMD Catalyst Install Manager"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64"{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting"{A79A9231-0A5A-9384-21D0-DB753C2BE59B}" = AMD Fuel"{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}" = Apple Mobile Device Support"{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}" = HP Registration Service"{E82EC5DF-28FD-C8F4-ED08-B88728158260}" = ccc-utility64"{F089B734-1356-484F-A7B8-1B78F1616A15}" = HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer"AVG" = AVG 2013"HP Imaging Device Functions" = HP Imaging Device Functions 14.0"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0"HPExtendedCapabilities" = HP Customer Participation Program 14.0"HPOCR" = OCR Software by I.R.I.S. 14.0"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)"SynTPDeinstKey" = Synaptics TouchPad Driver[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{0123AB93-E7A4-7F40-83B6-41EC2CF84B3F}" = CCC Help Dutch"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer"{0C3B99D2-35D0-6993-3C4B-A759419A8678}" = CCC Help Korean"{0C57987A-A03A-4B95-A309-D23F78F406CA}" = HP Utility Center"{0DCCD5F4-29E7-4AA0-8C1D-F8E1503B91F4}" = Catalyst Control Center - Branding"{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP"{1225C0F8-AB1A-BE3A-CD0C-DB8CA1613940}" = CCC Help Greek"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant"{167158CE-1637-4167-8A1C-C2549EEA966A}" = The Weather Channel App"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148"{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer"{26A24AE4-039D-4CA4-87B4-2F03217071FF}" = Java 7 Update 71"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox"{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery"{3C41A693-28E1-4335-A738-528B09DB600C}" = CCC Help Thai"{3C458872-A5BB-89F3-933C-2406F6D9E6F8}" = CCC Help Finnish"{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}" = QuickTime 7"{4734A746-A503-4B8E-A4FA-7B7C84A18D79}" = US Tech Support Framework"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skypeâ„¢ 6.11"{4ED7050C-9332-4FB2-AB07-E94F25A53D39}" = HP Quick Launch"{528AB81B-D65A-4AB0-A2B6-82B51A087D01}" = HP Recovery Manager"{52A3FC19-6F84-F293-08C6-80A1D2F7477F}" = CCC Help Swedish"{56BA241F-580C-43D2-8403-947241AAE633}" = center"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack"{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status"{5CD2FE1D-A3DB-F273-2798-EFAACF8492A5}" = CCC Help Portuguese"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM"{631EFC00-5A7A-4A90-9578-039EDA92DE0F}_is1" = HRBlockDirect version 1.1.2.0"{675D093B-815D-47FD-AB2C-192EC751E8E2}" = HP Software Framework"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE"{6A66D912-541C-54C6-43E6-17AF24700B91}" = CCC Help German"{6AAEB4CB-0573-41ec-89B0-0FE0D5134A8B}_is1" = MyCleanPC PC Optimizer"{6C8FF546-B0C0-0935-2F5E-7DC2DA727CFD}" = CCC Help Czech"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.2.3"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable"{734846E6-3E7A-04AC-0612-638A1D8A63F8}" = CCC Help Russian"{747F3993-036E-5F4F-1B82-7DA844B73966}" = Catalyst Control Center Localization All"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update"{793ED091-3F14-4968-3864-5C8A7727A5DA}" = CCC Help Chinese Standard"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform"{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}" = Apple Application Support"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver"{89D20029-0578-4D8D-979A-695C8D868868}" = H&R Block Deluxe + Efile 2012"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390R 802.11bgn Wi-Fi Adapter"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional"{9285EABA-D88C-4A8A-6E9D-5F55BF03E46F}" = Catalyst Control Center InstallProxy"{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker"{93EB60BA-458D-FBE6-E466-CD170080E719}" = CCC Help Polish"{941DE69D-6CEE-4171-8F1F-3D7E352AA498}" = HP Wireless Button Driver"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161"{9C0F4CBD-8543-96CC-46F1-75E57B1B22A6}" = Catalyst Control Center Graphics Previews Common"{9C35EDE5-4B0F-45E7-A438-314BA889948E}" = HP MyRoom"{9E50DEC9-081B-441F-B647-98DBEA8B01DD}" = CorelDRAW 10"{9EF69B68-6DFE-F916-2D6E-E486D21A26C2}" = CCC Help Spanish"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.09)"{AD9F55C5-93F8-4CAB-A311-77C195912CA4}" = H&R Block Deluxe + Efile 2013"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update"{B1E7FE70-3B18-5BA2-8032-2547FC636A50}" = CCC Help Japanese"{B424890D-64FC-E0D1-4A17-4B512CA45CD9}" = CCC Help Italian"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2"{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations"{BE64A239-E22E-9D77-AA57-36AE0443EC2F}" = CCC Help Chinese Traditional"{C045ED98-5FDB-45A0-AB48-C4B7560E7816}" = C309a"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget"{CCCDD476-98F9-4B06-91DB-23F27CEC3BE1}" = HPDetect"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform"{CF8C33C1-C978-527D-E0AF-530882DEB146}" = AMD VISION Engine Control Center"{D23CA718-0356-41F2-8E6A-B5C6CD383EF7}" = HP Documentation"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform"{D5DC9541-12F0-59CF-9430-1136D5A58BD0}" = CCC Help Hungarian"{D7FBE7DC-A18F-4DFF-80BB-A478E4E09CF7}" = CCC Help Danish"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq"{DC3C5C4A-1869-A99C-3AE4-55E0191105F0}" = CCC Help Norwegian"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources"{DE431304-8040-43D4-8419-A58E210A3894}" = RealDownloader"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center"{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}" = HP Support Assistant"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio"{E3AE96D6-E196-45B4-AF62-2B41998B9E37}" = UpdateService"{EB2CDF95-92D4-AC57-63B1-4E7F0BD8F9B8}" = CCC Help French"{ECA42F46-D80E-AD40-18FB-4BF64491CEE3}" = CCC Help English"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219"{FA0E7183-6B11-4899-B25F-2C490543967E}" = PS_AIO_05_C309_Software_Min"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials"{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr"{FF282A38-D10B-E302-FBAD-5903C9DD9A5B}" = CCC Help Turkish"Adobe AIR" = Adobe AIR"Adobe Flash Player Plugin" = Adobe Flash Player 15 Plugin"Adobe Shockwave Player" = Adobe Shockwave Player 11.6"CorelDRAW 10" = CorelDRAW 10"Google Chrome" = Google Chrome"HP Photo Creations" = HP Photo Creations"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam"InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10"InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.3.1025"Paltalk Messenger" ="Pdf995" = Pdf995 (installed by H&R Block)"PdfEdit995" = PdfEdit995 (installed by H&R Block)"PrintProjects" = PrintProjects"Rapport_msi" = Trusteer Endpoint Protection"RealPlayer 17.0" = RealPlayer Cloud"WildTangent hp Master Uninstall" = HP Games"WinLiveSuite" = Windows Live Essentials========== HKEY_USERS Uninstall List ==========[HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe" = SanDiskSecureAccess_Manager.exe"Dropbox" = Dropbox"OneDriveSetup.exe" = Microsoft OneDrive========== Last 20 Event Log Errors ==========[ Application Events ]Error - 11/10/2014 11:23:22 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002Description = The program backgroundTaskHost.exe version 6.3.9600.16384 stoppedinteracting with Windows and was closed. To see if more information about the problemis available, check the problem history in the Action Center control panel. ProcessID: c4 Start Time: 01cffd5e0d1808f7 Termination Time: 4294967295 Application Path:C:\WINDOWS\system32\backgroundTaskHost.exe Report Id: 00d45714-6952-11e4-bf3d-c8cbb8b06c44Faultingpackage full name: 53987RBL3.FinanceHelper_1.1.0.73_neutral__z2nrd37h46pd8 Faultingpackage-relative application ID: AppError - 11/10/2014 11:28:20 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002Description = The program wwahost.exe version 6.3.9600.17031 stopped interactingwith Windows and was closed. To see if more information about the problem is available,check the problem history in the Action Center control panel. Process ID: 14f8 StartTime: 01cffd5e0d10df01 Termination Time: 4294967295 Application Path: C:\WINDOWS\system32\wwahost.exeReportId: 00cf954a-6952-11e4-bf3d-c8cbb8b06c44 Faulting package full name: AD2F1837.HPConnectedPhotopoweredbySnapfish_2.5.6.4614_neutral__v10z8vjag6ke6Faultingpackage-relative application ID: AppError - 11/11/2014 10:48:39 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002Description = The program LiveComm.exe version 17.5.9600.20605 stopped interactingwith Windows and was closed. To see if more information about the problem is available,check the problem history in the Action Center control panel. Process ID: 300 StartTime: 01cffe21b9838d0e Termination Time: 4294967295 Application Path: C:\ProgramFiles\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exeReportId: 60fea05d-6a16-11e4-bf3d-c8cbb8b06c44 Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbweFaultingpackage-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1Error - 11/11/2014 11:33:03 PM | Computer Name = Laptop | Source = Application Hang | ID = 1002Description = The program LiveComm.exe version 17.5.9600.20605 stopped interactingwith Windows and was closed. To see if more information about the problem is available,check the problem history in the Action Center control panel. Process ID: 1b04 StartTime: 01cffe28a53756a5 Termination Time: 4294967295 Application Path: C:\ProgramFiles\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exeReportId: 99e99d85-6a1c-11e4-bf3d-c8cbb8b06c44 Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbweFaultingpackage-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1[ System Events ]Error - 11/10/2014 12:17:24 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7009Description = A timeout was reached (30000 milliseconds) while waiting for the KodakAiO Network Discovery Service service to connect.Error - 11/10/2014 12:17:24 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000Description = The Kodak AiO Network Discovery Service service failed to start dueto the following error: %%1053Error - 11/10/2014 12:19:34 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000Description = The Google Update Service (gupdate) service failed to start due tothe following error: %%2Error - 11/12/2014 12:04:15 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7009Description = A timeout was reached (30000 milliseconds) while waiting for the KodakAiO Network Discovery Service service to connect.Error - 11/12/2014 12:04:15 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000Description = The Kodak AiO Network Discovery Service service failed to start dueto the following error: %%1053Error - 11/12/2014 12:06:48 AM | Computer Name = Laptop | Source = Service Control Manager | ID = 7000Description = The Google Update Service (gupdate) service failed to start due tothe following error: %%2< End of report >
-
OTL logfile created on: 11/11/2014 9:08:19 PM - Run 2OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dave\Desktop64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstationInternet Explorer (Version = 9.11.9600.17351)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy3.60 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 63.30% Memory free4.47 Gb Paging File | 3.10 Gb Available in Paging File | 69.22% Paging File freePaging file location(s): ?:\pagefile.sys [binary data]%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)Drive C: | 275.65 Gb Total Space | 217.72 Gb Free Space | 78.98% Space Free | Partition Type: NTFSDrive D: | 21.33 Gb Total Space | 2.57 Gb Free Space | 12.07% Space Free | Partition Type: NTFSComputer Name: LAPTOP | User Name: Dave | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All users | Include 64bit ScansCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days========== Processes (SafeList) ==========PRC - [2014/11/10 20:36:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Desktop\OTL.comPRC - [2014/10/13 17:02:32 | 002,607,384 | ---- | M] (IBM Corp.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exePRC - [2014/10/13 17:02:32 | 001,919,256 | ---- | M] (IBM Corp.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exePRC - [2014/10/01 11:09:30 | 000,968,504 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exePRC - [2014/10/01 11:09:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exePRC - [2014/10/01 11:09:20 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exePRC - [2014/09/12 02:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exePRC - [2014/04/05 14:43:08 | 001,141,848 | ---- | M] (RealNetworks, Inc.) -- c:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exePRC - [2014/03/20 20:13:30 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exePRC - [2014/03/15 02:18:20 | 000,039,568 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exePRC - [2012/10/12 14:16:50 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exePRC - [2012/07/09 13:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exePRC - [2012/06/07 20:34:06 | 000,111,120 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe========== Modules (No Company Name) ==========MOD - [2014/03/23 16:04:20 | 000,557,056 | ---- | M] () -- C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dllMOD - [2012/06/08 11:34:06 | 000,016,400 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dllMOD - [2012/06/07 20:34:06 | 000,627,216 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll========== Services (SafeList) ==========SRV:64bit: - [2014/09/10 05:41:00 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)SRV:64bit: - [2014/08/15 20:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)SRV:64bit: - [2014/08/15 17:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)SRV:64bit: - [2014/08/15 17:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)SRV:64bit: - [2014/07/24 00:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)SRV:64bit: - [2014/04/06 04:20:36 | 000,201,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)SRV:64bit: - [2014/03/23 19:31:14 | 000,347,880 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)SRV:64bit: - [2014/03/23 19:31:14 | 000,023,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)SRV:64bit: - [2014/03/13 23:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)SRV:64bit: - [2014/03/07 22:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)SRV:64bit: - [2014/03/06 00:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)SRV:64bit: - [2014/02/22 08:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\WSService.dll -- (WSService)SRV:64bit: - [2014/02/22 02:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)SRV:64bit: - [2014/02/22 02:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)SRV:64bit: - [2014/02/22 02:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)SRV:64bit: - [2014/02/22 02:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)SRV:64bit: - [2014/01/22 01:27:09 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc)SRV:64bit: - [2013/12/13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)SRV:64bit: - [2013/12/10 00:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)SRV:64bit: - [2013/08/22 04:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)SRV:64bit: - [2013/08/22 04:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)SRV:64bit: - [2013/08/22 04:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)SRV:64bit: - [2013/08/22 04:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)SRV:64bit: - [2013/08/22 04:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)SRV:64bit: - [2013/08/22 03:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)SRV:64bit: - [2013/08/22 03:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)SRV:64bit: - [2013/08/22 03:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)SRV:64bit: - [2013/08/22 02:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)SRV:64bit: - [2013/08/22 02:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)SRV:64bit: - [2013/08/22 02:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)SRV:64bit: - [2013/08/22 02:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)SRV:64bit: - [2013/08/22 02:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)SRV:64bit: - [2013/08/22 02:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)SRV:64bit: - [2013/08/22 02:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)SRV:64bit: - [2013/08/22 02:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)SRV:64bit: - [2013/05/29 19:47:42 | 000,322,048 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)SRV:64bit: - [2012/08/06 12:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)SRV - [2014/11/11 20:15:36 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)SRV - [2014/10/13 17:02:32 | 001,919,256 | ---- | M] (IBM Corp.) [Auto | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)SRV - [2014/10/01 11:09:30 | 000,968,504 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)SRV - [2014/10/01 11:09:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)SRV - [2014/09/12 02:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)SRV - [2014/08/15 20:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)SRV - [2014/04/05 14:43:08 | 001,141,848 | ---- | M] (RealNetworks, Inc.) [Auto | Running] -- c:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe -- (RealPlayer Cloud Service)SRV - [2014/03/20 20:13:30 | 000,023,552 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe -- (RealPlayerUpdateSvc)SRV - [2014/03/15 02:18:20 | 000,039,568 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)SRV - [2014/03/13 23:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)SRV - [2014/01/22 01:27:11 | 000,475,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)SRV - [2014/01/22 01:27:08 | 000,066,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)SRV - [2014/01/22 01:27:07 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)SRV - [2013/11/04 18:31:56 | 000,092,160 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)SRV - [2013/08/21 20:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)SRV - [2013/08/21 19:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)SRV - [2012/07/13 18:02:16 | 002,451,456 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)SRV - [2012/07/09 13:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)SRV - [2011/08/18 00:29:52 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)SRV - [2009/08/05 12:49:44 | 000,284,016 | ---- | M] (Eastman Kodak Company) [Auto | Stopped] -- C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe -- (Kodak AiO Network Discovery Service)========== Driver Services (SafeList) ==========DRV:64bit: - [2014/11/11 21:05:35 | 000,129,752 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)DRV:64bit: - [2014/10/13 17:02:42 | 000,534,104 | ---- | M] (IBM Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RapportKE64.sys -- (RapportKE64)DRV:64bit: - [2014/10/13 17:02:42 | 000,289,656 | ---- | M] (IBM Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RapportHades64.sys -- (RapportHades64)DRV:64bit: - [2014/10/01 11:11:26 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)DRV:64bit: - [2014/10/01 11:11:12 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)DRV:64bit: - [2014/08/14 17:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)DRV:64bit: - [2014/07/24 08:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)DRV:64bit: - [2014/07/24 08:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)DRV:64bit: - [2014/07/24 04:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)DRV:64bit: - [2014/05/01 06:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)DRV:64bit: - [2014/03/23 19:30:57 | 000,257,880 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)DRV:64bit: - [2014/03/23 19:30:57 | 000,123,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)DRV:64bit: - [2014/03/23 19:27:03 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)DRV:64bit: - [2014/03/19 20:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)DRV:64bit: - [2014/03/19 14:23:14 | 000,050,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)DRV:64bit: - [2014/03/13 05:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)DRV:64bit: - [2014/03/08 13:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)DRV:64bit: - [2014/02/22 09:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)DRV:64bit: - [2014/02/22 08:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)DRV:64bit: - [2014/02/22 08:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)DRV:64bit: - [2014/02/22 08:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)DRV:64bit: - [2014/02/22 08:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)DRV:64bit: - [2014/02/22 05:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)DRV:64bit: - [2014/01/22 01:34:53 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)DRV:64bit: - [2014/01/22 01:34:52 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)DRV:64bit: - [2014/01/22 01:34:52 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)DRV:64bit: - [2014/01/08 23:48:02 | 000,010,112 | ---- | M] (support.com, Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssmirrdr.sys -- (ssmirrdr)DRV:64bit: - [2014/01/07 08:02:04 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)DRV:64bit: - [2014/01/07 07:42:08 | 000,076,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)DRV:64bit: - [2013/12/13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)DRV:64bit: - [2013/12/13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)DRV:64bit: - [2013/12/02 17:32:18 | 002,483,376 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)DRV:64bit: - [2013/11/14 00:28:58 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)DRV:64bit: - [2013/11/14 00:25:25 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)DRV:64bit: - [2013/11/14 00:16:57 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)DRV:64bit: - [2013/11/14 00:16:54 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)DRV:64bit: - [2013/08/22 06:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)DRV:64bit: - [2013/08/22 06:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)DRV:64bit: - [2013/08/22 05:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)DRV:64bit: - [2013/08/22 05:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)DRV:64bit: - [2013/08/22 05:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)DRV:64bit: - [2013/08/22 05:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)DRV:64bit: - [2013/08/22 05:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)DRV:64bit: - [2013/08/22 05:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)DRV:64bit: - [2013/08/22 05:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)DRV:64bit: - [2013/08/22 05:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)DRV:64bit: - [2013/08/22 05:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)DRV:64bit: - [2013/08/22 05:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)DRV:64bit: - [2013/08/22 05:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)DRV:64bit: - [2013/08/22 05:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)DRV:64bit: - [2013/08/22 05:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)DRV:64bit: - [2013/08/22 05:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)DRV:64bit: - [2013/08/22 05:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)DRV:64bit: - [2013/08/22 05:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)DRV:64bit: - [2013/08/22 05:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)DRV:64bit: - [2013/08/22 05:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)DRV:64bit: - [2013/08/22 05:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)DRV:64bit: - [2013/08/22 05:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)DRV:64bit: - [2013/08/22 05:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)DRV:64bit: - [2013/08/22 05:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)DRV:64bit: - [2013/08/22 05:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)DRV:64bit: - [2013/08/22 05:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)DRV:64bit: - [2013/08/22 05:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)DRV:64bit: - [2013/08/22 05:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)DRV:64bit: - [2013/08/22 05:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)DRV:64bit: - [2013/08/22 04:39:58 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)DRV:64bit: - [2013/08/22 04:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)DRV:64bit: - [2013/08/22 04:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)DRV:64bit: - [2013/08/22 04:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)DRV:64bit: - [2013/08/22 04:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)DRV:64bit: - [2013/08/22 04:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)DRV:64bit: - [2013/08/22 04:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)DRV:64bit: - [2013/08/22 04:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)DRV:64bit: - [2013/08/22 04:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)DRV:64bit: - [2013/08/22 04:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)DRV:64bit: - [2013/08/22 04:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)DRV:64bit: - [2013/08/22 04:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)DRV:64bit: - [2013/08/22 04:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)DRV:64bit: - [2013/08/22 04:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)DRV:64bit: - [2013/08/22 04:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)DRV:64bit: - [2013/08/22 04:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)DRV:64bit: - [2013/08/22 04:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)DRV:64bit: - [2013/08/22 04:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)DRV:64bit: - [2013/08/22 04:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)DRV:64bit: - [2013/08/22 04:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)DRV:64bit: - [2013/08/22 04:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)DRV:64bit: - [2013/08/22 04:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)DRV:64bit: - [2013/08/22 03:27:46 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)DRV:64bit: - [2013/08/22 01:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)DRV:64bit: - [2013/08/12 16:25:46 | 000,017,624 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)DRV:64bit: - [2013/08/09 17:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)DRV:64bit: - [2013/07/30 11:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)DRV:64bit: - [2013/07/25 12:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)DRV:64bit: - [2013/05/29 19:47:43 | 000,542,208 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)DRV:64bit: - [2012/08/24 02:38:28 | 000,448,312 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)DRV:64bit: - [2012/08/24 02:38:28 | 000,043,832 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)DRV:64bit: - [2012/08/24 02:38:26 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv)DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)DRV:64bit: - [2012/08/03 14:07:30 | 000,020,288 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WirelessButtonDriver64.sys -- (WirelessButtonDriver)DRV:64bit: - [2012/07/23 14:35:12 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)DRV:64bit: - [2012/07/23 14:35:12 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)DRV:64bit: - [2012/07/04 11:41:58 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)DRV:64bit: - [2012/06/25 10:24:50 | 000,092,536 | ---- | M] (CyberLink) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\CLVirtualDrive.sys -- (CLVirtualDrive)DRV:64bit: - [2012/06/18 19:07:50 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)DRV:64bit: - [2012/06/12 22:41:22 | 000,683,664 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)DRV - [2014/10/13 17:02:42 | 000,557,656 | ---- | M] (IBM Corp.) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys -- (RapportPG64)DRV - [2014/10/13 17:02:42 | 000,445,880 | ---- | M] (IBM Corp.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys -- (RapportEI64)DRV - [2014/10/10 15:57:39 | 000,761,720 | ---- | M] () [Kernel | System | Running] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_80055.sys -- (RapportCerberus_80055)========== Standard Registry (SafeList) ==================== Internet Explorer ==========IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.comIE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.comIE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.comIE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.comIE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:14297;https=127.0.0.1:14297IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:14297;https=127.0.0.1:14297IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.comIE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" = http://www.google.com/search?q={searchTerms}IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:14081;https=127.0.0.1:14081========== FireFox ==========FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll File not foundFF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not foundFF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=17.0.8.22: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=17.0.8: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=17.0.8: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=17.0.8: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=17.0.8.22: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll File not foundFF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll File not foundFF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)FF - HKCU\Software\MozillaPlugins\hp.com/HPDetect: C:\Users\Dave\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014/04/05 14:46:48 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0FAA5C82-A094-4541-8811-D3361F972A81}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2014/04/05 14:46:48 | 000,000,000 | ---D | M][2013/10/08 20:54:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions[2014/11/09 18:21:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}========== Chrome ==========CHR - default_search_provider: (Enabled)CHR - default_search_provider: search_url =CHR - default_search_provider: suggest_url =CHR - homepage:CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dllCHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewerCHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dllCHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dllCHR - plugin: Norton Confidential (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.0.0.72_0\npcoplgn.dllCHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dllCHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dllCHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dllCHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Disabled) = c:\program files (x86)\real\realplayer\netscape6\nppl3260.dllCHR - plugin: RealPlayer Video Downloader for PepperFlash (32-bit) (Disabled) = c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dllCHR - plugin: RealPlayer Download Plugin (Disabled) = c:\program files (x86)\real\realplayer\netscape6\nprpplugin.dllCHR - plugin: RocketLife Secure Plug-In Layer (Disabled) = c:\programdata\visan\plugins\nprlsecurepluginlayer.dllCHR - Extension: Google Drive = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\CHR - Extension: YouTube = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\CHR - Extension: Google Search = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\CHR - Extension: Google Wallet = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\CHR - Extension: Gmail = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\O1 HOSTS File: ([2013/11/02 08:48:46 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\HostsO1 - Hosts: 127.0.0.1 localhostO1 - Hosts: ::1 localhostO2:64bit: - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)O4:64bit: - HKLM..\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)O4 - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002..\Run: [TWC.Win7] C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe File not foundO4:64bit: - HKLM..\RunOnce: [NCPluginUpdater] C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)O13 - gopher Prefix: missingO17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 72.21.70.3 67.215.21.202O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}: DhcpNameServer = 72.21.70.3 67.215.21.202O18:64bit: - Protocol\Handler\msdaipp - No CLSID value foundO18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value foundO18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value foundO18:64bit: - Protocol\Handler\mso-offdap - No CLSID value foundO18:64bit: - Protocol\Handler\skype4com - No CLSID value foundO18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O32 - HKLM CDRom: AutoRun - 1O33 - MountPoints2\{bb7712fa-a231-11e3-beeb-c8cbb8b06c44}\Shell - "" = AutoRunO33 - MountPoints2\{bb7712fa-a231-11e3-beeb-c8cbb8b06c44}\Shell\AutoRun\command - "" = "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL F:\TL-Bootstrap.exeO34 - HKLM BootExecute: (autocheck autochk *)O34 - HKLM BootExecute: (MACHINE BootExecut)O35:64bit: - HKLM\..comfile [open] -- "%1" %*O35:64bit: - HKLM\..exefile [open] -- "%1" %*O35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)========== Files/Folders - Created Within 30 Days ==========[2014/11/11 20:14:02 | 017,926,832 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerInstaller.exe[2014/11/11 19:42:34 | 000,000,000 | ---D | C] -- C:\FRST[2014/11/10 20:36:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Dave\Desktop\OTL.com[2014/11/09 20:16:53 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys[2014/11/09 20:15:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware[2014/11/09 20:14:53 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys[2014/11/09 20:14:52 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys[2014/11/09 20:14:52 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys[2014/11/09 20:14:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware[2014/11/09 19:04:25 | 000,000,000 | ---D | C] -- C:\AdwCleaner[2014/11/09 18:54:02 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN[2014/11/09 18:46:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp[2014/11/09 18:46:50 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Temp[2014/11/09 18:09:12 | 000,000,000 | ---D | C] -- C:\zoek[2014/11/09 16:58:26 | 000,000,000 | ---D | C] -- C:\zoek_backup[2014/11/02 08:53:26 | 000,272,808 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe[2014/11/02 08:52:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java[2014/11/02 08:52:27 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe[2014/11/02 08:52:27 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe[2014/11/02 08:52:27 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll[2014/11/02 08:51:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java[2014/10/24 18:28:36 | 000,000,000 | ---D | C] -- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7[2014/10/15 20:12:22 | 000,105,440 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl[2014/10/15 20:12:21 | 000,706,016 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe[2014/10/14 19:38:41 | 005,829,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll[2014/10/14 19:38:23 | 002,108,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl[2014/10/14 19:38:23 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll[2014/10/14 19:38:22 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl[2014/10/14 19:38:21 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe[2014/10/14 19:38:19 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll[2014/10/14 19:38:17 | 000,289,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll[2014/10/14 19:38:16 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll[2014/10/14 19:38:16 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll[2014/10/14 19:38:16 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll[2014/10/14 19:38:15 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll[2014/10/14 19:38:15 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll[2014/10/14 19:38:14 | 000,775,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll[2014/10/14 19:38:13 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll[2014/10/14 19:36:43 | 000,921,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll[2014/10/14 19:36:42 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll[2014/10/14 19:36:38 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll[2014/10/14 19:36:10 | 001,702,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll[2014/10/14 19:36:10 | 000,839,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll[2014/10/14 19:36:10 | 000,672,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll[2014/10/14 19:36:10 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll[2014/10/14 19:36:10 | 000,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe[2014/10/14 19:36:09 | 000,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll[2014/10/14 19:36:09 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll[2014/10/14 19:36:09 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll[2014/10/14 19:36:09 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll[2014/10/14 19:36:09 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll[2014/10/14 19:36:08 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll[2014/10/14 19:36:08 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe[2014/10/14 19:36:08 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe[2014/10/14 19:34:57 | 008,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll[2014/10/14 19:34:54 | 005,902,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll[2014/10/14 19:34:53 | 006,649,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll[2014/10/14 19:34:52 | 005,777,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll[2014/10/14 19:34:51 | 004,758,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll[2014/10/14 19:34:49 | 001,106,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll[2014/10/14 19:34:48 | 001,710,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll[2014/10/14 19:34:48 | 001,112,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll[2014/10/14 19:34:45 | 001,507,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll[2014/10/14 19:34:45 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll[2014/10/14 19:34:44 | 000,756,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll[2014/10/14 19:34:43 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll[2014/10/14 19:34:40 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll[2014/10/14 19:34:38 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe[2014/10/14 19:34:38 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll[2014/10/14 19:34:38 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll[2014/10/14 19:34:37 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS[2014/10/14 19:34:37 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll[2014/10/14 19:34:37 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll[2014/10/14 19:34:36 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll[2014/10/14 19:34:36 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll[2014/10/14 19:34:36 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll[2014/10/14 19:34:36 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll[2014/10/14 19:34:34 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll[2014/10/14 19:34:34 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll[2014/10/14 19:34:08 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll[2014/10/14 19:34:08 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll[2014/10/14 19:34:04 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll[2014/10/14 19:34:04 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll[2014/10/14 19:34:01 | 000,527,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll[2014/10/14 19:33:55 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll[2014/10/14 19:33:55 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll[2014/10/14 19:23:02 | 002,779,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll[2014/10/14 19:23:01 | 002,646,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll[2014/10/14 19:23:00 | 002,321,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll[1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]========== Files - Modified Within 30 Days ==========[2014/11/11 21:14:07 | 000,000,908 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job[2014/11/11 21:13:51 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job[2014/11/11 21:05:35 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys[2014/11/11 21:05:34 | 000,022,961 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141111210435[2014/11/11 21:04:03 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat[2014/11/11 21:03:57 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys[2014/11/11 21:03:53 | 3088,904,192 | -HS- | M] () -- C:\hiberfil.sys[2014/11/11 20:52:20 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\HP Photo Creations Communicator.job[2014/11/11 20:31:13 | 000,000,330 | ---- | M] () -- C:\WINDOWS\tasks\PrintProjects Communicator.job[2014/11/11 20:14:38 | 017,926,832 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerInstaller.exe[2014/11/11 19:39:17 | 000,124,421 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141110201537[2014/11/11 19:39:17 | 000,102,664 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141111193818[2014/11/10 20:38:54 | 000,854,448 | ---- | M] () -- C:\Users\Dave\Desktop\SecurityCheck.exe[2014/11/10 20:36:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Desktop\OTL.com[2014/11/10 20:16:35 | 000,033,834 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109211734[2014/11/09 20:15:39 | 000,001,078 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[2014/11/09 19:47:12 | 000,108,693 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109194611[2014/11/09 19:13:35 | 000,038,679 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109191234[2014/11/09 18:57:59 | 000,956,540 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI[2014/11/09 18:57:59 | 000,796,126 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat[2014/11/09 18:57:59 | 000,161,346 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat[2014/11/09 18:51:22 | 000,025,377 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109185022[2014/11/09 18:50:29 | 000,000,008 | RHS- | M] () -- C:\ProgramData\ntuser.pol[2014/11/09 16:58:23 | 000,024,064 | ---- | M] () -- C:\WINDOWS\zoek-delete.exe[2014/11/09 04:41:33 | 001,738,235 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141108044053[2014/11/09 04:41:33 | 001,023,708 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141109044052[2014/11/08 04:41:30 | 000,994,658 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141107145630[2014/11/07 16:59:10 | 000,000,342 | ---- | M] () -- C:\WINDOWS\tasks\HPCeeScheduleForDave.job[2014/11/07 14:57:28 | 000,102,692 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141106195626[2014/11/06 19:57:24 | 000,003,634 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141105214132[2014/11/05 19:15:28 | 001,378,478 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141104031446[2014/11/05 19:15:28 | 000,176,385 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141105191432[2014/11/04 03:14:56 | 001,738,366 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141103031446[2014/11/03 03:14:54 | 000,504,737 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141102201553[2014/11/02 08:52:02 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll[2014/11/02 08:51:56 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe[2014/11/02 08:51:56 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe[2014/11/02 08:51:55 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe[2014/11/02 07:48:50 | 000,901,277 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141102074757[2014/11/02 07:48:50 | 000,505,736 | ---- | M] () -- C:\WINDOWS\SysWow64\rsslogs.20141102014845[2014/11/02 00:47:39 | 000,000,532 | ---- | M] () -- C:\WINDOWS\SysNative\ASOROSet.bin[2014/10/24 18:32:33 | 000,001,755 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk[2014/10/24 17:34:49 | 000,001,817 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk[2014/10/15 20:10:05 | 001,797,088 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT[2014/10/13 17:02:42 | 000,534,104 | ---- | M] (IBM Corp.) -- C:\WINDOWS\SysNative\drivers\RapportKE64.sys[2014/10/13 17:02:42 | 000,289,656 | ---- | M] (IBM Corp.) -- C:\WINDOWS\SysNative\drivers\RapportHades64.sys[1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]========== Files Created - No Company Name ==========[2014/11/11 21:05:34 | 000,015,715 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141111210435[2014/11/11 19:39:17 | 000,102,664 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141111193818[2014/11/10 20:38:40 | 000,854,448 | ---- | C] () -- C:\Users\Dave\Desktop\SecurityCheck.exe[2014/11/10 20:16:35 | 000,124,421 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141110201537[2014/11/09 21:18:34 | 000,033,834 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109211734[2014/11/09 20:15:39 | 000,001,078 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[2014/11/09 19:47:12 | 000,108,693 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109194611[2014/11/09 19:13:35 | 000,038,679 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109191234[2014/11/09 18:51:22 | 000,025,377 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109185022[2014/11/09 18:46:53 | 000,024,064 | ---- | C] () -- C:\WINDOWS\zoek-delete.exe[2014/11/09 04:41:33 | 001,023,708 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141109044052[2014/11/08 04:41:30 | 001,738,235 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141108044053[2014/11/07 14:57:28 | 000,994,658 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141107145630[2014/11/06 19:57:24 | 000,102,692 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141106195626[2014/11/05 21:42:31 | 000,003,634 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141105214132[2014/11/05 19:15:28 | 000,176,385 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141105191432[2014/11/04 03:14:56 | 001,378,478 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141104031446[2014/11/03 03:14:54 | 001,738,366 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141103031446[2014/11/02 20:16:52 | 000,504,737 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141102201553[2014/11/02 07:48:50 | 000,901,277 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141102074757[2014/11/02 00:49:45 | 000,505,736 | ---- | C] () -- C:\WINDOWS\SysWow64\rsslogs.20141102014845[2014/10/24 18:32:33 | 000,001,755 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk[2014/10/24 17:34:48 | 000,001,817 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk[2014/10/14 19:34:34 | 000,388,729 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml[2014/08/29 14:58:45 | 000,005,120 | ---- | C] () -- C:\Users\Dave\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2014/08/08 10:32:43 | 000,000,008 | RHS- | C] () -- C:\ProgramData\ntuser.pol[2014/04/25 19:35:00 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini[2014/02/22 15:20:28 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll[2014/02/05 13:14:58 | 000,000,142 | ---- | C] () -- C:\WINDOWS\wpd99.drv[2014/02/05 13:14:41 | 000,040,448 | ---- | C] () -- C:\WINDOWS\SysWow64\pdf995mon64.dll[2014/01/22 00:48:02 | 000,930,400 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI[2014/01/22 00:44:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin[2013/12/13 10:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat[2013/12/13 10:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat[2013/12/13 10:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat[2013/12/13 10:23:24 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe[2013/12/13 10:23:24 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe[2013/12/13 10:23:14 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll[2013/09/27 21:05:34 | 000,003,734 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml[2013/08/22 08:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat[2013/08/22 08:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT[2013/08/22 07:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat[2013/08/22 00:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin[2013/08/21 20:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll[2013/08/21 16:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll[2013/08/21 16:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat[2013/07/12 18:51:22 | 000,000,017 | ---- | C] () -- C:\Users\Dave\AppData\Local\resmon.resmoncfg[2013/03/17 15:59:51 | 000,001,067 | ---- | C] () -- C:\WINDOWS\hpomdl35.dat.temp[2013/03/17 15:33:22 | 000,225,825 | ---- | C] () -- C:\WINDOWS\hpoins35.dat[2013/03/17 15:33:22 | 000,001,067 | ---- | C] () -- C:\WINDOWS\hpomdl35.dat[2012/12/27 18:13:50 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI========== ZeroAccess Check ==========[2014/01/22 17:08:29 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32][HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32][HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64"" = C:\Windows\SysNative\shell32.dll -- [2014/08/15 21:08:41 | 021,195,616 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]"" = %SystemRoot%\system32\shell32.dll -- [2014/08/15 20:16:40 | 018,722,600 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 02:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 19:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 02:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Both[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]========== LOP Check ==========[2013/12/27 21:35:06 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\AVAST Software[2013/02/26 21:50:50 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\AVG[2013/09/20 21:09:17 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\AVG2013[2013/11/08 12:15:04 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\com.zoosk.Desktop[2013/11/08 12:15:05 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1[2014/08/28 18:21:28 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Dropbox[2014/02/22 14:33:36 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\HewlettPackard[2013/01/07 12:20:50 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\OpenOffice.org[2014/04/25 18:58:49 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Oracle[2014/06/22 15:51:31 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Paltalk[2014/02/05 13:17:18 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\pdf995[2013/07/28 09:52:27 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SanDisk[2013/07/26 18:08:23 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SanDisk SecureAccess[2014/04/25 19:13:21 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\SmartDraw[2014/03/02 11:47:28 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\supportdotcom[2012/12/25 18:52:39 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Synaptics[2014/02/05 13:17:35 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\TaxCut[2013/02/26 21:39:11 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\TuneUp Software[2013/01/04 16:52:26 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Visan[2014/03/02 18:41:13 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\WildTangent[2014/06/28 09:26:00 | 000,000,000 | ---D | M] -- C:\Users\Dave\AppData\Roaming\Windows[2014/01/22 01:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software[2014/01/22 01:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software[2013/09/20 18:34:22 | 000,000,000 | ---D | M] -- C:\Users\TEMP\AppData\Roaming\AVG2014[2013/03/07 11:22:48 | 000,000,000 | ---D | M] -- C:\Users\TEMP\AppData\Roaming\TuneUp Software========== Purity Check ==================== Alternate Data Streams ==========@Alternate Data Stream - 36 bytes -> C:\Users\Dave\OneDrive:ms-properties@Alternate Data Stream - 220 bytes -> C:\Users\Dave\SkyDrive:ms-properties@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:373E1720< End of report >
-
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014Ran by Dave (administrator) on LAPTOP on 11-11-2014 19:42:57Running from C:\Users\Dave\DownloadsLoaded Profiles: Dave & (Available profiles: Dave)Platform: Windows 7 Ultimate (X64) OS Language: English (United States)Internet Explorer Version 11Boot Mode: NormalTutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/==================== Processes (Whitelisted) =================(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe(AMD) C:\Windows\System32\atiesrxx.exe(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe(Microsoft Corporation) C:\Windows\System32\dasHost.exe(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe(Microsoft Corporation) C:\Windows\System32\dllhost.exe(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe(Microsoft Corporation) C:\Windows\System32\LogonUI.exe(AMD) C:\Windows\System32\atieclxx.exe(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\livecomm.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Microsoft Corporation) C:\Windows\System32\rundll32.exe(Microsoft Corporation) C:\Windows\System32\wsqmcons.exe(Microsoft Corporation) C:\Windows\System32\rundll32.exe(Microsoft Corporation) C:\Users\Dave\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe(Microsoft Corporation) C:\Windows\System32\msfeedssync.exe(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe==================== Registry (Whitelisted) ==================(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)HKLM\...\Run: [synTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-24] (Synaptics Incorporated)HKLM\...\Run: [sysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-29] (IDT, Inc.)HKLM-x32\...\Run: [startCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491320 2012-07-26] (CyberLink Corp.)HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [580512 2012-07-09] (Hewlett-Packard Development Company, L.P.)HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [296520 2014-04-05] (RealNetworks, Inc.)HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-08-19] (Hewlett-Packard)HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\Run: [TWC.Win7] => C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exeHKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\MountPoints2: {bb7712fa-a231-11e3-beeb-c8cbb8b06c44} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL F:\TL-Bootstrap.exeHKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [TWC.Win7] => C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exeHKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {bb7712fa-a231-11e3-beeb-c8cbb8b06c44} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL F:\TL-Bootstrap.exeStartup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnkShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnkShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnkShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnkShortcutTarget: Dropbox.lnk -> C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnkShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No FileShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No FileShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No FileShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No FileShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File==================== Internet (Whitelisted) ====================(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)ProxyServer: http=127.0.0.1:14081;https=127.0.0.1:14081StartMenuInternet: IEXPLORE.EXE - iexplore.exeSearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)Tcpip\Parameters: [DhcpNameServer] 72.21.70.3 67.215.21.202FireFox:========FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF Plugin-x32: @real.com/nppl3260;version=17.0.8.22 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.8 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.8 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.8 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)FF Plugin-x32: @real.com/nprpplugin;version=17.0.8.22 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No FileFF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No FileFF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)FF Plugin HKU\S-1-5-21-2989837996-1790684633-2971567215-1002: hp.com/HPDetect -> C:\Users\Dave\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)FF Plugin HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: hp.com/HPDetect -> C:\Users\Dave\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\ExtFF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-04-05]FF HKLM-x32\...\Firefox\Extensions: [{0FAA5C82-A094-4541-8811-D3361F972A81}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\ExtChrome:=======CHR dev: Chrome dev build detected! <======= ATTENTIONCHR Profile: C:\Users\Dave\AppData\Local\Google\Chrome\User Data\DefaultCHR Extension: (Google Drive) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-25]CHR Extension: (YouTube) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-25]CHR Extension: (Google Search) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-25]CHR Extension: (Google Wallet) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-03]CHR Extension: (Gmail) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-25]CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-03-15]CHR StartMenuInternet: Google Chrome - chrome.exe==================== Services (Whitelisted) =================(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-21] (Microsoft Corporation)S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-13] (Microsoft Corporation)R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-05] (Microsoft Corporation)S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1919256 2014-10-13] (IBM Corp.)R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-03-15] ()R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-04-05] (RealNetworks, Inc.)R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-03-20] () [File not signed]S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-21] (Microsoft Corporation)S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-21] (Microsoft Corporation)S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-01-22] (Microsoft Corporation)R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-23] (Microsoft Corporation)S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]==================== Drivers (Whitelisted) ====================(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-11] (Malwarebytes Corporation)R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)R1 RapportCerberus_80055; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_80055.sys [761720 2014-10-10] ()R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [445880 2014-10-13] (IBM Corp.)S3 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [289656 2014-10-13] (IBM Corp.)S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [534104 2014-10-13] (IBM Corp.)S3 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [557656 2014-10-13] (IBM Corp.)S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)S3 ssmirrdr; C:\Windows\system32\DRIVERS\ssmirrdr.sys [10112 2014-01-08] (support.com, Inc)R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.)==================== NetSvcs (Whitelisted) ===================(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)==================== One Month Created Files and Folders ========(If an entry is included in the fixlist, the file\folder will be moved.)2014-11-11 19:42 - 2014-11-11 19:49 - 00020868 _____ () C:\Users\Dave\Downloads\FRST.txt2014-11-11 19:42 - 2014-11-11 19:43 - 00000000 ____D () C:\FRST2014-11-11 19:41 - 2014-11-11 19:41 - 02116096 _____ (Farbar) C:\Users\Dave\Downloads\FRST64.exe2014-11-11 19:39 - 2014-11-11 19:39 - 00025371 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411111938182014-11-10 20:38 - 2014-11-10 20:38 - 00854448 _____ () C:\Users\Dave\Desktop\SecurityCheck.exe2014-11-10 20:36 - 2014-11-10 20:36 - 00602112 _____ (OldTimer Tools) C:\Users\Dave\Desktop\OTL.com2014-11-10 20:33 - 2014-11-10 20:34 - 00688992 _____ (Swearware) C:\Users\Dave\Downloads\dds (1).com2014-11-10 20:32 - 2014-11-10 20:32 - 00688992 _____ (Swearware) C:\Users\Dave\Downloads\dds.scr2014-11-10 20:30 - 2014-11-10 20:30 - 00688992 _____ (Swearware) C:\Users\Dave\Downloads\dds.com2014-11-10 20:21 - 2014-11-10 20:21 - 00003282 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-10022014-11-10 20:20 - 2014-11-10 20:20 - 00003334 _____ () C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-10022014-11-10 20:16 - 2014-11-11 19:39 - 00124421 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411102015372014-11-09 21:32 - 2014-11-09 21:32 - 00000000 ____D () C:\Users\Dave\Downloads\Scan2014-11-09 21:18 - 2014-11-10 20:16 - 00033834 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411092117342014-11-09 20:16 - 2014-11-11 19:39 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys2014-11-09 20:15 - 2014-11-09 20:15 - 00001078 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk2014-11-09 20:15 - 2014-11-09 20:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware2014-11-09 20:14 - 2014-11-09 20:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware2014-11-09 20:14 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys2014-11-09 20:14 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys2014-11-09 20:14 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys2014-11-09 20:12 - 2014-11-09 20:13 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Dave\Downloads\mbam-setup-2.0.3.1025.exe2014-11-09 20:10 - 2014-11-09 20:10 - 00001515 _____ () C:\Users\Dave\Desktop\JRT.txt2014-11-09 19:55 - 2014-11-09 19:55 - 01706808 _____ (Thisisu) C:\Users\Dave\Downloads\JRT (1).exe2014-11-09 19:47 - 2014-11-09 19:47 - 00108693 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411091946112014-11-09 19:13 - 2014-11-09 19:13 - 00038679 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411091912342014-11-09 19:05 - 2014-11-09 19:06 - 01706808 _____ (Thisisu) C:\Users\Dave\Downloads\JRT.exe2014-11-09 19:04 - 2014-11-09 19:44 - 00000000 ____D () C:\AdwCleaner2014-11-09 19:03 - 2014-11-09 19:03 - 02140160 _____ () C:\Users\Dave\Downloads\adwcleaner_4.101 (1).exe2014-11-09 18:51 - 2014-11-09 18:51 - 00025377 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411091850222014-11-09 18:46 - 2014-11-09 16:58 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe2014-11-09 18:09 - 2014-11-09 18:53 - 00000000 ____D () C:\zoek2014-11-09 17:02 - 2014-11-09 18:53 - 00027017 _____ () C:\zoek-results.log2014-11-09 16:58 - 2014-11-09 18:33 - 00000000 ____D () C:\zoek_backup2014-11-09 16:41 - 2014-11-09 16:59 - 00000000 ____D () C:\Users\Dave\Downloads\zoek2014-11-09 16:40 - 2014-11-09 16:41 - 04124640 _____ () C:\Users\Dave\Downloads\zoek.zip2014-11-09 04:41 - 2014-11-09 04:41 - 01023708 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411090440522014-11-08 04:41 - 2014-11-09 04:41 - 01738235 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411080440532014-11-07 14:57 - 2014-11-08 04:41 - 00994658 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411071456302014-11-06 19:57 - 2014-11-07 14:57 - 00102692 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411061956262014-11-05 21:42 - 2014-11-06 19:57 - 00003634 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411052141322014-11-05 19:15 - 2014-11-05 19:15 - 00176385 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411051914322014-11-04 03:14 - 2014-11-05 19:15 - 01378478 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411040314462014-11-03 03:14 - 2014-11-04 03:14 - 01738366 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411030314462014-11-02 20:16 - 2014-11-03 03:14 - 00504737 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411022015532014-11-02 08:53 - 2014-11-02 08:51 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe2014-11-02 08:52 - 2014-11-02 08:52 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll2014-11-02 08:52 - 2014-11-02 08:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java2014-11-02 08:52 - 2014-11-02 08:51 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe2014-11-02 08:52 - 2014-11-02 08:51 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe2014-11-02 08:51 - 2014-11-02 08:51 - 00000000 ____D () C:\Program Files (x86)\Java2014-11-02 07:48 - 2014-11-02 07:48 - 00901277 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411020747572014-11-02 00:49 - 2014-11-02 07:48 - 00505736 _____ () C:\WINDOWS\SysWOW64\rsslogs.201411020148452014-10-25 21:14 - 2014-10-25 21:14 - 00641609 _____ () C:\Users\Dave\Downloads\201410259516330395001.3gp2014-10-24 18:32 - 2014-10-24 18:32 - 00001755 _____ () C:\Users\Public\Desktop\iTunes.lnk2014-10-24 18:28 - 2014-10-24 18:32 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A72014-10-24 17:34 - 2014-10-24 17:34 - 00001817 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk2014-10-19 07:40 - 2014-10-19 07:40 - 13781330 _____ () C:\Users\Dave\Downloads\20141018_194348.mp42014-10-15 20:12 - 2014-09-29 15:45 - 00706016 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe2014-10-15 20:12 - 2014-09-29 15:45 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl2014-10-14 19:40 - 2014-09-27 15:25 - 04183040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys2014-10-14 19:39 - 2014-09-18 19:25 - 23631360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll2014-10-14 19:39 - 2014-09-18 18:44 - 17484800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll2014-10-14 19:38 - 2014-09-25 15:50 - 13619200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll2014-10-14 19:38 - 2014-09-25 15:46 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll2014-10-14 19:38 - 2014-09-25 15:46 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll2014-10-14 19:38 - 2014-09-25 15:43 - 11807232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll2014-10-14 19:38 - 2014-09-25 15:32 - 02017280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl2014-10-14 19:38 - 2014-09-25 15:31 - 02108416 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl2014-10-14 19:38 - 2014-09-18 18:41 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll2014-10-14 19:38 - 2014-09-18 18:40 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll2014-10-14 19:38 - 2014-09-18 18:38 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll2014-10-14 19:38 - 2014-09-18 18:36 - 05829632 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll2014-10-14 19:38 - 2014-09-18 18:25 - 04201472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll2014-10-14 19:38 - 2014-09-18 18:25 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll2014-10-14 19:38 - 2014-09-18 18:02 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll2014-10-14 19:38 - 2014-09-18 18:00 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll2014-10-14 19:38 - 2014-09-18 17:59 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll2014-10-14 19:38 - 2014-09-18 17:58 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll2014-10-14 19:38 - 2014-09-18 17:55 - 02187264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll2014-10-14 19:38 - 2014-09-18 17:42 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll2014-10-14 19:38 - 2014-09-18 17:42 - 00710656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe2014-10-14 19:38 - 2014-09-18 17:42 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll2014-10-14 19:38 - 2014-09-18 17:33 - 02309632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll2014-10-14 19:38 - 2014-09-18 17:20 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll2014-10-14 19:38 - 2014-09-18 17:20 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll2014-10-14 19:38 - 2014-09-18 17:14 - 01447936 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll2014-10-14 19:38 - 2014-09-18 16:59 - 01810944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll2014-10-14 19:38 - 2014-09-18 16:59 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll2014-10-14 19:38 - 2014-09-18 16:53 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll2014-10-14 19:38 - 2014-09-18 16:52 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll2014-10-14 19:36 - 2014-09-07 20:15 - 00054752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe2014-10-14 19:36 - 2014-09-07 18:46 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll2014-10-14 19:36 - 2014-09-07 18:46 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll2014-10-14 19:36 - 2014-09-07 17:08 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe2014-10-14 19:36 - 2014-09-07 17:07 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll2014-10-14 19:36 - 2014-09-07 17:05 - 03448320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll2014-10-14 19:36 - 2014-09-07 17:04 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll2014-10-14 19:36 - 2014-09-07 17:04 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll2014-10-14 19:36 - 2014-09-07 17:03 - 01702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll2014-10-14 19:36 - 2014-09-07 17:03 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll2014-10-14 19:36 - 2014-09-07 16:59 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll2014-10-14 19:36 - 2014-09-07 16:59 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe2014-10-14 19:36 - 2014-09-07 16:56 - 00672256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll2014-10-14 19:36 - 2014-09-07 16:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll2014-10-14 19:36 - 2014-09-03 17:10 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll2014-10-14 19:36 - 2014-09-03 16:57 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll2014-10-14 19:36 - 2014-09-03 16:49 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll2014-10-14 19:34 - 2014-10-09 15:16 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll2014-10-14 19:34 - 2014-10-08 15:09 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll2014-10-14 19:34 - 2014-09-18 18:24 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll2014-10-14 19:34 - 2014-09-12 23:29 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll2014-10-14 19:34 - 2014-09-12 22:49 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll2014-10-14 19:34 - 2014-08-15 21:08 - 21195616 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll2014-10-14 19:34 - 2014-08-15 21:08 - 01507648 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll2014-10-14 19:34 - 2014-08-15 21:01 - 01710184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll2014-10-14 19:34 - 2014-08-15 20:58 - 01112512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll2014-10-14 19:34 - 2014-08-15 20:57 - 02498880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys2014-10-14 19:34 - 2014-08-15 20:57 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS2014-10-14 19:34 - 2014-08-15 20:16 - 18722600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll2014-10-14 19:34 - 2014-08-15 20:16 - 01205976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll2014-10-14 19:34 - 2014-08-15 20:03 - 01467384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll2014-10-14 19:34 - 2014-08-15 18:31 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll2014-10-14 19:34 - 2014-08-15 18:04 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll2014-10-14 19:34 - 2014-08-15 17:58 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll2014-10-14 19:34 - 2014-08-15 17:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll2014-10-14 19:34 - 2014-08-15 17:46 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll2014-10-14 19:34 - 2014-08-15 17:45 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll2014-10-14 19:34 - 2014-08-15 17:43 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll2014-10-14 19:34 - 2014-08-15 17:43 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll2014-10-14 19:34 - 2014-08-15 17:31 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll2014-10-14 19:34 - 2014-08-15 17:31 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll2014-10-14 19:34 - 2014-08-15 17:29 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll2014-10-14 19:34 - 2014-08-15 17:23 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll2014-10-14 19:34 - 2014-08-15 17:22 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll2014-10-14 19:34 - 2014-08-15 17:22 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll2014-10-14 19:34 - 2014-08-15 17:19 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll2014-10-14 19:34 - 2014-08-15 17:18 - 04758528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll2014-10-14 19:34 - 2014-08-15 17:17 - 08757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll2014-10-14 19:34 - 2014-08-15 17:14 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll2014-10-14 19:34 - 2014-08-15 17:13 - 06649344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll2014-10-14 19:34 - 2014-08-15 17:13 - 05902848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll2014-10-14 19:34 - 2014-08-15 17:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll2014-10-14 19:34 - 2014-08-15 17:11 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll2014-10-14 19:34 - 2014-08-15 17:10 - 01120768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe2014-10-14 19:34 - 2014-08-15 17:08 - 05777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll2014-10-14 19:34 - 2014-08-15 17:07 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll2014-10-14 19:34 - 2014-07-31 16:22 - 00388729 _____ () C:\WINDOWS\system32\ApnDatabase.xml2014-10-14 19:33 - 2014-09-03 17:12 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll2014-10-14 19:33 - 2014-09-03 17:01 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll2014-10-14 19:23 - 2014-09-12 23:02 - 02779648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll2014-10-14 19:23 - 2014-09-12 22:30 - 03117568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll2014-10-14 19:23 - 2014-08-28 16:56 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll2014-10-14 19:23 - 2014-08-28 16:47 - 02321920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll2014-10-14 19:22 - 2014-08-28 18:58 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll==================== One Month Modified Files and Folders =======(If an entry is included in the fixlist, the file\folder will be moved.)2014-11-11 19:52 - 2013-03-26 19:20 - 00000350 _____ () C:\WINDOWS\Tasks\HP Photo Creations Communicator.job2014-11-11 19:45 - 2012-12-25 18:55 - 00003914 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6734F1F0-3039-47CD-A28F-2E62C34206E1}2014-11-11 19:39 - 2014-01-22 01:30 - 01172533 _____ () C:\WINDOWS\WindowsUpdate.log2014-11-11 19:38 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\system32\sru2014-11-10 21:31 - 2013-01-04 16:51 - 00000330 _____ () C:\WINDOWS\Tasks\PrintProjects Communicator.job2014-11-10 21:14 - 2012-12-25 12:14 - 00000908 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job2014-11-10 21:13 - 2013-01-20 12:35 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job2014-11-10 20:21 - 2012-12-25 19:01 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2989837996-1790684633-2971567215-10022014-11-10 20:17 - 2014-01-22 06:14 - 00000000 __RDO () C:\Users\Dave\SkyDrive2014-11-09 21:17 - 2013-11-14 00:20 - 00030068 _____ () C:\WINDOWS\PFRO.log2014-11-09 21:17 - 2013-08-22 07:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT2014-11-09 20:14 - 2013-10-26 22:07 - 00000000 ____D () C:\ProgramData\Malwarebytes2014-11-09 19:11 - 2013-08-22 06:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI2014-11-09 18:57 - 2013-11-14 00:28 - 00956540 _____ () C:\WINDOWS\system32\PerfStringBackup.INI2014-11-09 18:50 - 2014-08-08 10:32 - 00000008 __RSH () C:\ProgramData\ntuser.pol2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Dave\AppData\Local\Comodo2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google2014-11-09 18:28 - 2014-08-08 10:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo2014-11-09 18:28 - 2012-12-25 12:13 - 00000000 ____D () C:\Users\Dave\AppData\Local\Google2014-11-09 18:12 - 2013-08-22 08:36 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy2014-11-09 18:12 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy2014-11-09 16:31 - 2014-03-01 19:54 - 00002980 _____ () C:\WINDOWS\System32\Tasks\LAUNCH CDPCO2014-11-07 16:59 - 2013-01-17 21:51 - 00003154 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForDave2014-11-07 16:59 - 2013-01-17 21:51 - 00000342 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForDave.job2014-11-06 20:03 - 2014-09-24 19:17 - 00003356 _____ () C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-10022014-11-05 20:16 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\AppReadiness2014-11-05 19:23 - 2013-01-16 18:08 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log2014-11-05 19:22 - 2013-01-16 18:08 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt2014-11-04 20:42 - 2014-02-18 20:35 - 00387072 ___SH () C:\Users\Dave\Downloads\Thumbs.db2014-11-02 00:47 - 2014-03-02 14:28 - 00000532 _____ () C:\WINDOWS\system32\ASOROSet.bin2014-11-02 00:47 - 2013-08-22 06:25 - 83886080 _____ () C:\WINDOWS\system32\config\SOFTWARE.bak2014-11-02 00:47 - 2013-08-22 06:25 - 00024576 _____ () C:\WINDOWS\system32\config\SECURITY.bak2014-11-02 00:46 - 2013-08-22 06:25 - 00061440 _____ () C:\WINDOWS\system32\config\SAM.bak2014-10-30 04:25 - 2014-01-24 10:53 - 00275080 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe2014-10-28 18:55 - 2013-08-21 10:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection2014-10-24 18:32 - 2014-05-19 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes2014-10-24 18:32 - 2014-02-28 19:07 - 00000000 ____D () C:\Program Files\iTunes2014-10-24 18:32 - 2014-02-28 19:07 - 00000000 ____D () C:\Program Files (x86)\iTunes2014-10-24 18:28 - 2014-02-28 19:07 - 00000000 ____D () C:\Program Files\iPod2014-10-24 18:28 - 2013-06-21 20:50 - 00000000 ____D () C:\Program Files\Common Files\Apple2014-10-24 17:35 - 2014-02-28 18:43 - 00000000 ____D () C:\Program Files (x86)\QuickTime2014-10-24 17:34 - 2014-02-28 18:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime2014-10-18 10:44 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\system32\NDF2014-10-16 23:28 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\rescache2014-10-15 20:10 - 2013-08-22 07:44 - 01797088 _____ () C:\WINDOWS\system32\FNTCACHE.DAT2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ___RD () C:\WINDOWS\ToastData2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\WinStore2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\MediaViewer2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\FileManager2014-10-15 20:03 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\Camera2014-10-15 20:02 - 2012-07-26 00:59 - 00000000 ____D () C:\WINDOWS\CbsTemp2014-10-15 19:49 - 2014-07-13 20:34 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel2014-10-14 20:15 - 2013-08-17 00:14 - 00000000 ____D () C:\WINDOWS\system32\MRT2014-10-14 20:05 - 2012-12-26 21:49 - 103265616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe2014-10-13 17:02 - 2012-12-26 19:31 - 00289656 _____ (IBM Corp.) C:\WINDOWS\system32\Drivers\RapportHades64.sys2014-10-13 17:02 - 2012-12-26 19:30 - 00534104 _____ (IBM Corp.) C:\WINDOWS\system32\Drivers\RapportKE64.sysSome content of TEMP:====================C:\Users\Dave\AppData\Local\Temp\Quarantine.exeC:\Users\Dave\AppData\Local\Temp\sqlite3.dll==================== Bamital & volsnap Check =================(There is no automatic fix for files that do not pass verification.)C:\Windows\System32\winlogon.exe => File is digitally signedC:\Windows\System32\wininit.exe => File is digitally signedC:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.C:\Windows\explorer.exe => File is digitally signedC:\Windows\SysWOW64\explorer.exe => File is digitally signedC:\Windows\System32\svchost.exe => File is digitally signedC:\Windows\SysWOW64\svchost.exe => File is digitally signedC:\Windows\System32\services.exe => File is digitally signedC:\Windows\System32\User32.dll => File is digitally signedC:\Windows\SysWOW64\User32.dll => File is digitally signedC:\Windows\System32\userinit.exe => File is digitally signedC:\Windows\SysWOW64\userinit.exe => File is digitally signedC:\Windows\System32\rpcss.dll => File is digitally signedC:\Windows\System32\Drivers\volsnap.sys => File is digitally signedLastRegBack: 2014-11-09 19:44==================== End Of Log ============================
-
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2014Ran by Dave at 2014-11-11 20:03:30Running from C:\Users\Dave\DownloadsBoot Mode: Normal============================================================================== Security Center ========================(If an entry is included in the fixlist, it will be removed.)AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}==================== Installed Programs ======================(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) HiddenAdobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.)aiofw (x32 Version: 4.2.6.8 - Eastman Kodak Company) Hiddenaioprnt (Version: 4.2.7.4 - Eastman Kodak Company) Hiddenaioscnnr (x32 Version: 4.2.6.0 - Your Company Name) HiddenAMD Catalyst Install Manager (HKLM\...\{63ADEC24-A374-80A8-E89B-BE401C787F75}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)AVG 2013 (HKLM\...\AVG) (Version: 2013.0.3392 - AVG Technologies)Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) HiddenC309a (x32 Version: 140.0.846.000 - Hewlett-Packard) Hiddencenter (x32 Version: 4.2.6.8 - Eastman Kodak Company) HiddenCompatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)CorelDRAW 10 (HKLM-x32\...\CorelDRAW 10) (Version: - )CorelDRAW 10 (x32 Version: 10 - Corel) HiddenCyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1.5407 - CyberLink Corp.)CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.1.1926 - CyberLink Corp.)CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.)CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.)D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) HiddenDestinations (x32 Version: 140.0.253.000 - Hewlett-Packard) HiddenDeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) HiddenDocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) HiddenDropbox (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)Dropbox (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) HiddenGoogle Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) HiddenGoogle Update Helper (x32 Version: 1.3.24.15 - Google Inc.) HiddenGPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) HiddenH&R Block Deluxe + Efile 2012 (HKLM-x32\...\{89D20029-0578-4D8D-979A-695C8D868868}) (Version: 12.04.7803 - HRB Technology, LLC.)H&R Block Deluxe + Efile 2013 (HKLM-x32\...\{AD9F55C5-93F8-4CAB-A311-77C195912CA4}) (Version: 13.04.5801 - HRB Technology, LLC.)Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) HiddenHP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)HP Documentation (HKLM-x32\...\{D23CA718-0356-41F2-8E6A-B5C6CD383EF7}) (Version: 1.1.0.0 - Hewlett-Packard)HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)HP MyRoom (HKLM-x32\...\{9C35EDE5-4B0F-45E7-A438-314BA889948E}) (Version: 9.0.0.0 - Hewlett-Packard Company)HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.11502 - HP)HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6 (HKLM\...\{F089B734-1356-484F-A7B8-1B78F1616A15}) (Version: 14.0 - HP)HP Quick Launch (HKLM-x32\...\{4ED7050C-9332-4FB2-AB07-E94F25A53D39}) (Version: 3.0.3 - Hewlett-Packard Company)HP Registration Service (HKLM\...\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard)HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard)HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.5.1 - Hewlett-Packard Company)HPDetect (HKLM-x32\...\{CCCDD476-98F9-4B06-91DB-23F27CEC3BE1}) (Version: 1.0.0.0 - HP)HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) HiddenHPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) HiddenHRBlockDirect version 1.1.2.0 (HKLM-x32\...\{631EFC00-5A7A-4A90-9578-039EDA92DE0F}_is1) (Version: 1.1.2.0 - HRBlock)iCloud (HKLM\...\{6096C0CC-7E19-4355-87F0-627EC5AA146D}) (Version: 4.0.3.56 - Apple Inc.)IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6423.0 - IDT)iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)KODAK AiO Home Center (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 4.2.7.7 - Eastman Kodak Company)ksDIP (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) HiddenMalwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) HiddenMicrosoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)Microsoft Office XP Media Content (HKLM-x32\...\{90300409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2619.0 - Microsoft Corporation)Microsoft Office XP Professional (HKLM-x32\...\{91110409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)Microsoft OneDrive (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)Microsoft OneDrive (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)MyCleanPC PC Optimizer (HKLM-x32\...\{6AAEB4CB-0573-41ec-89B0-0FE0D5134A8B}_is1) (Version: 2.0.648.15539 - USTechSupport)Network64 (Version: 140.0.306.000 - Hewlett-Packard) HiddenOCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)OpenOffice.org 3.4.1 (HKLM-x32\...\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)Pdf995 (installed by H&R Block) (HKLM-x32\...\Pdf995) (Version: - )PdfEdit995 (installed by H&R Block) (HKLM-x32\...\PdfEdit995) (Version: - )PreReq (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) HiddenPrintProjects (HKLM-x32\...\PrintProjects) (Version: 1.0.0.12842 - RocketLife Inc.)PS_AIO_05_C309_Software_Min (x32 Version: 140.0.855.000 - Hewlett-Packard) HiddenQuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)Ralink RT5390R 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.2.0 - Ralink)Rapport (x32 Version: 3.5.1404.21 - Trusteer) HiddenRealDownloader (x32 Version: 17.0.8 - RealNetworks, Inc.) HiddenRealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) HiddenRealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) HiddenRealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) HiddenRealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.8 - RealNetworks)Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.28123 - Realtek Semiconductor Corp.)RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) HiddenSanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\...\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-2989837996-1790684633-2971567215-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19755 - Gemalto N.V.)Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) HiddenSkypeâ„¢ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) HiddenStatus (x32 Version: 140.0.342.000 - Hewlett-Packard) HiddenswMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) HiddenSynaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated)The Weather Channel App (HKLM-x32\...\{167158CE-1637-4167-8A1C-C2549EEA966A}) (Version: 1.00.0000 - The Weather Channel)Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) HiddenTrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) HiddenTrusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1404.21 - Trusteer)UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) HiddenUS Tech Support Framework (HKLM-x32\...\{4734A746-A503-4B8E-A4FA-7B7C84A18D79}) (Version: 2.1.0.4741 - US Tech Support LLC)WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) HiddenWindows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)==================== Custom CLSID (selected items): ==========================(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)==================== Restore Points =========================02-11-2014 06:28:59 MyCleanPCPCOptimizer_BeforeFixingIssues02-11-2014 15:49:06 Installed Java 7 Update 7104-11-2014 03:19:30 Activeris AntiMalware09-11-2014 07:29:56 MyCleanPCPCOptimizer_BeforeFixingIssues10-11-2014 00:02:47 zoek.exe restore point==================== Hosts content: ==========================(If needed Hosts: directive could be included in the fixlist to reset Hosts.)2012-07-25 22:26 - 2013-11-02 08:48 - 00000098 ____A C:\WINDOWS\system32\Drivers\etc\hosts127.0.0.1 localhost::1 localhost==================== Scheduled Tasks (whitelisted) =============(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)Task: {0CE77290-6C90-4736-8A58-ADA98B3D4E12} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-24] (Synaptics Incorporated)Task: {16A4324C-A396-460A-BB02-5C5463E8CF52} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-2989837996-1790684633-2971567215-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exeTask: {2F479EB9-097F-4D4E-AAEE-3BB23DACCCF2} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-03-26] ()Task: {31039BA7-AB5C-4759-AD4D-DFEBBD5223C0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)Task: {372FF955-5904-477D-B8E2-D6ACC04F4DD5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-09-22] (Hewlett-Packard)Task: {384730F8-58C1-4DF6-97C0-F1F4079B17A2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-10-14] (Microsoft Corporation)Task: {3C28E809-DD74-4E2D-8800-2A1359D2FF2E} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)Task: {45677C94-4A54-493B-A37F-06620638B55C} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)Task: {4ADA22F5-E7E9-4EE7-9FAB-29776C108B45} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-03-15] (RealNetworks, Inc.)Task: {729E0FE4-EA3F-4B2E-9E54-665A6EB6729D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)Task: {8D94B28D-7FF3-4333-AF99-E815A96CBAB7} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-03-20] (RealNetworks, Inc.)Task: {91760CEA-8DCD-4D98-A587-809BC244CD34} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-09-22] (Hewlett-Packard)Task: {95FD93E0-88E4-4373-BE4C-61CC5001D987} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2013-11-04] (Hewlett-Packard Company)Task: {9B4764CB-0DB0-47A2-9B8A-E23FF553C9ED} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)Task: {A41E952D-CE82-42D6-A8C1-8A70C4D97971} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)Task: {B78FBC55-3ACA-4BAE-B1D5-364936955538} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)Task: {C2389E22-D793-4EB6-BC58-7BF1B3B5AEBF} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-12] (CyberLink)Task: {C258507F-A465-4E0C-A6F4-7EB34EC86A59} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)Task: {C3C594CE-E07F-4415-B1F3-4B556B528F08} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)Task: {C5BEE337-92EC-48E5-9C6B-E99BCF5B859F} - System32\Tasks\PrintProjects Communicator => C:\ProgramData\PrintProjects\Communicator.exe [2013-12-21] ()Task: {C7DF08C9-42F4-424C-800D-1EE5F9C9CE92} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)Task: {CC909D9E-E254-4E3C-9807-BF59C9AD6C3D} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-03-20] (RealNetworks, Inc.)Task: {CFBAE89D-2978-4694-B039-D1C96BB5AC41} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackupTask: {E06C2A65-1770-463B-9155-9683771261F1} - System32\Tasks\LAUNCH CDPCO => C:\Program Files (x86)\USTechSupport\PC Optimizer\USTSPCO.exeTask: {F41AFF04-916A-4ACF-B121-8B926E2467A1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)Task: {F6306C56-C5E2-402B-AAEB-5402514EC1C6} - System32\Tasks\HPCeeScheduleForDave => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)Task: {FABDB386-48DE-4D30-B843-40CB0CE82A31} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: {FAE1F865-9DFE-4285-A82D-5721E836B5F8} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-07] (CyberLink)Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeTask: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\WINDOWS\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exeTask: C:\WINDOWS\Tasks\HPCeeScheduleForDave.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exeTask: C:\WINDOWS\Tasks\PrintProjects Communicator.job => C:\ProgramData\PrintProjects\Communicator.exeTask: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe==================== Loaded Modules (whitelisted) =============2014-02-05 13:14 - 2012-04-26 15:51 - 00040448 _____ () C:\WINDOWS\System32\pdf995mon64.dll2012-08-06 12:09 - 2012-08-06 12:09 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll2014-03-15 02:18 - 2014-03-15 02:18 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe2014-03-20 20:13 - 2014-03-20 20:13 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe2014-04-27 18:04 - 2014-04-27 18:04 - 00043520 _____ () C:\Users\Dave\AppData\Local\Packages\53987rbl3.financehelper_z2nrd37h46pd8\AC\Microsoft\CLR_v4.0\NativeImages\Tasks\9e3e7a9b672757fec0f0b3de7245f539\Tasks.ni.dll2014-10-16 23:24 - 2014-10-16 23:24 - 01782784 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\3f4dc590466037f015f65bc07d1ea923\Windows.ApplicationModel.ni.dll2014-04-27 18:04 - 2014-04-27 18:04 - 00348672 _____ () C:\Users\Dave\AppData\Local\Packages\53987rbl3.financehelper_z2nrd37h46pd8\AC\Microsoft\CLR_v4.0\NativeImages\Notificatioc5a47191#\39274f50b85b30f3b823e5dd99be667c\NotificationsExtensions.ni.dll2014-10-16 23:24 - 2014-10-16 23:24 - 00521216 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Data\fae2b750f87849ca11806d20b2504bf2\Windows.Data.ni.dll2014-10-16 23:24 - 2014-10-16 23:24 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\4bd80968bf666252841ca7792faaff11\Windows.UI.ni.dll2014-09-14 10:01 - 2014-09-14 10:01 - 00088576 _____ () C:\Users\Dave\AppData\Local\Packages\53987rbl3.financehelper_z2nrd37h46pd8\AC\Microsoft\CLR_v4.0\NativeImages\SharedDataLink\846b13847670d6d4ee629471089a53d7\SharedDataLink.ni.dll2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll2014-03-23 16:04 - 2014-03-23 16:04 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll2012-09-15 07:31 - 2012-06-07 20:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll2012-06-08 11:34 - 2012-06-08 11:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll2014-07-19 09:26 - 2014-07-15 02:24 - 00718664 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll2014-07-19 09:26 - 2014-07-15 02:24 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll2014-07-19 09:26 - 2014-07-15 02:24 - 08537928 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll2014-07-19 09:26 - 2014-07-15 02:24 - 00353096 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll2014-07-19 09:26 - 2014-07-15 02:24 - 01732936 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll2014-07-19 09:26 - 2014-07-15 02:24 - 14664008 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll==================== Alternate Data Streams (whitelisted) =========(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)AlternateDataStreams: C:\ProgramData\Temp:373E1720AlternateDataStreams: C:\Users\Dave\OneDrive:ms-propertiesAlternateDataStreams: C:\Users\Dave\SkyDrive:ms-properties==================== Safe Mode (whitelisted) ===================(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)==================== EXE Association (whitelisted) =============(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)==================== MSCONFIG/TASK MANAGER disabled items =========(Currently there is no automatic fix for this section.)HKLM\...\StartupApproved\StartupFolder: => "Microsoft Office.lnk"HKLM\...\StartupApproved\StartupFolder: => "AtHomeConnect.lnk"HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"HKLM\...\StartupApproved\StartupFolder: => "HRBlockDirect.lnk"HKLM\...\StartupApproved\StartupFolder: => "RealPlayer Cloud Service UI.lnk"HKLM\...\StartupApproved\Run32: => "APSDaemon"HKLM\...\StartupApproved\Run32: => "Conime"HKLM\...\StartupApproved\Run32: => "QuickTime Task"HKLM\...\StartupApproved\Run32: => "Corel Reminder"HKLM\...\StartupApproved\Run32: => "AVG_UI"HKLM\...\StartupApproved\Run32: => "HP Software Update"HKLM\...\StartupApproved\Run32: => "iTunesHelper"HKLM\...\StartupApproved\Run32: => "TkBellExe"HKLM\...\StartupApproved\Run32: => "ApnTBMon"HKLM\...\StartupApproved\Run32: => "BrowserSafeguard"HKLM\...\StartupApproved\Run32: => "VNT"HKCU\...\StartupApproved\StartupFolder: => "OpenOffice.org 3.4.1.lnk"HKCU\...\StartupApproved\StartupFolder: => "Dropbox.lnk"HKCU\...\StartupApproved\StartupFolder: => "PalTalk.lnk"HKCU\...\StartupApproved\Run: => "Skype"HKCU\...\StartupApproved\Run: => "DW7"========================= Accounts: ==========================Administrator (S-1-5-21-2989837996-1790684633-2971567215-500 - Administrator - Disabled)Dave (S-1-5-21-2989837996-1790684633-2971567215-1002 - Administrator - Enabled) => C:\Users\DaveGuest (S-1-5-21-2989837996-1790684633-2971567215-501 - Limited - Disabled)HomeGroupUser$ (S-1-5-21-2989837996-1790684633-2971567215-1010 - Limited - Enabled)==================== Faulty Device Manager Devices ================================= Event log errors: =========================Application errors:==================Error: (11/11/2014 07:48:39 PM) (Source: Application Hang) (EventID: 1002) (User: )Description: The program LiveComm.exe version 17.5.9600.20605 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.Process ID: 300Start Time: 01cffe21b9838d0eTermination Time: 4294967295Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exeReport Id: 60fea05d-6a16-11e4-bf3d-c8cbb8b06c44Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbweFaulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1Error: (11/10/2014 08:28:20 PM) (Source: Application Hang) (EventID: 1002) (User: )Description: The program wwahost.exe version 6.3.9600.17031 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.Process ID: 14f8Start Time: 01cffd5e0d10df01Termination Time: 4294967295Application Path: C:\WINDOWS\system32\wwahost.exeReport Id: 00cf954a-6952-11e4-bf3d-c8cbb8b06c44Faulting package full name: AD2F1837.HPConnectedPhotopoweredbySnapfish_2.5.6.4614_neutral__v10z8vjag6ke6Faulting package-relative application ID: AppError: (11/10/2014 08:23:22 PM) (Source: Application Hang) (EventID: 1002) (User: )Description: The program backgroundTaskHost.exe version 6.3.9600.16384 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.Process ID: c4Start Time: 01cffd5e0d1808f7Termination Time: 4294967295Application Path: C:\WINDOWS\system32\backgroundTaskHost.exeReport Id: 00d45714-6952-11e4-bf3d-c8cbb8b06c44Faulting package full name: 53987RBL3.FinanceHelper_1.1.0.73_neutral__z2nrd37h46pd8Faulting package-relative application ID: AppSystem errors:=============Error: (11/09/2014 09:19:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )Description: The Google Update Service (gupdate) service failed to start due to the following error:%%2Error: (11/09/2014 09:17:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )Description: The Kodak AiO Network Discovery Service service failed to start due to the following error:%%1053Error: (11/09/2014 09:17:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: )Description: A timeout was reached (30000 milliseconds) while waiting for the Kodak AiO Network Discovery Service service to connect.Microsoft Office Sessions:=========================Error: (11/11/2014 07:48:39 PM) (Source: Application Hang) (EventID: 1002) (User: )Description: LiveComm.exe17.5.9600.2060530001cffe21b9838d0e4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe60fea05d-6a16-11e4-bf3d-c8cbb8b06c44microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1Error: (11/10/2014 08:28:20 PM) (Source: Application Hang) (EventID: 1002) (User: )Description: wwahost.exe6.3.9600.1703114f801cffd5e0d10df014294967295C:\WINDOWS\system32\wwahost.exe00cf954a-6952-11e4-bf3d-c8cbb8b06c44AD2F1837.HPConnectedPhotopoweredbySnapfish_2.5.6.4614_neutral__v10z8vjag6ke6AppError: (11/10/2014 08:23:22 PM) (Source: Application Hang) (EventID: 1002) (User: )Description: backgroundTaskHost.exe6.3.9600.16384c401cffd5e0d1808f74294967295C:\WINDOWS\system32\backgroundTaskHost.exe00d45714-6952-11e4-bf3d-c8cbb8b06c4453987RBL3.FinanceHelper_1.1.0.73_neutral__z2nrd37h46pd8AppCodeIntegrity Errors:===================================Date: 2014-11-10 20:40:36.675Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-11-10 20:40:35.762Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:40.640Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:39.996Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:39.375Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:38.166Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:37.503Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:36.848Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:31.260Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.Date: 2014-10-26 19:35:30.495Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.==================== Memory info ===========================Processor: AMD E-300 APU with Radeon HD GraphicsPercentage of memory in use: 52%Total physical RAM: 3682.26 MBAvailable physical RAM: 1736.68 MBTotal Pagefile: 4578.26 MBAvailable Pagefile: 1816.53 MBTotal Virtual: 131072 MBAvailable Virtual: 131071.75 MB==================== Drives ================================Drive c: () (Fixed) (Total:275.65 GB) (Free:217.97 GB) NTFS ==>[system with boot components (obtained from reading drive)]Drive d: (RECOVERY) (Fixed) (Total:21.33 GB) (Free:2.57 GB) NTFS ==>[system with boot components (obtained from reading drive)]==================== MBR & Partition Table ==========================================================================Disk: 0 (Size: 298.1 GB) (Disk ID: C2C9F703)Partition: GPT Partition Type.==================== End Of Log ============================
-
It will not let me run either DDS programs anything else I can do
-
Chuck no natepad log came up but I quarantined 14
-
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Junkware Removal Tool (JRT) by ThisisuVersion: 6.3.7 (11.08.2014:1)OS: Windows 8.1 x64Ran by Dave on Sun 11/09/2014 at 19:56:14.64~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ServicesSuccessfully stopped: [service] ustspcodiskoptimizerSuccessfully deleted: [service] ustspcodiskoptimizerSuccessfully stopped: [service] ustsschedulerSuccessfully deleted: [service] ustsscheduler~~~ Registry Values~~~ Registry KeysSuccessfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181102}~~~ Files~~~ FoldersSuccessfully deleted: [Folder] "C:\ProgramData\pchealthboost"Successfully deleted: [Folder] "C:\ProgramData\ustechsupport"Successfully deleted: [Folder] "C:\Users\Dave\AppData\Roaming\ustechsupport"Successfully deleted: [Folder] "C:\Program Files (x86)\pc healthboost"Successfully deleted: [Folder] "C:\Program Files (x86)\ustechsupport"Successfully deleted: [Folder] "C:\Program Files (x86)\Common Files\ustechsupport"Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mycleanpc"~~~ Event Viewer Logs were cleared~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Scan was completed on Sun 11/09/2014 at 20:10:15.20End of JRT log~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-
# AdwCleaner v4.101 - Report created 09/11/2014 at 19:44:32# Updated 09/11/2014 by Xplode# Database : 2014-11-07.1 [Live]# Operating System : Windows 8.1 (64 bits)# Username : Dave - LAPTOP# Running from : C:\Users\Dave\Downloads\adwcleaner_4.101 (1).exe# Option : Clean***** [ Services ] ********** [ Files / Folders ] ********** [ Scheduled Tasks ] ********** [ Shortcuts ] ********** [ Registry ] *****Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536***** [ Browsers ] *****-\\ Internet Explorer v11.0.9600.17344Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [search Page]Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [start Page]-\\ Mozilla Firefox v-\\ Google Chrome v36.0.1985.125[C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : blmchfpimpbbdmgpcieclabeafkljbhm[C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kdidombaedgpfiiedeimiebkmbilgmlc[C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : licjnkifamhpbaefhdpacpmihicfbomb[C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : niapdbllcanepiiimjjndipklodoedlc[C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma[C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo[C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg[C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : hphibigbodkkohoglgfkddblldpfohjl[C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej[C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl[C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc[C:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc*************************AdwCleaner[R3].txt - [293 octets] - [09/11/2014 19:04:29]AdwCleaner[R4].txt - [286 octets] - [09/11/2014 19:10:11]AdwCleaner[R5].txt - [7011 octets] - [09/11/2014 19:19:05]AdwCleaner[R6].txt - [7849 octets] - [09/11/2014 19:37:16]AdwCleaner[s2].txt - [2165 octets] - [09/11/2014 19:35:24]AdwCleaner[s3].txt - [7336 octets] - [09/11/2014 19:44:32]########## EOF - C:\AdwCleaner\AdwCleaner[s3].txt - [7396 octets] ##########
-
Zoek.exe v5.0.0.0 Updated 09-November-2014Tool run by Dave on Sun 11/09/2014 at 16:58:58.24.Microsoft Windows 8.1 6.3.9600 x64Running in: Normal Mode Internet Access DetectedLaunched: C:\Users\Dave\Downloads\zoek\zoek.exe [scan all users] [Quick Scan] [Auto Clean]==== System Restore Info ======================11/9/2014 5:03:55 PM Zoek.exe System Restore Point Created Succesfully.==== Empty Folders Check ======================C:\PROGRA~2\predm deleted successfullyC:\PROGRA~2\VNT deleted successfullyC:\PROGRA~2\COMMON~1\supportdotcom deleted successfullyC:\PROGRA~2\COMMON~1\SWF Studio deleted successfullyC:\PROGRA~2\COMMON~1\Symantec Shared deleted successfullyC:\PROGRA~3\cosstminn deleted successfullyC:\PROGRA~3\Oracle deleted successfullyC:\Users\Dave\AppData\Roaming\Activeris deleted successfullyC:\Users\Dave\AppData\Local\CrashDumps deleted successfullyC:\Users\Dave\AppData\Local\VisualBeeExe deleted successfullyC:\Users\Dave\AppData\Local\WordOv deleted successfully==== Deleting CLSID Registry Keys ======================HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6} deleted successfully==== Deleting CLSID Registry Values ========================== Deleting Services ========================== Deleting Files \ Folders ======================C:\Users\Dave\AppData\LocalLow\{84A16F3D-D897-5769-5232-703FC5F4369F} deletedC:\PROGRA~2\cosstminn deletedC:\PROGRA~2\Mozilla Firefox\browser\nsprotector.js deletedC:\PROGRA~2\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml deletedC:\PROGRA~2\Mozilla Firefox\browser\searchplugins\sweettunes_search.xml deletedC:\PROGRA~2\The Weather Channel deletedC:\PROGRA~2\Yahoo! deletedC:\PROGRA~2\Optimizer Pro deletedC:\PROGRA~2\MyPC Backup deletedC:\PROGRA~2\AskPartnerNetwork deletedC:\Users\Dave\AppData\Roaming\WB.CFG deletedC:\Users\Dave\AppData\Roaming\Yahoo! deletedC:\PROGRA~3\AskPartnerNetwork deletedC:\PROGRA~3\APN deletedC:\PROGRA~3\VisualBee deletedC:\PROGRA~3\AVG SafeGuard toolbar deletedC:\Users\Dave\AppData\Local\BrowserSafeguard deletedC:\Users\Dave\AppData\Local\Systweak deletedC:\Users\Dave\AppData\Local\AVG SafeGuard toolbar deletedC:\Users\Dave\AppData\Local\emaze deletedC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx deletedC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data-journal deletedC:\Users\TEMP\AppData\Local\AVG SafeGuard toolbar deletedC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deletedC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 deletedC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deletedC:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk deletedC:\WINDOWS\SysNative\roboot64.exe deletedC:\Users\Dave\AppData\LocalLow\AVG SafeGuard toolbar deletedC:\Users\TEMP\AppData\LocalLow\AVG SafeGuard toolbar deletedC:\WINDOWS\tasks\Groovorio Updater.job deletedC:\windows\SysNative\tasks\USTSPCO-USTSPCOOneClickCare deletedC:\WINDOWS\tasks\USTSPCO-USTSPCOOneClickCare.job deletedC:\components deletedC:\WINDOWS\SysNative\config\systemprofile\Searches deletedC:\windows\SysNative\GroupPolicy\Machine deletedC:\windows\SysNative\GroupPolicy\User deletedC:\windows\SysNative\GroupPolicy\GPT.INI deletedC:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deletedC:\WINDOWS\SysWow64\searchplugins deletedC:\WINDOWS\SysWow64\Extensions deletedC:\Users\Dave\Documents\Optimizer Pro deleted"C:\PROGRA~3\ab34c546d7769ac4\{CE681A67-9477-CBE6-EB9D-FE534875F98D}.20140808113335" deleted"C:\PROGRA~3\ab34c546d7769ac4" deleted"C:\Users\Dave\AppData\Roaming\Temp" deleted==== Files Recently Created / Modified ============================ C:\WINDOWS ========== C:\Users\Dave\AppData\Local\Temp ========== Java Cache =========== C:\WINDOWS\SysWOW64 =====2014-11-02 15:53:26 B9F9FD6188CC732F19DB69CAE5CC597C 272808 ----a-w- C:\WINDOWS\SysWOW64\javaws.exe2014-11-02 15:52:27 8FA677D5F2AFE2A3F111C50D68A93542 98216 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll2014-11-02 15:52:27 3594C0ABBFFE10B3CF95714B8B3C89A4 175528 ----a-w- C:\WINDOWS\SysWOW64\javaw.exe2014-11-02 15:52:27 095826BCBBFA5C09C72463A82612B23C 175528 ----a-w- C:\WINDOWS\SysWOW64\java.exe====== C:\WINDOWS\SysWOW64\drivers =========== C:\WINDOWS\Sysnative =========== C:\WINDOWS\Sysnative\drivers =====2014-10-15 02:34:50 87F3713E620F62D243A82B3CB66CBDDE 2498880 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys2014-10-15 02:34:37 329FEB41BBE82FBBD9BD69547BA1CB82 428864 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS====== C:\WINDOWS\Tasks ============ C:\WINDOWS\Temp ============= C:\Program Files ============ C:\PROGRA~2 =====2014-11-02 15:51:48 -------- d-----w- C:\PROGRA~2\Java======= C: =========== C:\Users\Dave\AppData\Roaming ============ C:\Users\Dave ======2014-11-02 18:25:11 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp2014-11-02 15:52:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java2014-10-25 01:28:36 -------- d-----w- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7====== C: exe-files ===== C: other files ====== Startup Registry Enabled ======================[HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Run]"TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun""CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R""RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe""HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe""APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe""HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe""Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe""TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe -osboot""QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime""iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe""SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]"TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"==== Startup Registry Enabled x64 ======================[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe ""SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]"NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update"==== Startup Folders ======================2014-05-04 18:29:12 1096 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk2013-01-07 19:21:07 1239 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk2013-03-17 22:43:48 2099 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk2012-12-28 01:12:20 2015 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk2014-04-05 21:43:33 1236 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk==== Task Scheduler Jobs ======================C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/09/2014 01:14 PM]C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe []C:\WINDOWS\tasks\HP Photo Creations Communicator.job --a-------- C:\ProgramData\HP Photo Creations\Communicator.exe [03/26/2013 08:02 PM]C:\WINDOWS\tasks\HPCeeScheduleForDave.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [07/15/2011 04:43 AM]C:\WINDOWS\tasks\PrintProjects Communicator.job --a-------- C:\ProgramData\PrintProjects\Communicator.exe [12/21/2013 03:42 PM]C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [08/24/2012 02:38 AM]==== Other Scheduled Tasks ======================"C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]"C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe]"C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]"C:\WINDOWS\SysNative\tasks\HP Photo Creations Communicator" [C:\ProgramData\HP Photo Creations\Communicator.exe]"C:\WINDOWS\SysNative\tasks\HPCeeScheduleForDave" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe]"C:\WINDOWS\SysNative\tasks\LAUNCH CDPCO" [C:\Program Files (x86)\USTechSupport\PC Optimizer\USTSPCO.exe]"C:\WINDOWS\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe]"C:\WINDOWS\SysNative\tasks\PrintProjects Communicator" [C:\ProgramData\PrintProjects\Communicator.exe]"C:\WINDOWS\SysNative\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe]"C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]"C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]"C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe]"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{46B47638-2502-497D-8CC1-2C969B303C86}" [C:\Windows\system32\msfeedssync.exe]"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{49D05411-CAF0-410C-AA14-1BED537C90A2}" [C:\Windows\system32\msfeedssync.exe]"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{6734F1F0-3039-47CD-A28F-2E62C34206E1}" [C:\Windows\system32\msfeedssync.exe]"C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]==== Firefox Extensions Registry ======================[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]"{0FAA5C82-A094-4541-8811-D3361F972A81}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [04/05/2014 02:46 PM]==== Firefox Extensions ======================ProfilePath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default- Undetermined - %ProfilePath%\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}==== Firefox Plugins ======================Profilepath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\rt286xcf.default3D3CAF586124C4E8102764C8B3063BB6 - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director1B05342DC6A8896A90952AF2084620F5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll - RocketLife Secure Plug-In Layer==== Fake Chromium Profiles Check ======================Fake profile C:\Users\Administrator\AppData\Local\Torch deletedFake profile C:\Users\Administrator\AppData\Local\Google\Chrome deletedFake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deletedFake profile C:\Users\Dave\AppData\Local\Torch deletedFake profile C:\Users\Dave\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\Dave\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\Dave\AppData\Local\Chromatic Browser deletedFake profile C:\Users\Guest\AppData\Local\Torch deletedFake profile C:\Users\Guest\AppData\Local\Google\Chrome deletedFake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\Guest\AppData\Local\Chromatic Browser deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted==== Chromium Look ======================HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensionsblklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[03/15/2014 02:22 AM]mmlkabjddkpgkgfhdhpimhcbonapngoh - C:\Users\Dave\AppData\Local\CRE\mmlkabjddkpgkgfhdhpimhcbonapngoh.crx[]pelmeidfhdlhlbjimpabfcbnnojbboma - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx[]pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensionsblklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]Google Drive - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalfYouTube - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeocosstminn - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfgGoogle Search - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpfGoogle Wallet - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmiedaGmail - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaediaGoogle Docs - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokakeGoogle Drive - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalfYouTube - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeoGoogle Search - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpfChrome In-App Payments service - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmiedaGmail - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaediaInternetHelper3 - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp==== Chromium Startpages ======================C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Preferences"startup_urls": [ "http://groovorio.com/?f=7&a=grv_tuto2_14_30&cd=2XzuyEtN2Y1L1Qzu0Czz0C0B0Bzz0BtDyC0CyEyEtAyEyD0FtN0D0Tzu0SzyyDyBtN1L2XzutBtFtBtCtFtCzztFtAtN1L1Czu1N1C2X1V2Z2Y2Z1FtB1VtCyE1VtAtDtN1L1G1B1V1N2Y1L1Qzu2SyC0B0F0DyEyDtCyCtGtAtDzy0CtG0ByD0AtCtG0F0F0C0BtGyBtAyB0EyBtB0A0C0E0CtD0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0D0C0EtA0AzztGtDtC0FyBtG0Bzy0A0BtG0C0DyE0AtGyD0D0DzzyE0B0EyC0EyBtBzz2Q&cr=157610599&ir=", "http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX" ],==== Chromium Fix ======================C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage-journal deleted successfullyC:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pnjnnnhampgflieglcelomcofocioegp deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfg deleted successfully==== Set IE to Default ======================Old Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]"Default_Page_URL"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX"[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}""Default_Page_URL"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Start Page"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Search Page"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}"[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}""Default_Page_URL"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Start Page"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Search Page"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}"New Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157""Start Page"="http://www.google.com"[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896""Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896""Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157""Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896""Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896""Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157""Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"==== All HKCU SearchScopes ======================HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"==== Deleting CLSID Registry Keys ======================HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfullyHKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfullyHKEY_CLASSES_ROOT\Wow6432Node\CLSID\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully==== Deleting CLSID Registry Values ========================== Reset IE Proxy ======================Value(s) before fix:"ProxyServer"="http=127.0.0.1:13918;https=127.0.0.1:13918""ProxyOverride"="<-loopback>""ProxyEnable"=dword:00000001Value(s) after fix:"ProxyEnable"=dword:00000000==== Deleting Registry Keys ======================HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mmlkabjddkpgkgfhdhpimhcbonapngoh deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfullyHKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfullyHKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfullyHKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully==== Empty IE Cache ======================C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfullyC:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfullyC:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\Users\Default User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully==== Empty FireFox Cache ======================No FireFox Cache found==== Empty Chrome Cache ======================C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfullyC:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully==== Empty All Flash Cache ======================Flash Cache Emptied Successfully==== Empty All Java Cache ======================Java Cache cleared successfully==== C:\zoek_backup content ======================C:\zoek_backup (files=1070 folders=347 52396145 bytes)==== Empty Temp Folders ======================C:\Users\Dave\AppData\Local\Temp will be emptied at rebootC:\Users\Default\AppData\Local\Temp emptied successfullyC:\Users\Default User\AppData\Local\Temp emptied successfullyC:\Users\TEMP\AppData\Local\Temp emptied successfullyC:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfullyC:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfullyC:\WINDOWS\Temp will be emptied at reboot==== After Reboot ========================== Empty Temp Folders ======================C:\WINDOWS\Temp successfully emptiedC:\Users\Dave\AppData\Local\Temp successfully emptied==== Empty Recycle Bin ======================C:\$RECYCLE.BIN successfully emptied==== EOF on Sun 11/09/2014 at 18:53:48.72 ======================
-
Zoek.exe v5.0.0.0 Updated 09-November-2014Tool run by Dave on Sun 11/09/2014 at 16:58:58.24.Microsoft Windows 8.1 6.3.9600 x64Running in: Normal Mode Internet Access DetectedLaunched: C:\Users\Dave\Downloads\zoek\zoek.exe [scan all users] [Quick Scan] [Auto Clean]==== System Restore Info ======================11/9/2014 5:03:55 PM Zoek.exe System Restore Point Created Succesfully.==== Empty Folders Check ======================C:\PROGRA~2\predm deleted successfullyC:\PROGRA~2\VNT deleted successfullyC:\PROGRA~2\COMMON~1\supportdotcom deleted successfullyC:\PROGRA~2\COMMON~1\SWF Studio deleted successfullyC:\PROGRA~2\COMMON~1\Symantec Shared deleted successfullyC:\PROGRA~3\cosstminn deleted successfullyC:\PROGRA~3\Oracle deleted successfullyC:\Users\Dave\AppData\Roaming\Activeris deleted successfullyC:\Users\Dave\AppData\Local\CrashDumps deleted successfullyC:\Users\Dave\AppData\Local\VisualBeeExe deleted successfullyC:\Users\Dave\AppData\Local\WordOv deleted successfully==== Deleting CLSID Registry Keys ======================HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6} deleted successfully==== Deleting CLSID Registry Values ========================== Deleting Services ========================== Deleting Files \ Folders ======================C:\Users\Dave\AppData\LocalLow\{84A16F3D-D897-5769-5232-703FC5F4369F} deletedC:\PROGRA~2\cosstminn deletedC:\PROGRA~2\Mozilla Firefox\browser\nsprotector.js deletedC:\PROGRA~2\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml deletedC:\PROGRA~2\Mozilla Firefox\browser\searchplugins\sweettunes_search.xml deletedC:\PROGRA~2\The Weather Channel deletedC:\PROGRA~2\Yahoo! deletedC:\PROGRA~2\Optimizer Pro deletedC:\PROGRA~2\MyPC Backup deletedC:\PROGRA~2\AskPartnerNetwork deletedC:\Users\Dave\AppData\Roaming\WB.CFG deletedC:\Users\Dave\AppData\Roaming\Yahoo! deletedC:\PROGRA~3\AskPartnerNetwork deletedC:\PROGRA~3\APN deletedC:\PROGRA~3\VisualBee deletedC:\PROGRA~3\AVG SafeGuard toolbar deletedC:\Users\Dave\AppData\Local\BrowserSafeguard deletedC:\Users\Dave\AppData\Local\Systweak deletedC:\Users\Dave\AppData\Local\AVG SafeGuard toolbar deletedC:\Users\Dave\AppData\Local\emaze deletedC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx deletedC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data-journal deletedC:\Users\TEMP\AppData\Local\AVG SafeGuard toolbar deletedC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deletedC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 deletedC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deletedC:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk deletedC:\WINDOWS\SysNative\roboot64.exe deletedC:\Users\Dave\AppData\LocalLow\AVG SafeGuard toolbar deletedC:\Users\TEMP\AppData\LocalLow\AVG SafeGuard toolbar deletedC:\WINDOWS\tasks\Groovorio Updater.job deletedC:\windows\SysNative\tasks\USTSPCO-USTSPCOOneClickCare deletedC:\WINDOWS\tasks\USTSPCO-USTSPCOOneClickCare.job deletedC:\components deletedC:\WINDOWS\SysNative\config\systemprofile\Searches deletedC:\windows\SysNative\GroupPolicy\Machine deletedC:\windows\SysNative\GroupPolicy\User deletedC:\windows\SysNative\GroupPolicy\GPT.INI deletedC:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deletedC:\WINDOWS\SysWow64\searchplugins deletedC:\WINDOWS\SysWow64\Extensions deletedC:\Users\Dave\Documents\Optimizer Pro deleted"C:\PROGRA~3\ab34c546d7769ac4\{CE681A67-9477-CBE6-EB9D-FE534875F98D}.20140808113335" deleted"C:\PROGRA~3\ab34c546d7769ac4" deleted"C:\Users\Dave\AppData\Roaming\Temp" deleted==== Files Recently Created / Modified ============================ C:\WINDOWS ========== C:\Users\Dave\AppData\Local\Temp ========== Java Cache =========== C:\WINDOWS\SysWOW64 =====2014-11-02 15:53:26 B9F9FD6188CC732F19DB69CAE5CC597C 272808 ----a-w- C:\WINDOWS\SysWOW64\javaws.exe2014-11-02 15:52:27 8FA677D5F2AFE2A3F111C50D68A93542 98216 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll2014-11-02 15:52:27 3594C0ABBFFE10B3CF95714B8B3C89A4 175528 ----a-w- C:\WINDOWS\SysWOW64\javaw.exe2014-11-02 15:52:27 095826BCBBFA5C09C72463A82612B23C 175528 ----a-w- C:\WINDOWS\SysWOW64\java.exe====== C:\WINDOWS\SysWOW64\drivers =========== C:\WINDOWS\Sysnative =========== C:\WINDOWS\Sysnative\drivers =====2014-10-15 02:34:50 87F3713E620F62D243A82B3CB66CBDDE 2498880 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys2014-10-15 02:34:37 329FEB41BBE82FBBD9BD69547BA1CB82 428864 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS====== C:\WINDOWS\Tasks ============ C:\WINDOWS\Temp ============= C:\Program Files ============ C:\PROGRA~2 =====2014-11-02 15:51:48 -------- d-----w- C:\PROGRA~2\Java======= C: =========== C:\Users\Dave\AppData\Roaming ============ C:\Users\Dave ======2014-11-02 18:25:11 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp2014-11-02 15:52:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java2014-10-25 01:28:36 -------- d-----w- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7====== C: exe-files ===== C: other files ====== Startup Registry Enabled ======================[HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Run]"TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun""CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R""RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe""HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe""APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe""HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe""Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe""TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe -osboot""QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime""iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe""SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]"TWC.Win7"="C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe"==== Startup Registry Enabled x64 ======================[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe ""SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]"NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update"==== Startup Folders ======================2014-05-04 18:29:12 1096 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk2013-01-07 19:21:07 1239 ----a-w- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk2013-03-17 22:43:48 2099 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk2012-12-28 01:12:20 2015 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk2014-04-05 21:43:33 1236 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk==== Task Scheduler Jobs ======================C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/09/2014 01:14 PM]C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe []C:\WINDOWS\tasks\HP Photo Creations Communicator.job --a-------- C:\ProgramData\HP Photo Creations\Communicator.exe [03/26/2013 08:02 PM]C:\WINDOWS\tasks\HPCeeScheduleForDave.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [07/15/2011 04:43 AM]C:\WINDOWS\tasks\PrintProjects Communicator.job --a-------- C:\ProgramData\PrintProjects\Communicator.exe [12/21/2013 03:42 PM]C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [08/24/2012 02:38 AM]==== Other Scheduled Tasks ======================"C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]"C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe]"C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]"C:\WINDOWS\SysNative\tasks\HP Photo Creations Communicator" [C:\ProgramData\HP Photo Creations\Communicator.exe]"C:\WINDOWS\SysNative\tasks\HPCeeScheduleForDave" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe]"C:\WINDOWS\SysNative\tasks\LAUNCH CDPCO" [C:\Program Files (x86)\USTechSupport\PC Optimizer\USTSPCO.exe]"C:\WINDOWS\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe]"C:\WINDOWS\SysNative\tasks\PrintProjects Communicator" [C:\ProgramData\PrintProjects\Communicator.exe]"C:\WINDOWS\SysNative\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe]"C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]"C:\WINDOWS\SysNative\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2989837996-1790684633-2971567215-1002" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe]"C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe]"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{46B47638-2502-497D-8CC1-2C969B303C86}" [C:\Windows\system32\msfeedssync.exe]"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{49D05411-CAF0-410C-AA14-1BED537C90A2}" [C:\Windows\system32\msfeedssync.exe]"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{6734F1F0-3039-47CD-A28F-2E62C34206E1}" [C:\Windows\system32\msfeedssync.exe]"C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]==== Firefox Extensions Registry ======================[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]"{0FAA5C82-A094-4541-8811-D3361F972A81}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [04/05/2014 02:46 PM]==== Firefox Extensions ======================ProfilePath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default- Undetermined - %ProfilePath%\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}==== Firefox Plugins ======================Profilepath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\rt286xcf.default3D3CAF586124C4E8102764C8B3063BB6 - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director1B05342DC6A8896A90952AF2084620F5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll - RocketLife Secure Plug-In Layer==== Fake Chromium Profiles Check ======================Fake profile C:\Users\Administrator\AppData\Local\Torch deletedFake profile C:\Users\Administrator\AppData\Local\Google\Chrome deletedFake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deletedFake profile C:\Users\Dave\AppData\Local\Torch deletedFake profile C:\Users\Dave\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\Dave\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\Dave\AppData\Local\Chromatic Browser deletedFake profile C:\Users\Guest\AppData\Local\Torch deletedFake profile C:\Users\Guest\AppData\Local\Google\Chrome deletedFake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\Guest\AppData\Local\Chromatic Browser deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deletedFake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted==== Chromium Look ======================HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensionsblklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[03/15/2014 02:22 AM]mmlkabjddkpgkgfhdhpimhcbonapngoh - C:\Users\Dave\AppData\Local\CRE\mmlkabjddkpgkgfhdhpimhcbonapngoh.crx[]pelmeidfhdlhlbjimpabfcbnnojbboma - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx[]pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensionsblklojfklgnogjaijkibhfjepakiocng - C:\Users\Dave\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx[]blmchfpimpbbdmgpcieclabeafkljbhm - No path found[]pnjnnnhampgflieglcelomcofocioegp - C:\Users\Dave\AppData\Local\CRE\pnjnnnhampgflieglcelomcofocioegp.crx[]Google Drive - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalfYouTube - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeocosstminn - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfgGoogle Search - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpfGoogle Wallet - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmiedaGmail - Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaediaGoogle Docs - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokakeGoogle Drive - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalfYouTube - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeoGoogle Search - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpfChrome In-App Payments service - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmiedaGmail - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaediaInternetHelper3 - TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp==== Chromium Startpages ======================C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Preferences"startup_urls": [ "http://groovorio.com/?f=7&a=grv_tuto2_14_30&cd=2XzuyEtN2Y1L1Qzu0Czz0C0B0Bzz0BtDyC0CyEyEtAyEyD0FtN0D0Tzu0SzyyDyBtN1L2XzutBtFtBtCtFtCzztFtAtN1L1Czu1N1C2X1V2Z2Y2Z1FtB1VtCyE1VtAtDtN1L1G1B1V1N2Y1L1Qzu2SyC0B0F0DyEyDtCyCtGtAtDzy0CtG0ByD0AtCtG0F0F0C0BtGyBtAyB0EyBtB0A0C0E0CtD0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0D0C0EtA0AzztGtDtC0FyBtG0Bzy0A0BtG0C0DyE0AtGyD0D0DzzyE0B0EyC0EyBtBzz2Q&cr=157610599&ir=", "http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX" ],==== Chromium Fix ======================C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.scrabblefinder.com_0.localstorage-journal deleted successfullyC:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pnjnnnhampgflieglcelomcofocioegp deleted successfullyC:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnaiikenilbilljeemeemhdhfecipfg deleted successfully==== Set IE to Default ======================Old Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]"Default_Page_URL"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX"[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}""Default_Page_URL"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Start Page"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Search Page"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}"[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}""Default_Page_URL"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Start Page"="http://www.istart123.com/?type=hp&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX""Search Page"="http://www.istart123.com/web/?type=ds&ts=1407519110&from=tugs&uid=HitachiXHTS543232A7A384_E2P342BL0L92XP0L92XPX&q={searchTerms}"New Values:[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157""Start Page"="http://www.google.com"[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896""Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896""Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157""Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896""Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896""Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157""Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"==== All HKCU SearchScopes ======================HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"==== Deleting CLSID Registry Keys ======================HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfullyHKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfullyHKEY_CLASSES_ROOT\Wow6432Node\CLSID\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84A16F3D-D897-5769-5232-703FC5F4369F} deleted successfully==== Deleting CLSID Registry Values ========================== Reset IE Proxy ======================Value(s) before fix:"ProxyServer"="http=127.0.0.1:13918;https=127.0.0.1:13918""ProxyOverride"="<-loopback>""ProxyEnable"=dword:00000001Value(s) after fix:"ProxyEnable"=dword:00000000==== Deleting Registry Keys ======================HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mmlkabjddkpgkgfhdhpimhcbonapngoh deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma deleted successfullyHKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfullyHKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blklojfklgnogjaijkibhfjepakiocng deleted successfullyHKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm deleted successfullyHKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\pnjnnnhampgflieglcelomcofocioegp deleted successfully==== Empty IE Cache ======================C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfullyC:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\Users\Dave\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfullyC:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\Users\Default User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfullyC:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully==== Empty FireFox Cache ======================No FireFox Cache found==== Empty Chrome Cache ======================C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfullyC:\Users\TEMP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully==== Empty All Flash Cache ======================Flash Cache Emptied Successfully==== Empty All Java Cache ======================Java Cache cleared successfully==== C:\zoek_backup content ======================C:\zoek_backup (files=1070 folders=347 52396145 bytes)==== Empty Temp Folders ======================C:\Users\Dave\AppData\Local\Temp will be emptied at rebootC:\Users\Default\AppData\Local\Temp emptied successfullyC:\Users\Default User\AppData\Local\Temp emptied successfullyC:\Users\TEMP\AppData\Local\Temp emptied successfullyC:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfullyC:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfullyC:\WINDOWS\Temp will be emptied at reboot==== After Reboot ========================== Empty Temp Folders ======================C:\WINDOWS\Temp successfully emptiedC:\Users\Dave\AppData\Local\Temp successfully emptied==== Empty Recycle Bin ======================C:\$RECYCLE.BIN successfully emptied==== EOF on Sun 11/09/2014 at 18:53:48.72 ======================
-
Needing help again sir
-
Thanks Chuck it is running better I will spread the word for you
-
All processes killed========== OTL ==========HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.Registry key HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.Registry value HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect deleted successfully.Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\cdo\ deleted successfully.File Protocol\Handler\cdo - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.File Protocol\Handler\msdaipp - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap\ deleted successfully.File Protocol\Handler\mso-offdap - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.File Protocol\Handler\skype4com - No CLSID value found not found.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.File Protocol\Handler\wlpg - No CLSID value found not found.64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages:livessp deleted successfully.Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\ deleted successfully.Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\ not found.========== COMMANDS ==========[EMPTYJAVA]User: All UsersUser: DaveUser: DefaultUser: Default UserUser: PublicUser: TEMPTotal Java Files Cleaned = 0.00 mb[EMPTYFLASH]User: All UsersUser: Dave->Flash cache emptied: 8876 bytesUser: DefaultUser: Default UserUser: PublicUser: TEMPTotal Flash Files Cleaned = 0.00 mb[EMPTYTEMP]User: All UsersUser: Dave->Temp folder emptied: 5006567 bytes->Temporary Internet Files folder emptied: 5584144 bytes->FireFox cache emptied: 0 bytes->Google Chrome cache emptied: 287090024 bytes->Flash cache emptied: 0 bytesUser: Default->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytesUser: Default User->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytesUser: PublicUser: TEMP->Temp folder emptied: 40362572 bytes->Temporary Internet Files folder emptied: 128 bytes->FireFox cache emptied: 28999173 bytes->Google Chrome cache emptied: 10785735 bytes%systemdrive% .tmp files removed: 0 bytes%systemroot% .tmp files removed: 0 bytes%systemroot%\System32 .tmp files removed: 0 bytes%systemroot%\System32 (64bit) .tmp files removed: 0 bytes%systemroot%\System32\drivers .tmp files removed: 0 bytesWindows Temp folder emptied: 331746736 bytes%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytesRecycleBin emptied: 0 bytesTotal Files Cleaned = 677.00 mbC:\Windows\System32\drivers\etc\Hosts moved successfully.HOSTS file reset successfullyRestore point Set: OTL Restore PointOTL by OldTimer - Version 3.2.69.0 log created on 11022013_094523Files\Folders moved on Reboot...File move failed. C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca2c not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca2e not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca2f not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca30 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca31 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca32 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca33 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca34 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca37 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca45 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca46 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca47 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca48 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca49 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca4a not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca4b not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00ca4c not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc39 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3a not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3b not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3c not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3d not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3e not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc3f not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc40 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc41 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc42 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc43 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc44 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc45 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc46 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc47 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc48 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc49 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4a not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4b not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4c not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4d not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4e not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc4f not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc50 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc51 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc52 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc53 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc54 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc55 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc56 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc57 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc58 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc59 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc5a not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc5b not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cc5c not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf26 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf27 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf28 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf29 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2a not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2b not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2c not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2d not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2e not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf2f not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf30 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf31 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf32 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf33 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf34 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf35 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf36 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf37 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf38 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf39 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3a not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3b not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3c not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3d not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3e not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf3f not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf40 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf41 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf42 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf43 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf44 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf45 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf46 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf47 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf48 not found!File\Folder C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00cf49 not found!PendingFileRenameOperations files...Registry entries deleted on Reboot...
-
Chuck sorry I have been working a bunch I hope I can get to this tomorrow night if not then Saturday right now I just checked my email and am headed to bed thanks
Dave
-
OTL Extras logfile created on: 10/27/2013 10:14:54 PM - Run 1OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dave\Downloads64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstationInternet Explorer (Version = 9.10.9200.16721)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy3.60 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 63.95% Memory free4.22 Gb Paging File | 2.75 Gb Available in Paging File | 65.12% Paging File freePaging file location(s): ?:\pagefile.sys [binary data]%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)Drive C: | 276.00 Gb Total Space | 216.80 Gb Free Space | 78.55% Space Free | Partition Type: NTFSDrive D: | 21.33 Gb Total Space | 2.62 Gb Free Space | 12.28% Space Free | Partition Type: NTFSComputer Name: LAPTOP | User Name: Dave | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All users | Include 64bit ScansCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 180 Days========== Extra Registry (SafeList) ==================== File Associations ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation).url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation).html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)========== Shell Spawning ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*exefile [open] -- "%1" %*helpfile [open] -- Reg Error: Key error.htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [explore] -- Reg Error: Value error.Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)exefile [open] -- "%1" %*helpfile [open] -- Reg Error: Key error.htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- "C:\Program Files (x86)\File Scout\filescout.exe" /open "%1"Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [explore] -- Reg Error: Value error.Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.========== Security Center Settings ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"cval" = 164bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]"AntiVirusOverride" = 0"AntiSpywareOverride" = 0"FirewallOverride" = 064bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]========== Firewall Settings ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]"EnableFirewall" = 1"DisableNotifications" = 0[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall" = 1"DisableNotifications" = 0[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]"EnableFirewall" = 1"DisableNotifications" = 0========== Authorized Applications List ==================== Vista Active Open Ports Exception List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]"{43B3AACF-45EB-4B05-AA02-B3077FFCDE9C}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |"{51D9E665-683E-4856-ADC8-D9292260C609}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |"{6B288D59-35D7-4560-8063-5E2D274490CA}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |"{910AE036-C75B-4250-9F09-A9448E203513}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |"{B803DC99-019C-400E-8B42-BCF98DD0CBC3}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |========== Vista Active Application Exception List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]"{03DBB28F-E233-4534-972D-69CF6C13A413}" = dir=in | name=hp+ |"{07531A7F-0AE1-49FF-B287-397F55CA06B4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |"{07AAE2C5-14EE-4CDF-84DB-02FC86A4A54C}" = dir=out | name=netflix |"{0DD3F581-C76D-4528-A0EF-67F710C2E826}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |"{0FD14463-2202-4FA6-9129-9BFD7779AB93}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe |"{151668CE-44AB-44CF-9EE6-15195BB90226}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |"{191487FE-D290-4C6D-BE29-896BB8402A76}" = dir=out | name=windows_ie_ac_001 |"{19711016-E1A8-48F7-BB52-ABFB014C8FCC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe |"{198DB91B-EDB0-42ED-B38C-1B759757FC72}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |"{1C0E78D2-1D6D-45D2-AD96-F50715921004}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |"{1F270FBB-6CBB-4DBA-8B78-EE7BDD64FFFB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |"{20582113-2722-47BD-82E9-DD4AF1B24525}" = dir=out | name=easy diy |"{26016C1A-DC13-4A7A-B87D-7B35A6BD15EF}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe |"{267FB111-1BE4-4BC4-A8E4-7DE19B86329C}" = dir=out | name=ebay |"{26E34F31-158D-4098-BF23-BE810C493A86}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |"{28BD95FB-FCD5-4BB2-8A21-272E74BBB609}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe |"{2CC191C4-E30C-4F8F-A177-79DEDF5C85D1}" = dir=out | name=iheartradio |"{2E225E47-F63B-4BCB-9A3D-00D39F537A42}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |"{36ECDF71-DC35-466B-8B5C-0B17108DD969}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |"{37DB58ED-91B7-4532-884D-9D9528B6C226}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |"{381C99C7-DC03-4A2A-BECC-B26826D14E88}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |"{3850A51C-1A27-489F-9EA1-D872216A076D}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |"{3A57F579-7DE1-4B05-99FA-AD54182A832C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |"{43184DE2-7AED-4BCB-9A40-C9A580C2B612}" = dir=out | name=hp printer control |"{44B8C1FC-99FB-4C51-B30C-FBA4017793DC}" = dir=in | name=hp printer control |"{476B597A-E6B7-437F-9091-2D4C1DA0C5B3}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |"{4F9777AB-DB6C-4CF3-B207-BA1DB676B171}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |"{546608D9-4876-4F81-8BE8-58CC4BF78D42}" = dir=in | name=ebay |"{59C27785-55AE-40E7-983C-919377142F37}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |"{6B371E8F-FFC4-4EAD-BBA6-6B48456CE480}" = dir=out | name=hp registration |"{6B5C7923-3D9E-4111-AF91-8D364EA55128}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |"{781B4773-97FE-4F90-883D-1C9DA4C1948D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |"{78C9C4E2-3A66-4322-8804-06EC7FF38E8E}" = dir=out | name=norton studio |"{82EC8B0A-751F-454C-A5BD-E8A39F8F7831}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe |"{837481C4-6BE3-4724-93DE-04344545E1BD}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe |"{87D56309-C907-4C96-945B-71A72AA371B9}" = dir=out | name=hp connected photo powered by snapfish |"{8A0F0DBE-48D9-4A52-B212-2AF7B1462902}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe |"{8DE79230-48B9-4691-A167-9C8AC4F65C19}" = dir=in | name=hp connected photo powered by snapfish |"{90142915-B93E-41C2-9F1A-9D272D70F90D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |"{91D585D5-C91F-42C4-9111-126554242621}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |"{91E1FA52-1AC5-43D9-9ED7-12318E3648CF}" = dir=out | name=getting started with windows 8 |"{934CFA53-948E-4868-8CD5-F12B9FC6BDB2}" = dir=out | name=finance helper |"{9D26F191-F22A-4E94-B64C-5BFD0E9E282F}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe |"{9F802A4A-A96B-4965-9C19-1B48DA693464}" = dir=out | name=work it out |"{A10B8D24-5239-44DA-B105-FBDD917A39C1}" = dir=out | name=microsoft solitaire collection |"{AB35DE72-4497-4541-A06D-A39BA2EF5DB7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |"{B03CADAD-F714-4A36-B91F-DB49D0F75948}" = dir=out | name=pinball fx2 |"{B94560A9-131A-4CA8-8BC0-F49745D77A16}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |"{CF960A71-2A1C-4184-BC65-7C3B00F1955A}" = dir=in | name=pinball fx2 |"{D074B610-22D4-42B3-9A6C-471DC129952D}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |"{D77152BF-8A9E-4CD9-9179-B0DC5CD975FD}" = dir=in | app=c:\users\dave\appdata\local\temp\7zs00d5\setup\hpznui40.exe |"{DC56DC94-2D87-496C-AEF8-17F9652D991C}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |"{DE25D9F1-4D02-4BFC-8057-DB37FA61FF65}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |"{E22C0720-45A7-42C8-865D-54F55AADEA4E}" = dir=out | name=microsoft mahjong |"{E6FFBC3C-DB39-499E-831E-E2E100C3763F}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |"{ED1DDEB0-C97C-4EB1-85CC-1144FA582B72}" = dir=out | name=hp+ |"{EDA11C8E-7185-4EE7-A505-1B884A0E750A}" = dir=out | name=kindle |"{F567D314-85D4-42BF-9EEB-A84F29E00BEE}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |"{FBDA0F67-9F61-4A3F-B726-236DA16A646B}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe |========== HKEY_LOCAL_MACHINE Uninstall List ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt"{0FA995CC-C849-4755-B14B-5404CC75DC24}" = Energy Star"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables"{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}" = Apple Mobile Device Support"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148"{4FF9E8AA-D554-4CE7-89F9-B69DAA5A1E98}" = AVG 2013"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161"{63ADEC24-A374-80A8-E89B-BE401C787F75}" = AMD Catalyst Install Manager"{6B02D047-A56D-4994-B1F1-53DA6B9885AB}" = AVG 2013"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64"{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting"{A535111D-95C8-487F-869E-CE4C239972D2}" = iTunes"{A79A9231-0A5A-9384-21D0-DB753C2BE59B}" = AMD Fuel"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319"{E3047FA0-2D6B-4BD6-8CD4-599955F1CE9D}" = Microsoft Mouse and Keyboard Center"{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}" = HP Registration Service"{E82EC5DF-28FD-C8F4-ED08-B88728158260}" = ccc-utility64"{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}" = iCloud"{F089B734-1356-484F-A7B8-1B78F1616A15}" = HP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer"AVG" = AVG 2013"HP Imaging Device Functions" = HP Imaging Device Functions 14.0"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0"HPExtendedCapabilities" = HP Customer Participation Program 14.0"HPOCR" = OCR Software by I.R.I.S. 14.0"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center"Shop for HP Supplies" = Shop for HP Supplies"SynTPDeinstKey" = Synaptics Pointing Device Driver[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{0123AB93-E7A4-7F40-83B6-41EC2CF84B3F}" = CCC Help Dutch"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer"{0C3B99D2-35D0-6993-3C4B-A759419A8678}" = CCC Help Korean"{0C57987A-A03A-4B95-A309-D23F78F406CA}" = HP Utility Center"{0DCCD5F4-29E7-4AA0-8C1D-F8E1503B91F4}" = Catalyst Control Center - Branding"{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP"{1225C0F8-AB1A-BE3A-CD0C-DB8CA1613940}" = CCC Help Greek"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148"{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox"{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery"{3C41A693-28E1-4335-A738-528B09DB600C}" = CCC Help Thai"{3C458872-A5BB-89F3-933C-2406F6D9E6F8}" = CCC Help Finnish"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skypeâ„¢ 6.1"{4ED7050C-9332-4FB2-AB07-E94F25A53D39}" = HP Quick Launch"{528AB81B-D65A-4AB0-A2B6-82B51A087D01}" = HP Recovery Manager"{52A3FC19-6F84-F293-08C6-80A1D2F7477F}" = CCC Help Swedish"{56BA241F-580C-43D2-8403-947241AAE633}" = center"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack"{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status"{5CD2FE1D-A3DB-F273-2798-EFAACF8492A5}" = CCC Help Portuguese"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM"{631EFC00-5A7A-4A90-9578-039EDA92DE0F}_is1" = AtHomeConnect version 1.0.1.0"{675D093B-815D-47FD-AB2C-192EC751E8E2}" = HP Software Framework"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE"{6A66D912-541C-54C6-43E6-17AF24700B91}" = CCC Help German"{6C8FF546-B0C0-0935-2F5E-7DC2DA727CFD}" = CCC Help Czech"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.0.0"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable"{734846E6-3E7A-04AC-0612-638A1D8A63F8}" = CCC Help Russian"{747F3993-036E-5F4F-1B82-7DA844B73966}" = Catalyst Control Center Localization All"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update"{793ED091-3F14-4968-3864-5C8A7727A5DA}" = CCC Help Chinese Standard"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver"{89D20029-0578-4D8D-979A-695C8D868868}" = H&R Block Deluxe + Efile 2012"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390R 802.11bgn Wi-Fi Adapter"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional"{9285EABA-D88C-4A8A-6E9D-5F55BF03E46F}" = Catalyst Control Center InstallProxy"{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker"{93EB60BA-458D-FBE6-E466-CD170080E719}" = CCC Help Polish"{941DE69D-6CEE-4171-8F1F-3D7E352AA498}" = HP Wireless Button Driver"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161"{9C0F4CBD-8543-96CC-46F1-75E57B1B22A6}" = Catalyst Control Center Graphics Previews Common"{9C35EDE5-4B0F-45E7-A438-314BA889948E}" = HP MyRoom"{9E50DEC9-081B-441F-B647-98DBEA8B01DD}" = CorelDRAW 10"{9EF69B68-6DFE-F916-2D6E-E486D21A26C2}" = CCC Help Spanish"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer"{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.05)"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update"{B1E7FE70-3B18-5BA2-8032-2547FC636A50}" = CCC Help Japanese"{B424890D-64FC-E0D1-4A17-4B512CA45CD9}" = CCC Help Italian"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime"{B8019B54-F9BE-490A-9619-6D06F18F129F}" = HP Support Assistant"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2"{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations"{BE64A239-E22E-9D77-AA57-36AE0443EC2F}" = CCC Help Chinese Traditional"{C045ED98-5FDB-45A0-AB48-C4B7560E7816}" = C309a"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint"{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform"{CF8C33C1-C978-527D-E0AF-530882DEB146}" = AMD VISION Engine Control Center"{D23CA718-0356-41F2-8E6A-B5C6CD383EF7}" = HP Documentation"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform"{D5DC9541-12F0-59CF-9430-1136D5A58BD0}" = CCC Help Hungarian"{D7FBE7DC-A18F-4DFF-80BB-A478E4E09CF7}" = CCC Help Danish"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq"{DC3C5C4A-1869-A99C-3AE4-55E0191105F0}" = CCC Help Norwegian"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio"{EB2CDF95-92D4-AC57-63B1-4E7F0BD8F9B8}" = CCC Help French"{ECA42F46-D80E-AD40-18FB-4BF64491CEE3}" = CCC Help English"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219"{FA0E7183-6B11-4899-B25F-2C490543967E}" = PS_AIO_05_C309_Software_Min"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials"{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr"{FF282A38-D10B-E302-FBAD-5903C9DD9A5B}" = CCC Help Turkish"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin"Adobe Shockwave Player" = Adobe Shockwave Player 11.6"AVG SafeGuard toolbar" = AVG SafeGuard toolbar"CorelDRAW 10" = CorelDRAW 10"Google Chrome" = Google Chrome"HP Photo Creations" = HP Photo Creations"IECT3311875" = SweetTunes Toolbar for IE"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam"InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10"InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD"InternetHelper3 Chrome Toolbar" = InternetHelper3 Chrome Toolbar"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300"McAfee Security Scan" = McAfee Security Scan Plus"PrintProjects" = PrintProjects"Rapport_msi" = Trusteer Endpoint Protection"RealPlayer 16.0" = RealPlayer"The Weather Channel App" = The Weather Channel App"WildTangent hp Master Uninstall" = HP Games"WildTangent wildgames Master Uninstall" = WildTangent Games"WinLiveSuite" = Windows Live Essentials"WTA-34a0f46f-2586-4346-812c-3e18d190d88a" = Luxor Evolved"WTA-3e034c4a-10db-4d90-986c-4ad842d30c78" = Polar Bowler"WTA-43d91043-ebc0-4697-8d3d-d2bc3c24954c" = Farm Frenzy"WTA-4685aa80-dc5b-4935-83fa-befd7b91e9f5" = Chuzzle Deluxe"WTA-4a27aa2d-9c25-4db9-98ad-36510c794c7f" = Cradle Of Egypt Collector's Edition"WTA-4a30ae7a-f08b-4f44-a12c-09edc11ad2a6" = Governor of Poker 2 Premium Edition"WTA-52d040ec-7135-4eec-9cd4-cdf2230564a1" = Mahjongg Dimensions Deluxe: Tiles in Time"WTA-5506661c-81d3-49e4-b2f9-072576c15d91" = Roads of Rome 3"WTA-5c01f4e4-2494-4342-bf09-6b5fba8368f5" = John Deere Drive Green"WTA-5e80cd2a-d654-401d-b385-74b579628353" = Jewel Match 3"WTA-715442b8-3be5-4073-9b0e-f41506dd2310" = Hoyle Card Games"WTA-7c7027da-bc2b-4364-af24-485d85da4b7b" = Final Drive Fury"WTA-83705bd4-8013-45e7-b430-3806a7dc4745" = Mortimer Beckett and the Crimson Thief Premium Edition"WTA-8ba64964-a6d3-492c-9d8f-02006b962c0c" = Vacation Questâ„¢ - Australia"WTA-9431f875-5fc4-41b0-8bbb-5a2107f43f7b" = Penguins!"WTA-973dfb2b-f35d-4000-af3a-be238aa6ef88" = Bejeweled 3"WTA-a86c3f90-cf5b-4c9f-8c9a-690d3045ff3d" = Peggle Nights"WTA-b08e9137-7fa1-480b-8f21-a404a4877e38" = Mystery P.I. - Curious Case of Counterfeit Cove"WTA-bd80f60a-4ecd-4a36-a634-a563d4b1e9de" = Polar Golfer"WTA-d76db04b-4e71-4bac-880c-969c2616d43d" = Tales of Lagoona"WTA-d8e241f0-1a03-4a4a-94d2-f0379e66bc9a" = FATE: The Cursed King"WTA-d9f2e693-20fd-4edf-99dd-54fc5c9567f9" = Build-a-lot 4 - Power Source"WTA-df35cdb0-0d63-4dfb-afa8-94429c4cf1f3" = Zuma's Revenge"WTA-e173b0c7-0897-4cc2-910e-53ef978247b4" = Cradle of Rome 2"WTA-fa24b63a-3a29-4c8b-9aeb-e1577cb8a12f" = 4 Elements II"WTA-fb2ce78a-3b49-4539-8948-b141dca7fa98" = FlatOut 2========== HKEY_USERS Uninstall List ==========[HKEY_USERS\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe" = SanDiskSecureAccess_Manager.exe========== Last 20 Event Log Errors ==========[ Application Events ]Error - 7/30/2013 11:11:16 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/30/2013 11:11:16 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/30/2013 11:12:09 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/30/2013 11:12:09 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/30/2013 3:56:56 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/30/2013 3:56:56 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/30/2013 10:30:31 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._pdl-datastream._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/30/2013 10:30:31 PM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Client application bug: DNSServiceResolve(Photosmart\032C309a\032series\032[4C3104]._scanner._tcp.local.)active for over two minutes. This places considerable burden on the network.Error - 7/31/2013 1:01:18 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Task Scheduling Error: Continuously busy for more than a secondError - 7/31/2013 1:01:18 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Task Scheduling Error: m->NextScheduledEvent 15506Error - 7/31/2013 1:01:18 AM | Computer Name = Laptop | Source = Bonjour Service | ID = 100Description = Task Scheduling Error: m->NextScheduledSPRetry 15506[ System Events ]Error - 10/5/2013 2:19:25 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034Description = The Rapport Management Service service terminated unexpectedly. Ithas done this 1 time(s).Error - 10/7/2013 9:54:59 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024Description = The AVGIDSAgent service terminated with the following service-specificerror: %%3758213659Error - 10/7/2013 9:55:27 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034Description = The AVG WatchDog service terminated unexpectedly. It has done this1 time(s).Error - 10/8/2013 11:15:49 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024Description = The AVGIDSAgent service terminated with the following service-specificerror: %%3758213659Error - 10/8/2013 11:16:20 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034Description = The AVG WatchDog service terminated unexpectedly. It has done this1 time(s).Error - 10/10/2013 5:19:29 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024Description = The AVGIDSAgent service terminated with the following service-specificerror: %%3758213659Error - 10/10/2013 5:20:01 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034Description = The AVG WatchDog service terminated unexpectedly. It has done this1 time(s).Error - 10/10/2013 5:22:17 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034Description = The Rapport Management Service service terminated unexpectedly. Ithas done this 1 time(s).Error - 10/15/2013 3:43:39 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7024Description = The AVGIDSAgent service terminated with the following service-specificerror: %%3758213659Error - 10/15/2013 3:44:11 PM | Computer Name = Laptop | Source = Service Control Manager | ID = 7034Description = The AVG WatchDog service terminated unexpectedly. It has done this1 time(s).< End of report >
-
OTL logfile created on: 10/27/2013 10:14:54 PM - Run 1OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dave\Downloads64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstationInternet Explorer (Version = 9.10.9200.16721)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy3.60 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 63.95% Memory free4.22 Gb Paging File | 2.75 Gb Available in Paging File | 65.12% Paging File freePaging file location(s): ?:\pagefile.sys [binary data]%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)Drive C: | 276.00 Gb Total Space | 216.80 Gb Free Space | 78.55% Space Free | Partition Type: NTFSDrive D: | 21.33 Gb Total Space | 2.62 Gb Free Space | 12.28% Space Free | Partition Type: NTFSComputer Name: LAPTOP | User Name: Dave | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All users | Include 64bit ScansCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 180 Days========== Processes (SafeList) ==========PRC - [2013/10/27 22:12:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dave\Downloads\OTL (1).comPRC - [2013/10/08 18:02:45 | 000,844,752 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exePRC - [2013/10/07 19:13:49 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exePRC - [2013/09/10 23:18:16 | 002,476,312 | ---- | M] (Trusteer Ltd.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exePRC - [2013/09/10 23:18:16 | 001,435,928 | ---- | M] (Trusteer Ltd.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exePRC - [2013/08/14 15:19:24 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exePRC - [2013/05/11 04:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exePRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exePRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exePRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exePRC - [2012/10/12 15:16:50 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exePRC - [2012/07/09 14:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exePRC - [2012/06/07 21:34:06 | 000,111,120 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exePRC - [2012/03/28 19:34:30 | 000,091,432 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exePRC - [2012/02/15 00:39:36 | 030,705,792 | ---- | M] (Gemalto N.V.) -- C:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exePRC - [2009/08/05 13:49:44 | 000,284,016 | ---- | M] (Eastman Kodak Company) -- C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe========== Modules (No Company Name) ==========MOD - [2013/10/08 18:02:43 | 000,415,184 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppgooglenaclpluginchrome.dllMOD - [2013/10/08 18:02:41 | 004,055,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dllMOD - [2013/10/08 18:01:50 | 000,698,832 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dllMOD - [2013/10/08 18:01:49 | 000,099,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dllMOD - [2013/10/08 18:01:47 | 001,604,560 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dllMOD - [2013/08/21 11:14:59 | 000,991,984 | ---- | M] () -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportMS.dllMOD - [2012/06/27 15:09:06 | 000,557,056 | ---- | M] () -- C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dllMOD - [2012/06/08 12:34:06 | 000,016,400 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dllMOD - [2012/06/07 21:34:06 | 000,627,216 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dllMOD - [2012/02/14 17:37:52 | 011,796,096 | ---- | M] () -- C:\Users\Dave\AppData\Roaming\SanDisk\My Vaults\dmBackup.dll========== Services (SafeList) ==========SRV:64bit: - [2013/08/15 23:39:26 | 002,371,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)SRV:64bit: - [2013/07/01 18:44:21 | 000,016,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)SRV:64bit: - [2013/06/24 16:54:45 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)SRV:64bit: - [2013/06/01 03:19:58 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)SRV:64bit: - [2013/05/29 20:47:42 | 000,322,048 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)SRV:64bit: - [2013/05/04 00:58:02 | 000,470,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)SRV:64bit: - [2013/05/04 00:57:05 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)SRV:64bit: - [2013/04/08 22:48:42 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)SRV:64bit: - [2013/03/01 20:45:07 | 000,171,008 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)SRV:64bit: - [2013/03/01 20:45:05 | 000,180,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)SRV:64bit: - [2013/01/09 17:23:16 | 001,964,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)SRV:64bit: - [2013/01/09 17:22:35 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)SRV:64bit: - [2012/11/05 22:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)SRV:64bit: - [2012/09/20 00:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)SRV:64bit: - [2012/08/06 13:08:48 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)SRV:64bit: - [2012/08/02 03:06:02 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)SRV:64bit: - [2012/07/25 21:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)SRV:64bit: - [2012/07/25 21:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)SRV:64bit: - [2012/07/25 21:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)SRV:64bit: - [2012/07/25 21:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)SRV:64bit: - [2012/07/25 21:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)SRV:64bit: - [2012/07/25 21:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)SRV:64bit: - [2012/07/25 21:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)SRV:64bit: - [2012/07/25 21:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)SRV:64bit: - [2012/07/25 21:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)SRV:64bit: - [2012/07/25 21:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)SRV:64bit: - [2012/07/25 18:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)SRV - [2013/10/08 19:13:28 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)SRV - [2013/09/10 23:18:16 | 001,435,928 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)SRV - [2013/08/14 15:19:24 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)SRV - [2013/07/23 19:09:28 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd)SRV - [2013/07/04 15:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)SRV - [2013/05/11 04:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)SRV - [2013/02/05 09:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)SRV - [2013/01/08 13:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)SRV - [2012/11/05 22:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)SRV - [2012/08/10 18:53:44 | 000,085,504 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)SRV - [2012/07/25 21:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)SRV - [2012/07/25 21:18:41 | 000,408,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)SRV - [2012/07/25 21:17:52 | 000,060,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)SRV - [2012/07/13 19:02:16 | 002,451,456 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)SRV - [2012/07/09 14:40:02 | 000,035,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)SRV - [2011/08/18 01:29:52 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)SRV - [2009/08/05 13:49:44 | 000,284,016 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe -- (Kodak AiO Network Discovery Service)========== Driver Services (SafeList) ==========DRV:64bit: - [2013/09/10 23:18:30 | 000,266,928 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RapportHades64.sys -- (RapportHades64)DRV:64bit: - [2013/09/10 23:18:28 | 000,295,696 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RapportKE64.sys -- (RapportKE64)DRV:64bit: - [2013/08/15 23:41:13 | 000,058,200 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)DRV:64bit: - [2013/07/20 01:51:00 | 000,311,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgloga.sys -- (Avgloga)DRV:64bit: - [2013/07/20 01:50:56 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\Drivers\avgidsdrivera.sys -- (AVGIDSDriver)DRV:64bit: - [2013/07/20 01:50:56 | 000,071,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgidsha.sys -- (AVGIDSHA)DRV:64bit: - [2013/07/20 01:50:50 | 000,206,648 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\SysNative\Drivers\avgldx64.sys -- (Avgldx64)DRV:64bit: - [2013/07/10 01:32:38 | 000,045,880 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgrkx64.sys -- (Avgrkx64)DRV:64bit: - [2013/07/09 02:04:07 | 000,120,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)DRV:64bit: - [2013/07/09 01:28:50 | 000,248,632 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgwfpa.sys -- (Avgwfpa)DRV:64bit: - [2013/07/01 19:41:47 | 000,447,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)DRV:64bit: - [2013/07/01 19:41:47 | 000,337,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)DRV:64bit: - [2013/07/01 19:41:47 | 000,213,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)DRV:64bit: - [2013/07/01 18:44:14 | 000,036,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)DRV:64bit: - [2013/07/01 16:08:49 | 000,247,216 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)DRV:64bit: - [2013/07/01 01:45:28 | 000,116,536 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgmfx64.sys -- (Avgmfx64)DRV:64bit: - [2013/06/29 00:15:54 | 000,195,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)DRV:64bit: - [2013/06/10 15:17:46 | 000,096,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)DRV:64bit: - [2013/05/31 21:08:57 | 000,037,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)DRV:64bit: - [2013/05/29 20:47:43 | 000,542,208 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\stwrt64.sys -- (STHDA)DRV:64bit: - [2013/05/13 15:36:06 | 000,050,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\point64.sys -- (Point64)DRV:64bit: - [2013/05/06 08:32:28 | 000,076,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\dc3d.sys -- (dc3d)DRV:64bit: - [2013/05/04 01:34:15 | 000,284,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)DRV:64bit: - [2013/04/15 07:02:04 | 002,482,960 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\netr28x.sys -- (netr28x)DRV:64bit: - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mbam.sys -- (MBAMProtector)DRV:64bit: - [2013/03/02 04:57:46 | 000,077,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)DRV:64bit: - [2013/03/02 04:45:20 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)DRV:64bit: - [2013/03/02 04:39:38 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)DRV:64bit: - [2013/01/29 18:15:04 | 000,029,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\nuidfltr.sys -- (NuidFltr)DRV:64bit: - [2013/01/09 19:53:32 | 000,028,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)DRV:64bit: - [2012/11/26 21:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)DRV:64bit: - [2012/11/19 22:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)DRV:64bit: - [2012/11/05 21:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)DRV:64bit: - [2012/10/26 05:17:44 | 000,020,912 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\avgboota.sys -- (Avgboota)DRV:64bit: - [2012/10/12 02:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)DRV:64bit: - [2012/10/11 01:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)DRV:64bit: - [2012/10/10 21:51:49 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\serscan.sys -- (StillCam)DRV:64bit: - [2012/09/20 01:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)DRV:64bit: - [2012/09/20 01:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)DRV:64bit: - [2012/08/24 03:38:28 | 000,448,312 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\SynTP.sys -- (SynTP)DRV:64bit: - [2012/08/24 03:38:28 | 000,043,832 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys -- (SmbDrvI)DRV:64bit: - [2012/08/24 03:38:26 | 000,041,272 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\Smb_driver_AMDASF.sys -- (SmbDrv)DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)DRV:64bit: - [2012/08/03 15:07:30 | 000,020,288 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\WirelessButtonDriver64.sys -- (WirelessButtonDriver)DRV:64bit: - [2012/08/02 04:54:18 | 010,280,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)DRV:64bit: - [2012/08/02 02:09:30 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)DRV:64bit: - [2012/07/25 23:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)DRV:64bit: - [2012/07/25 23:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)DRV:64bit: - [2012/07/25 23:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)DRV:64bit: - [2012/07/25 23:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)DRV:64bit: - [2012/07/25 23:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)DRV:64bit: - [2012/07/25 23:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)DRV:64bit: - [2012/07/25 23:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)DRV:64bit: - [2012/07/25 23:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)DRV:64bit: - [2012/07/25 23:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)DRV:64bit: - [2012/07/25 23:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)DRV:64bit: - [2012/07/25 23:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)DRV:64bit: - [2012/07/25 23:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)DRV:64bit: - [2012/07/25 23:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)DRV:64bit: - [2012/07/25 23:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)DRV:64bit: - [2012/07/25 23:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)DRV:64bit: - [2012/07/25 23:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)DRV:64bit: - [2012/07/25 23:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)DRV:64bit: - [2012/07/25 22:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)DRV:64bit: - [2012/07/25 22:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)DRV:64bit: - [2012/07/25 21:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)DRV:64bit: - [2012/07/25 20:29:47 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\WSDPrint.sys -- (WSDPrintDevice)DRV:64bit: - [2012/07/25 20:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)DRV:64bit: - [2012/07/25 20:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)DRV:64bit: - [2012/07/25 20:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)DRV:64bit: - [2012/07/25 20:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)DRV:64bit: - [2012/07/25 20:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)DRV:64bit: - [2012/07/25 20:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)DRV:64bit: - [2012/07/25 20:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)DRV:64bit: - [2012/07/25 20:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)DRV:64bit: - [2012/07/25 20:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)DRV:64bit: - [2012/07/25 20:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)DRV:64bit: - [2012/07/25 20:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)DRV:64bit: - [2012/07/25 20:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)DRV:64bit: - [2012/07/25 20:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)DRV:64bit: - [2012/07/25 20:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)DRV:64bit: - [2012/07/25 20:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)DRV:64bit: - [2012/07/25 20:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)DRV:64bit: - [2012/07/25 20:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)DRV:64bit: - [2012/07/25 20:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)DRV:64bit: - [2012/07/25 20:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)DRV:64bit: - [2012/07/25 20:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)DRV:64bit: - [2012/07/25 20:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)DRV:64bit: - [2012/07/23 15:35:12 | 000,079,528 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\amd_sata.sys -- (amd_sata)DRV:64bit: - [2012/07/23 15:35:12 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\amd_xata.sys -- (amd_xata)DRV:64bit: - [2012/07/04 12:41:58 | 000,339,600 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RtsPStor.sys -- (RSPCIESTOR)DRV:64bit: - [2012/06/25 11:24:50 | 000,092,536 | ---- | M] (CyberLink) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\CLVirtualDrive.sys -- (CLVirtualDrive)DRV:64bit: - [2012/06/18 20:07:50 | 000,057,000 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\usbfilter.sys -- (usbfilter)DRV:64bit: - [2012/06/12 23:41:22 | 000,683,664 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168)DRV:64bit: - [2012/06/02 08:32:26 | 010,627,744 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\igdkmd64.sys -- (igfx)DRV - [2013/09/10 23:18:30 | 000,265,872 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys -- (RapportEI64)DRV - [2013/09/10 23:18:28 | 000,384,432 | ---- | M] (Trusteer Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys -- (RapportPG64)DRV - [2013/08/21 11:14:57 | 000,589,872 | ---- | M] () [Kernel | System | Running] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys -- (RapportCerberus_56758)========== Standard Registry (SafeList) ==================== Internet Explorer ==========IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPNTDFJSIE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1IE - HKLM\..\SearchScopes,DefaultScope =IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.comIE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes,DefaultScope =IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPNTDFJSIE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}IE - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0========== FireFox ==========FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll File not foundFF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not foundFF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/10/07 19:17:00 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/10/07 19:17:00 | 000,000,000 | ---D | M][2013/10/08 21:54:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default\extensions[2013/10/08 21:54:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\ij70wgnu.default\extensions\{5fec7248-515c-47be-ab0a-6bc547472dea}========== Chrome ==========CHR - default_search_provider: Google (Enabled)CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},CHR - homepage: http://www.google.comCHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dllCHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewerCHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dllCHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dllCHR - plugin: Norton Confidential (Enabled) = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.0.0.72_0\npcoplgn.dllCHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dllCHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dllCHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dllCHR - Extension: Google Drive = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\CHR - Extension: YouTube = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\CHR - Extension: Google Search = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\CHR - Extension: RealDownloader = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_0\CHR - Extension: Gmail = C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\O1 HOSTS File: ([2012/07/25 23:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hostsO2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)O3 - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.O4:64bit: - HKLM..\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)O4 - HKLM..\Run: [] File not foundO4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)O4 - HKU\.DEFAULT..\Run: [searchProtect] \SearchProtect\bin\cltmng.exe File not foundO4 - HKU\S-1-5-18..\Run: [searchProtect] \SearchProtect\bin\cltmng.exe File not foundO4 - HKU\S-1-5-21-2989837996-1790684633-2971567215-1002..\Run: [sanDiskSecureAccess_Manager.exe] C:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe (Gemalto N.V.)O4 - Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)O1364bit: - gopher Prefix: missingO13 - gopher Prefix: missingO17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 67.215.21.202 72.21.70.3O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}: DhcpNameServer = 67.215.21.202 72.21.70.3O18:64bit: - Protocol\Handler\cdo - No CLSID value foundO18:64bit: - Protocol\Handler\msdaipp - No CLSID value foundO18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value foundO18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value foundO18:64bit: - Protocol\Handler\mso-offdap - No CLSID value foundO18:64bit: - Protocol\Handler\skype4com - No CLSID value foundO18:64bit: - Protocol\Handler\wlpg - No CLSID value foundO18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O30 - LSA: Security Packages - (livessp) - File not foundO32 - HKLM CDRom: AutoRun - 1O33 - MountPoints2\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\Shell - "" = AutoRunO33 - MountPoints2\{7c7c7a2e-764b-11e2-be8b-c8cbb8b06c44}\Shell\AutoRun\command - "" = "F:\LaunchU3.exe" -aO34 - HKLM BootExecute: (autocheck autochk *)O35:64bit: - HKLM\..comfile [open] -- "%1" %*O35:64bit: - HKLM\..exefile [open] -- "%1" %*O35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)========== Files/Folders - Created Within 180 Days ==========[2013/10/27 21:08:57 | 000,000,000 | ---D | C] -- C:\Users\Dave\Desktop\Scans[2013/10/27 20:03:07 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Avg2013[2013/10/26 23:07:30 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Malwarebytes[2013/10/26 23:07:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes[2013/10/26 23:07:04 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys[2013/10/26 23:07:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware[2013/10/26 22:13:00 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT[2013/10/26 22:05:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner[2013/10/15 13:44:43 | 000,694,232 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe[2013/10/15 13:44:43 | 000,078,296 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl[2013/10/12 21:39:54 | 001,374,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdc.dll[2013/10/12 21:39:53 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wvc.dll[2013/10/12 21:39:45 | 001,245,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdc.dll[2013/10/12 21:39:44 | 000,462,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx[2013/10/12 21:39:42 | 000,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx[2013/10/12 21:39:41 | 000,437,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wvc.dll[2013/10/12 21:36:01 | 010,116,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll[2013/10/12 21:35:57 | 008,858,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll[2013/10/12 21:35:56 | 001,125,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll[2013/10/12 21:35:51 | 002,304,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll[2013/10/12 21:35:51 | 002,035,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll[2013/10/12 21:35:51 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSync.dll[2013/10/12 21:35:51 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll[2013/10/12 21:35:50 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSync.dll[2013/10/12 21:35:50 | 000,225,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mbsmsapi.dll[2013/10/12 21:35:49 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mbsmsapi.dll[2013/10/12 21:35:48 | 000,128,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncInfo.dll[2013/10/10 15:53:07 | 000,652,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll[2013/10/10 15:53:02 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UXInit.dll[2013/10/10 15:53:01 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll[2013/10/10 15:52:59 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll[2013/10/10 15:52:58 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UXInit.dll[2013/10/10 15:52:57 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll[2013/10/10 15:52:57 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll[2013/10/10 15:52:52 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll[2013/10/10 15:52:52 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe[2013/10/10 15:52:52 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll[2013/10/10 15:52:50 | 000,915,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uxtheme.dll[2013/10/10 15:52:50 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll[2013/10/10 15:52:41 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll[2013/10/10 15:51:05 | 003,959,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll[2013/10/10 15:51:02 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll[2013/10/10 15:48:41 | 000,054,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys[2013/10/10 15:48:40 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys[2013/10/10 15:48:40 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys[2013/10/10 15:48:25 | 000,362,496 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll[2013/10/10 15:48:25 | 000,300,032 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll[2013/10/10 15:48:25 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll[2013/10/10 15:48:25 | 000,035,328 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll[2013/10/10 15:48:15 | 000,498,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys[2013/10/10 15:48:15 | 000,021,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys[2013/10/10 15:48:10 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll[2013/10/10 15:48:10 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll[2013/10/10 15:48:09 | 000,337,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS[2013/10/10 15:48:08 | 000,447,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS[2013/10/10 15:48:08 | 000,213,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UCX01000.SYS[2013/10/07 19:19:07 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Programs[2013/10/07 19:18:15 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\WordOv[2013/10/07 19:18:13 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\RealNetworks[2013/10/07 19:16:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RealNetworks[2013/10/07 19:16:45 | 000,000,000 | ---D | C] -- C:\ProgramData\RealNetworks[2013/10/07 19:14:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared[2013/10/07 19:14:31 | 000,201,872 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll[2013/10/07 19:14:08 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll[2013/10/07 19:14:08 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll[2013/10/07 19:13:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks[2013/10/07 19:13:56 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll[2013/10/07 19:13:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real[2013/10/07 19:11:24 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Real[2013/10/07 19:10:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Real[2013/10/04 13:18:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes[2013/10/04 13:17:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod[2013/10/04 13:17:04 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes[2013/10/04 13:17:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes[2013/10/04 13:17:04 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69[2013/09/25 18:58:09 | 000,000,000 | ---D | C] -- C:\Users\Dave\New folder (2)[2013/09/25 18:56:05 | 000,000,000 | ---D | C] -- C:\Users\Dave\New folder[2013/09/25 18:54:30 | 000,000,000 | ---D | C] -- C:\Users\Dave\Work[2013/09/20 22:57:50 | 000,209,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationUI.exe[2013/09/20 22:57:49 | 002,371,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSService.dll[2013/09/20 22:57:49 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll[2013/09/20 22:57:44 | 000,688,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSShared.dll[2013/09/20 22:57:44 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSetupUI.dll[2013/09/20 22:57:43 | 000,562,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSShared.dll[2013/09/20 22:57:42 | 000,773,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll[2013/09/20 22:57:41 | 000,368,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppwinob.dll[2013/09/20 22:57:41 | 000,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppc.dll[2013/09/20 22:57:40 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sppc.dll[2013/09/20 22:57:39 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll[2013/09/20 22:57:38 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll[2013/09/20 22:57:37 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSSync.dll[2013/09/20 22:57:34 | 001,621,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll[2013/09/20 22:57:33 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSSync.dll[2013/09/20 22:57:33 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll[2013/09/20 22:57:32 | 000,059,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe[2013/09/20 22:57:32 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll[2013/09/20 22:57:31 | 000,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll[2013/09/20 22:57:30 | 000,204,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSClient.dll[2013/09/20 22:57:29 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.dll[2013/09/20 22:57:29 | 000,058,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dam.sys[2013/09/20 22:57:29 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll[2013/09/20 22:57:28 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSClient.dll[2013/09/20 22:57:27 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\storewuauth.dll[2013/09/20 22:57:26 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll[2013/09/20 22:57:26 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll[2013/09/20 22:57:25 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll[2013/09/20 22:57:23 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll[2013/09/20 22:57:22 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupcln.dll[2013/09/20 22:57:22 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe[2013/09/20 22:57:22 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe[2013/09/20 22:57:21 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll[2013/09/20 22:57:20 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll[2013/09/20 22:57:19 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setupcln.dll[2013/09/20 22:52:13 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tssdisai.dll[2013/09/20 19:32:12 | 000,000,000 | ---D | C] -- C:\temp[2013/09/20 19:31:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC HealthBoost[2013/09/20 19:31:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC HealthBoost[2013/09/20 19:30:34 | 000,000,000 | ---D | C] -- C:\ProgramData\PCHealthBoost[2013/09/20 19:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2014[2013/09/20 19:02:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CodeMeter[2013/09/20 19:01:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GetData[2013/09/11 09:02:26 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Macromedia[2013/09/11 09:00:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Mozilla[2013/09/11 09:00:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Mozilla[2013/09/11 09:00:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla[2013/09/11 08:59:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox[2013/08/27 11:10:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG[2013/08/21 11:12:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection[2013/08/19 17:18:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center[2013/08/19 17:17:40 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Mouse and Keyboard Center[2013/08/19 17:14:50 | 002,273,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll[2013/08/19 17:14:48 | 002,839,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll[2013/08/19 17:14:46 | 001,025,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll[2013/08/19 17:14:46 | 000,778,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll[2013/08/19 17:14:45 | 001,300,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll[2013/08/19 17:14:44 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL[2013/08/19 17:14:43 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanconn.dll[2013/08/19 17:14:43 | 000,327,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys[2013/08/19 17:14:42 | 000,439,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFault.exe[2013/08/19 17:14:42 | 000,263,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll[2013/08/19 17:14:42 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll[2013/08/19 17:14:42 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmmbase.dll[2013/08/19 17:14:42 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmm.dll[2013/08/19 17:14:41 | 000,385,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFault.exe[2013/08/19 17:14:41 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winmmbase.dll[2013/08/19 17:14:38 | 000,195,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys[2013/08/19 17:14:38 | 000,125,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpsd.sys[2013/08/19 17:14:38 | 000,120,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\msgpioclx.sys[2013/08/19 17:14:37 | 000,370,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wwanadvui.dll[2013/08/19 17:14:37 | 000,268,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll[2013/08/19 17:14:37 | 000,096,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys[2013/08/19 17:14:37 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmcsp.dll[2013/08/19 17:14:36 | 000,543,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanmm.dll[2013/08/19 17:14:36 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.dll[2013/08/19 17:14:36 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL[2013/08/19 17:14:36 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\openfiles.exe[2013/08/19 17:14:35 | 000,888,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll[2013/08/19 17:14:35 | 000,702,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll[2013/08/19 17:14:35 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\openfiles.exe[2013/08/19 17:14:34 | 000,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\LocationApi.dll[2013/08/19 17:14:34 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\LocationApi.dll[2013/08/19 17:12:38 | 000,000,000 | ---D | C] -- C:\1570ac898210a48ebc25d182f807[2013/08/17 01:14:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT[2013/08/16 12:37:31 | 000,247,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdFilter.sys[2013/08/16 12:37:31 | 000,036,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdBoot.sys[2013/08/14 23:09:25 | 001,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll[2013/08/14 15:12:06 | 001,889,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll[2013/08/14 15:12:05 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll[2013/08/14 15:12:04 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apprepapi.dll[2013/08/14 15:12:04 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apprepsync.dll[2013/08/14 15:12:04 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepapi.dll[2013/08/14 15:12:04 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepsync.dll[2013/07/26 19:11:44 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk SecureAccess Manager[2013/07/26 19:11:41 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\SanDisk[2013/07/26 19:08:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Roaming\SanDisk SecureAccess[2013/07/20 01:51:00 | 000,311,608 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys[2013/07/20 01:50:56 | 000,246,072 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys[2013/07/20 01:50:56 | 000,071,480 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys[2013/07/20 01:50:50 | 000,206,648 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys[2013/07/16 18:43:51 | 002,219,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll[2013/07/16 18:43:48 | 002,391,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe[2013/07/16 18:43:48 | 001,842,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll[2013/07/16 18:43:47 | 006,987,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe[2013/07/16 18:43:47 | 002,106,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe[2013/07/16 18:43:44 | 000,729,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll[2013/07/16 18:43:41 | 001,527,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll[2013/07/16 18:43:41 | 001,453,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll[2013/07/16 18:43:39 | 001,403,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi[2013/07/16 18:43:39 | 001,271,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe[2013/07/16 18:43:38 | 000,523,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll[2013/07/16 18:43:37 | 001,217,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi[2013/07/16 18:43:37 | 001,093,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe[2013/07/16 18:43:37 | 000,583,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscms.dll[2013/07/16 18:43:36 | 001,048,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfasfsrcsnk.dll[2013/07/16 18:43:36 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll[2013/07/16 18:43:35 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samlib.dll[2013/07/16 18:43:34 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfasfsrcsnk.dll[2013/07/16 18:43:34 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceSetupManager.dll[2013/07/16 18:43:34 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MbaeParserTask.exe[2013/07/16 18:43:32 | 000,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsutil.dll[2013/07/16 18:43:32 | 000,037,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys[2013/07/16 10:57:23 | 000,000,000 | ---D | C] -- C:\Users\Dave\Documents\Corel User Files[2013/07/16 10:37:15 | 000,000,000 | ---D | C] -- C:\Users\Dave\Documents\Fonts[2013/07/13 13:15:18 | 000,000,000 | ---D | C] -- C:\Users\Dave\Documents\Graphics[2013/07/11 10:56:53 | 001,838,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll[2013/07/11 10:56:50 | 000,595,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll[2013/07/11 10:56:50 | 000,496,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll[2013/07/11 10:54:23 | 002,842,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL[2013/07/11 10:54:22 | 002,620,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL[2013/07/10 01:32:38 | 000,045,880 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys[2013/07/09 01:28:50 | 000,248,632 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgwfpa.sys[2013/07/07 17:22:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus[2013/07/07 17:20:48 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan[2013/07/07 17:20:45 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee[2013/07/07 17:20:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee Security Scan[2013/07/07 17:19:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe[2013/07/07 17:19:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe[2013/07/07 17:17:51 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Adobe[2013/07/01 01:45:28 | 000,116,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys[2013/06/21 21:55:05 | 000,000,000 | ---D | C] -- C:\Users\Dave\AppData\Local\Apple Computer[2013/06/21 21:54:16 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys[2013/06/21 21:50:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud[2013/06/21 21:50:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple[2013/06/21 21:46:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime[2013/06/21 21:45:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime[2013/06/21 21:45:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer[2013/06/16 15:19:44 | 001,257,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll[2013/06/15 23:15:14 | 000,888,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autochk.exe[2013/06/15 23:15:13 | 000,542,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll[2013/06/15 23:15:13 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll[2013/06/15 23:15:12 | 000,793,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe[2013/06/15 11:20:12 | 013,644,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll[2013/06/15 11:20:06 | 010,788,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll[2013/06/15 11:20:02 | 001,131,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll[2013/06/15 11:19:54 | 000,470,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netprofmsvc.dll[2013/06/15 11:19:48 | 000,014,848 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\rars.rs[2013/06/15 11:19:48 | 000,014,848 | ---- | C] (Microsoft) -- C:\Windows\SysNative\rars.rs[2013/06/15 11:19:47 | 000,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BCP47Langs.dll[2013/06/15 11:19:47 | 000,330,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll[2013/06/15 11:19:47 | 000,328,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ubpm.dll[2013/06/15 11:19:47 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ubpm.dll[2013/06/15 11:19:46 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.dll[2013/06/15 11:19:46 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netplwiz.dll[2013/06/15 11:19:45 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Magnify.exe[2013/06/15 11:19:44 | 000,560,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfmp4srcsnk.dll[2013/06/15 11:19:44 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psmsrv.dll[2013/06/15 11:19:41 | 000,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll[2013/06/15 11:19:40 | 000,501,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairing.dll[2013/06/15 11:19:40 | 000,284,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys[2013/06/15 11:19:39 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\intl.cpl[2013/06/15 11:19:39 | 000,120,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuthHost.exe[2013/06/15 11:19:38 | 000,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Magnify.exe[2013/06/15 11:19:37 | 000,449,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairing.dll[2013/06/15 11:19:37 | 000,122,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\biwinrt.dll[2013/06/15 11:19:36 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\biwinrt.dll[2013/06/15 11:19:35 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\intl.cpl[2013/06/15 11:19:35 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bisrv.dll[2013/06/15 11:19:34 | 000,411,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfmp4srcsnk.dll[2013/06/15 11:19:34 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\BCP47Langs.dll[2013/06/15 11:19:32 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\muifontsetup.dll[2013/06/15 11:19:32 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\muifontsetup.dll[2013/06/12 15:40:07 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptdlg.dll[2013/06/12 15:40:07 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptdlg.dll[2013/06/12 08:40:52 | 001,255,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe[2013/06/12 08:40:51 | 001,013,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe[2013/06/12 08:40:51 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll[2013/06/12 08:40:45 | 000,733,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll[2013/05/29 20:53:04 | 006,085,632 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll[2013/05/29 20:53:04 | 001,821,184 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\IDTNC64.cpl[2013/05/29 20:53:04 | 001,664,000 | ---- | C] (IDT, Inc.) -- C:\Windows\sttray64.exe[2013/05/29 20:52:52 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SRSLabs[2013/05/29 20:49:36 | 000,255,488 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\staco64.dll[2013/05/29 20:49:28 | 000,542,208 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys[2013/05/29 20:49:26 | 002,188,800 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll[2013/05/29 20:49:26 | 000,671,744 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll[2013/05/29 20:49:26 | 000,499,200 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll[2013/05/23 23:08:49 | 000,000,000 | -H-D | C] -- C:\$SysReset[2013/05/17 09:17:06 | 003,552,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll[2013/05/17 09:17:05 | 014,267,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll[2013/05/17 09:17:01 | 011,878,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll[2013/05/17 09:16:58 | 002,107,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll[2013/05/17 09:16:55 | 002,767,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll[2013/05/17 09:16:53 | 001,593,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll[2013/05/17 09:16:49 | 001,829,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll[2013/05/17 09:16:47 | 001,444,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAudDecMFT.dll[2013/05/17 09:16:37 | 001,113,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAudDecMFT.dll[2013/05/17 09:16:36 | 000,306,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd_02_10ec.dll[2013/05/17 09:16:35 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll[2013/05/17 09:16:34 | 000,298,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rsaenh.dll[2013/05/17 09:16:33 | 000,446,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll[2013/05/17 09:16:33 | 000,373,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe[2013/05/17 09:16:31 | 000,489,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll[2013/05/17 09:16:30 | 000,435,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll[2013/05/17 09:16:30 | 000,367,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe[2013/05/17 09:16:30 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmredir.dll[2013/05/17 09:16:28 | 000,595,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.dll[2013/05/17 09:16:28 | 000,253,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe[2013/05/17 09:16:27 | 000,804,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RecoveryDrive.exe[2013/05/17 09:16:27 | 000,456,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpncore.dll[2013/05/17 09:16:21 | 000,196,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dmvdsitf.dll[2013/05/17 09:16:20 | 000,503,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll[2013/05/17 09:16:20 | 000,468,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MFMediaEngine.dll[2013/05/17 09:16:20 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fhengine.dll[2013/05/17 09:16:19 | 000,659,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll[2013/05/17 09:16:19 | 000,411,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.dll[2013/05/17 09:16:19 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll[2013/05/17 09:16:19 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEndpointBuilder.dll[2013/05/17 09:16:18 | 000,123,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll[2013/05/17 09:16:17 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Robocopy.exe[2013/05/17 09:16:17 | 000,077,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdvm.dll[2013/05/17 09:16:16 | 000,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iuilp.dll[2013/05/17 09:16:16 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe[2013/05/17 09:16:16 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Robocopy.exe[2013/05/17 09:16:15 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll[2013/05/17 09:16:15 | 000,155,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmvdsitf.dll[2013/05/17 09:16:15 | 000,086,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdnet.dll[2013/05/17 09:16:14 | 000,745,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll[2013/05/17 09:16:14 | 000,414,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GenuineCenter.dll[2013/05/17 09:16:14 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFMediaEngine.dll[2013/05/17 09:16:13 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssprxy.dll[2013/05/17 09:16:13 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll[2013/05/17 09:16:13 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fmifs.dll[2013/05/17 09:16:13 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fmifs.dll[2013/05/17 09:16:13 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msshooks.dll[2013/05/17 09:16:13 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msshooks.dll[2013/05/15 19:48:08 | 002,382,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\esent.dll[2013/05/15 19:48:06 | 002,851,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\esent.dll[2013/05/15 08:50:08 | 000,112,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe[2013/05/13 15:36:12 | 000,354,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vccorlib110.dll[2013/05/13 15:36:06 | 000,050,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\point64.sys[2013/05/06 08:32:28 | 002,274,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\coin94.dll[2013/05/06 08:32:28 | 000,076,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dc3d.sys[2013/05/01 03:59:12 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\Windows\SysWow64\QuickTimeVR.qtx[2013/05/01 03:59:12 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\Windows\SysWow64\QuickTime.qts[1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]========== Files - Modified Within 180 Days ==========[2013/10/27 22:13:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job[2013/10/27 22:11:17 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job[2013/10/27 21:52:26 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job[2013/10/27 21:47:01 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job[2013/10/27 21:41:59 | 000,001,050 | ---- | M] () -- C:\Users\Dave\Desktop\JRT - Shortcut.lnk[2013/10/27 21:36:01 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\PrintProjects Communicator.job[2013/10/27 20:22:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat[2013/10/27 20:20:39 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys[2013/10/27 20:20:38 | 3088,900,096 | -HS- | M] () -- C:\hiberfil.sys[2013/10/27 19:26:01 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForDave.job[2013/10/26 23:07:09 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[2013/10/26 22:25:45 | 001,653,808 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT[2013/10/07 19:14:31 | 000,201,872 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll[2013/10/07 19:14:08 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll[2013/10/07 19:14:08 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll[2013/10/07 19:13:57 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll[2013/10/04 13:18:10 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk[2013/10/01 20:57:21 | 000,003,734 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml[2013/10/01 20:57:03 | 000,046,368 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys[2013/10/01 19:38:13 | 000,694,232 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe[2013/10/01 19:38:13 | 000,078,296 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl[2013/10/01 12:14:12 | 000,000,068 | ---- | M] () -- C:\Users\Dave\AppData\Roaming\WB.CFG[2013/09/22 17:27:49 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll[2013/09/22 16:55:16 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe[2013/09/22 16:54:55 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll[2013/09/22 16:54:51 | 003,959,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll[2013/09/22 16:54:51 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll[2013/09/20 23:25:14 | 000,941,114 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI[2013/09/20 23:25:14 | 000,783,894 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat[2013/09/20 23:25:14 | 000,158,368 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat[2013/09/10 23:18:30 | 000,266,928 | ---- | M] (Trusteer Ltd.) -- C:\Windows\SysNative\drivers\RapportHades64.sys[2013/09/10 23:18:28 | 000,295,696 | ---- | M] (Trusteer Ltd.) -- C:\Windows\SysNative\drivers\RapportKE64.sys[2013/08/15 23:41:13 | 000,058,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dam.sys[2013/08/15 23:39:26 | 002,371,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSService.dll[2013/08/15 23:39:26 | 000,059,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe[2013/08/15 23:32:48 | 000,209,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\NotificationUI.exe[2013/08/15 23:22:22 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe[2013/08/15 23:21:55 | 001,621,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll[2013/08/15 23:21:55 | 000,252,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll[2013/08/15 23:21:55 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll[2013/08/15 23:21:55 | 000,099,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll[2013/08/15 23:21:55 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll[2013/08/15 23:21:55 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll[2013/08/15 23:21:53 | 000,773,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll[2013/08/15 23:21:43 | 000,688,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSShared.dll[2013/08/15 23:21:43 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSSync.dll[2013/08/15 23:21:42 | 000,204,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSClient.dll[2013/08/15 23:21:42 | 000,198,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.dll[2013/08/15 23:21:42 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll[2013/08/15 23:21:22 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\storewuauth.dll[2013/08/15 23:21:18 | 001,164,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppobjs.dll[2013/08/15 23:21:18 | 000,368,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppwinob.dll[2013/08/15 23:21:12 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\setupcln.dll[2013/08/15 23:21:00 | 000,120,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppc.dll[2013/08/15 23:20:30 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WinSetupUI.dll[2013/08/15 16:43:21 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe[2013/08/15 16:43:07 | 000,628,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll[2013/08/15 16:43:07 | 000,126,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll[2013/08/15 16:43:07 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll[2013/08/15 16:43:07 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll[2013/08/15 16:43:03 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSShared.dll[2013/08/15 16:43:03 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSSync.dll[2013/08/15 16:43:02 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSClient.dll[2013/08/15 16:43:02 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll[2013/08/15 16:43:02 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll[2013/08/15 16:43:02 | 000,083,968 | ---- | M] () -- C:\Windows\SysWow64\OEMLicense.dll[2013/08/15 16:42:52 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\setupcln.dll[2013/08/15 16:42:47 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\sppc.dll[2013/08/09 23:21:51 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSync.dll[2013/08/09 23:21:51 | 000,128,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncInfo.dll[2013/08/09 21:58:51 | 000,356,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSync.dll[2013/08/06 23:15:02 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tssdisai.dll[2013/08/03 00:40:49 | 000,462,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx[2013/08/03 00:40:17 | 000,566,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wvc.dll[2013/08/03 00:40:01 | 001,374,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wdc.dll[2013/08/02 23:14:15 | 000,399,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx[2013/08/02 23:13:57 | 000,437,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wvc.dll[2013/08/02 23:13:43 | 001,245,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wdc.dll[2013/08/02 18:02:49 | 356,661,235 | ---- | M] () -- C:\Windows\MEMORY.DMP[2013/08/02 00:28:29 | 010,116,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll[2013/08/02 00:28:20 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll[2013/08/02 00:26:53 | 002,304,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll[2013/08/01 23:08:18 | 008,858,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll[2013/08/01 23:06:50 | 002,035,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll[2013/07/30 17:30:05 | 000,386,923 | ---- | M] () -- C:\Windows\SysNative\ApnDatabase.xml[2013/07/26 21:58:39 | 002,207,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\PrintConfig.dll[2013/07/26 19:53:41 | 000,001,312 | ---- | M] () -- C:\Users\Public\Desktop\The Weather Channel App.lnk[2013/07/24 17:10:08 | 000,158,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mbsmsapi.dll[2013/07/24 17:06:39 | 000,225,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mbsmsapi.dll[2013/07/20 01:51:00 | 000,311,608 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys[2013/07/20 01:50:56 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys[2013/07/20 01:50:56 | 000,071,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys[2013/07/20 01:50:50 | 000,206,648 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys[2013/07/19 16:13:34 | 000,124,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll[2013/07/19 16:13:15 | 000,102,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll[2013/07/13 00:18:21 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll[2013/07/13 00:16:06 | 001,889,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll[2013/07/13 00:15:53 | 000,124,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\apprepapi.dll[2013/07/13 00:15:53 | 000,098,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\apprepsync.dll[2013/07/12 22:23:03 | 000,087,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepapi.dll[2013/07/12 22:23:03 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\apprepsync.dll[2013/07/12 19:51:22 | 000,000,017 | ---- | M] () -- C:\Users\Dave\AppData\Local\resmon.resmoncfg[2013/07/10 01:32:38 | 000,045,880 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys[2013/07/09 02:04:07 | 000,120,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\msgpioclx.sys[2013/07/09 01:28:50 | 000,248,632 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgwfpa.sys[2013/07/09 00:18:21 | 000,439,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WerFault.exe[2013/07/08 22:25:45 | 000,385,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFault.exe[2013/07/08 21:57:19 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\LocationApi.dll[2013/07/08 16:46:00 | 000,543,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wwanmm.dll[2013/07/08 16:46:00 | 000,414,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wwanconn.dll[2013/07/08 16:46:00 | 000,370,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Wwanadvui.dll[2013/07/08 16:45:16 | 000,312,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\LocationApi.dll[2013/07/07 17:22:56 | 000,002,046 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk[2013/07/07 17:22:56 | 000,002,046 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk[2013/07/05 18:16:17 | 001,025,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll[2013/07/05 18:15:29 | 000,652,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll[2013/07/02 18:23:43 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.dll[2013/07/02 18:23:12 | 000,778,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll[2013/07/02 18:22:47 | 002,839,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll[2013/07/02 18:22:26 | 001,300,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll[2013/07/02 18:11:23 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll[2013/07/02 18:10:53 | 002,273,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll[2013/07/01 19:41:47 | 000,447,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS[2013/07/01 19:41:47 | 000,337,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS[2013/07/01 19:41:47 | 000,213,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UCX01000.SYS[2013/07/01 18:44:14 | 000,036,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdBoot.sys[2013/07/01 16:08:49 | 000,247,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdFilter.sys[2013/07/01 01:45:28 | 000,116,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys[2013/06/30 19:42:09 | 000,498,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys[2013/06/30 19:42:09 | 000,021,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys[2013/06/30 16:30:14 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\openfiles.exe[2013/06/30 16:29:22 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\openfiles.exe[2013/06/29 00:15:54 | 000,195,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys[2013/06/29 00:15:47 | 000,125,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpsd.sys[2013/06/28 23:43:16 | 000,327,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys[2013/06/28 21:08:18 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys[2013/06/28 21:07:13 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys[2013/06/25 14:54:11 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_dc3d_01011.Wdf[2013/06/24 16:54:45 | 000,263,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll[2013/06/24 16:54:45 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wcmcsp.dll[2013/06/21 23:45:57 | 000,054,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys[2013/06/18 23:36:21 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winmmbase.dll[2013/06/18 23:36:21 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winmm.dll[2013/06/18 16:38:00 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\winmmbase.dll[2013/06/11 17:26:20 | 000,230,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll[2013/06/10 15:17:46 | 000,096,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys[2013/06/10 13:16:07 | 000,888,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll[2013/06/10 13:15:38 | 000,381,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL[2013/06/10 13:10:58 | 000,702,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll[2013/06/10 13:10:37 | 000,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL[2013/06/01 05:34:21 | 002,391,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe[2013/06/01 05:26:31 | 006,987,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe[2013/06/01 04:24:46 | 002,106,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe[2013/06/01 03:25:52 | 000,364,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll[2013/06/01 03:25:03 | 000,496,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll[2013/06/01 03:24:09 | 001,453,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll[2013/06/01 03:24:09 | 000,850,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfasfsrcsnk.dll[2013/06/01 03:23:46 | 001,842,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll[2013/06/01 03:22:47 | 000,080,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MbaeParserTask.exe[2013/06/01 03:22:33 | 000,523,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll[2013/06/01 03:22:09 | 000,190,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vdsutil.dll[2013/06/01 03:21:39 | 000,729,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll[2013/06/01 03:21:39 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\samlib.dll[2013/06/01 03:21:34 | 000,595,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll[2013/06/01 03:20:45 | 000,583,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mscms.dll[2013/06/01 03:20:34 | 001,527,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll[2013/06/01 03:20:34 | 001,048,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfasfsrcsnk.dll[2013/06/01 03:20:04 | 002,219,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll[2013/06/01 03:19:58 | 000,207,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceSetupManager.dll[2013/05/31 21:08:57 | 000,037,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys[2013/05/30 17:24:29 | 001,257,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll[2013/05/29 20:47:43 | 006,085,632 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stlang64.dll[2013/05/29 20:47:43 | 001,664,000 | ---- | M] (IDT, Inc.) -- C:\Windows\sttray64.exe[2013/05/29 20:47:43 | 000,542,208 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys[2013/05/29 20:47:43 | 000,499,200 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll[2013/05/29 20:47:42 | 002,188,800 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll[2013/05/29 20:47:42 | 000,671,744 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll[2013/05/29 20:47:42 | 000,255,488 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\staco64.dll[2013/05/29 20:47:37 | 001,821,184 | ---- | M] (IDT, Inc.) -- C:\Windows\SysNative\IDTNC64.cpl[2013/05/26 17:17:30 | 000,035,328 | ---- | M] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll[2013/05/26 16:59:03 | 000,046,080 | ---- | M] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll[2013/05/24 21:15:19 | 000,362,496 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll[2013/05/24 20:32:52 | 000,300,032 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll[2013/05/24 16:09:20 | 001,403,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi[2013/05/24 16:09:20 | 001,271,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe[2013/05/24 16:09:20 | 001,217,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi[2013/05/24 16:09:20 | 001,093,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe[2013/05/23 17:02:30 | 001,314,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll[2013/05/15 16:37:03 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\UXInit.dll[2013/05/15 16:35:49 | 000,053,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UXInit.dll[2013/05/14 20:25:59 | 000,888,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\autochk.exe[2013/05/14 20:25:44 | 000,542,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll[2013/05/14 20:24:10 | 000,793,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe[2013/05/14 20:24:01 | 000,482,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll[2013/05/13 15:36:12 | 000,828,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msvcr110.dll[2013/05/13 15:36:12 | 000,661,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msvcp110.dll[2013/05/13 15:36:12 | 000,354,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vccorlib110.dll[2013/05/13 15:36:06 | 000,050,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\point64.sys[2013/05/06 08:32:28 | 002,274,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\coin94.dll[2013/05/06 08:32:28 | 000,076,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dc3d.sys[2013/05/04 01:58:17 | 000,120,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AuthHost.exe[2013/05/04 01:34:15 | 000,284,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys[2013/05/04 00:59:36 | 000,812,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Magnify.exe[2013/05/04 00:59:21 | 002,842,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL[2013/05/04 00:59:08 | 013,644,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll[2013/05/04 00:58:54 | 000,328,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ubpm.dll[2013/05/04 00:58:48 | 000,330,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll[2013/05/04 00:58:28 | 000,093,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\psmsrv.dll[2013/05/04 00:58:02 | 000,470,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netprofmsvc.dll[2013/05/04 00:58:01 | 000,169,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\netplwiz.dll[2013/05/04 00:57:59 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\muifontsetup.dll[2013/05/04 00:57:46 | 000,560,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfmp4srcsnk.dll[2013/05/04 00:57:15 | 000,501,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairing.dll[2013/05/04 00:57:05 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\bisrv.dll[2013/05/04 00:57:05 | 000,122,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\biwinrt.dll[2013/05/04 00:57:04 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\BCP47Langs.dll[2013/05/04 00:57:00 | 001,131,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll[2013/05/04 00:57:00 | 000,708,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.dll[2013/05/04 00:56:53 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\intl.cpl[2013/05/03 22:58:14 | 000,758,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Magnify.exe[2013/05/03 22:57:58 | 002,620,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL[2013/05/03 22:57:49 | 010,788,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll[2013/05/03 22:57:39 | 000,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ubpm.dll[2013/05/03 22:57:04 | 000,151,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll[2013/05/03 22:57:02 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\muifontsetup.dll[2013/05/03 22:56:48 | 000,411,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfmp4srcsnk.dll[2013/05/03 22:56:14 | 000,449,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairing.dll[2013/05/03 22:56:06 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\biwinrt.dll[2013/05/03 22:56:05 | 000,309,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\BCP47Langs.dll[2013/05/03 22:55:58 | 000,389,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\intl.cpl[2013/05/03 22:51:38 | 000,014,848 | ---- | M] (Microsoft) -- C:\Windows\SysNative\rars.rs[2013/05/03 22:10:47 | 000,014,848 | ---- | M] (Microsoft) -- C:\Windows\SysWow64\rars.rs[2013/05/01 03:59:12 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\Windows\SysWow64\QuickTimeVR.qtx[2013/05/01 03:59:12 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\Windows\SysWow64\QuickTime.qts[1 C:\Users\Dave\Documents\*.tmp files -> C:\Users\Dave\Documents\*.tmp -> ]========== Files Created - No Company Name ==========[2013/10/27 21:41:59 | 000,001,050 | ---- | C] () -- C:\Users\Dave\Desktop\JRT - Shortcut.lnk[2013/10/26 23:07:09 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk[2013/10/26 22:25:45 | 001,653,808 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT[2013/10/12 21:35:48 | 000,386,923 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml[2013/10/04 13:18:10 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk[2013/09/27 22:05:34 | 000,003,734 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml[2013/09/27 12:09:03 | 000,000,068 | ---- | C] () -- C:\Users\Dave\AppData\Roaming\WB.CFG[2013/09/20 22:57:19 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll[2013/07/12 19:51:22 | 000,000,017 | ---- | C] () -- C:\Users\Dave\AppData\Local\resmon.resmoncfg[2013/07/07 17:20:44 | 000,002,046 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk[2013/07/07 17:20:44 | 000,002,046 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk[2013/07/07 17:20:00 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk[2013/06/25 14:54:11 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_dc3d_01011.Wdf[2013/03/17 16:59:51 | 000,001,067 | ---- | C] () -- C:\Windows\hpomdl35.dat.temp[2013/03/17 16:33:22 | 000,225,825 | ---- | C] () -- C:\Windows\hpoins35.dat[2013/03/17 16:33:22 | 000,001,067 | ---- | C] () -- C:\Windows\hpomdl35.dat[2012/12/27 19:13:50 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI[2012/08/17 18:11:41 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin[2012/08/03 16:40:09 | 000,916,510 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI[2012/08/02 02:53:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat[2012/08/02 02:53:50 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat[2012/07/26 02:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat[2012/07/26 02:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT[2012/07/26 01:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat[2012/07/25 19:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll[2012/07/25 14:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin[2012/07/25 14:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll[2012/07/25 14:22:54 | 000,982,240 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin[2012/07/25 14:22:54 | 000,439,308 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin[2012/07/25 14:22:54 | 000,092,356 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin[2012/06/02 08:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat========== ZeroAccess Check ==========[2012/08/17 18:26:03 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32][HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32][HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64"" = C:\Windows\SysNative\shell32.dll -- [2013/08/02 00:28:20 | 019,758,080 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]"" = %SystemRoot%\system32\shell32.dll -- [2013/08/01 23:08:10 | 017,561,088 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/25 21:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/25 21:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/25 21:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Both[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]========== Purity Check ==========< End of report >
-
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Junkware Removal Tool (JRT) by ThisisuVersion: 6.0.7 (10.15.2013:3)OS: Windows 8 x64Ran by Dave on Sun 10/27/2013 at 21:42:28.06~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Services~~~ Registry Values~~~ Registry KeysFailed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181102}Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181102}~~~ Files~~~ FoldersFailed to delete: [Folder] "C:\ProgramData\pchealthboost"Failed to delete: [Folder] "C:\Program Files (x86)\pc healthboost"~~~ Event Viewer Logs were cleared~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Scan was completed on Sun 10/27/2013 at 22:02:51.55End of JRT log~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-
.UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2012-11-20.01).Microsoft Windows 8Boot Device: \Device\HarddiskVolume2Install Date: 12/25/2012 6:49:48 PMSystem Uptime: 10/27/2013 8:20:24 PM (1 hours ago).Motherboard: Hewlett-Packard | | 169AProcessor: AMD E-300 APU with Radeon HD Graphics | Socket FT1 | 1300/100mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 276 GiB total, 216.8 GiB free.D: is FIXED (NTFS) - 21 GiB total, 2.619 GiB free.E: is CDROM ().==== Disabled Device Manager Items =============.Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}Description: Photosmart C309a seriesDevice ID: ROOT\MULTIFUNCTION\0000Manufacturer: HPName: Photosmart C309a seriesPNP Device ID: ROOT\MULTIFUNCTION\0000Service:.==== System Restore Points ===================.RP76: 10/10/2013 8:15:54 PM - HPSF Restore PointRP77: 10/13/2013 12:10:26 PM - Installed RapportRP78: 10/27/2013 1:20:31 AM - Scheduled Checkpoint.==== Installed Programs ======================.4 Elements II64 Bit HP CIO Components InstallerAdobe Flash Player 11 PluginAdobe Reader XI (11.0.05)Adobe Shockwave Player 11.6aiofwaioprntaioscnnrAMD APP SDK RuntimeAMD Catalyst Install ManagerAMD FuelAMD VISION Engine Control CenterApple Application SupportApple Mobile Device SupportApple Software UpdateAtHomeConnect version 1.0.1.0AVG 2013AVG SafeGuard toolbarBejeweled 3BonjourBufferChmBuild-a-lot 4 - Power SourceC309aCatalyst Control Center - BrandingCatalyst Control Center Graphics Previews CommonCatalyst Control Center InstallProxyCatalyst Control Center Localization Allccc-utility64CCC Help Chinese StandardCCC Help Chinese TraditionalCCC Help CzechCCC Help DanishCCC Help DutchCCC Help EnglishCCC Help FinnishCCC Help FrenchCCC Help GermanCCC Help GreekCCC Help HungarianCCC Help ItalianCCC Help JapaneseCCC Help KoreanCCC Help NorwegianCCC Help PolishCCC Help PortugueseCCC Help RussianCCC Help SpanishCCC Help SwedishCCC Help ThaiCCC Help TurkishcenterChuzzle DeluxeCorelDRAW 10Cradle Of Egypt Collector's EditionCradle of Rome 2CyberLink LabelPrintCyberLink Media Suite 10CyberLink Power2Go 8CyberLink PowerDVDCyberLink YouCamD3DX10DestinationsDeviceDiscoveryDocProcEnergy StarFarm FrenzyFATE: The Cursed KingFaxFinal Drive FuryFlatOut 2Google ChromeGoogle Update HelperGovernor of Poker 2 Premium EditionGPBaseService2H&R Block Deluxe + Efile 2012Hewlett-Packard ACLM.NET v1.2.0.0Hoyle Card GamesHP Customer Experience EnhancementsHP Customer Participation Program 14.0HP DocumentationHP GamesHP Imaging Device Functions 14.0HP MyRoomHP Photo CreationsHP Photosmart C309a All-In-One Driver Software 14.0 Rel. 6HP Postscript ConverterHP Quick LaunchHP Recovery ManagerHP Registration ServiceHP Software FrameworkHP Solution Center 14.0HP Support AssistantHP UpdateHP Utility CenterHP Wireless Button DriverHPPhotoGadgetHPProductAssistantHPSSupplyiCloudIDT AudioInternetHelper3 Chrome ToolbariTunesJewel Match 3John Deere Drive GreenKODAK AiO Home CenterksDIPLuxor EvolvedMahjongg Dimensions Deluxe: Tiles in TimeMalwarebytes Anti-Malware version 1.75.0.1300MarketResearchMcAfee Security Scan PlusMicrosoft Application Error ReportingMicrosoft Mouse and Keyboard CenterMicrosoft OfficeMicrosoft Office XP Media ContentMicrosoft Office XP ProfessionalMicrosoft SQL Server 2005 Compact Edition [ENU]Microsoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219Mortimer Beckett and the Crimson Thief Premium EditionMSVCRTMystery P.I. - Curious Case of Counterfeit CoveNetwork64OCR Software by I.R.I.S. 14.0OpenOffice.org 3.4.1Peggle NightsPenguins!Polar BowlerPolar GolferPreReqPrintProjectsPS_AIO_05_C309_Software_MinQuickTimeRalink RT5390R 802.11bgn Wi-Fi AdapterRapportRealDownloaderRealNetworks - Microsoft Visual C++ 2008 RuntimeRealNetworks - Microsoft Visual C++ 2010 RuntimeRealPlayerRealtek Ethernet Controller DriverRealtek PCIE Card ReaderRealUpgrade 1.1Roads of Rome 3SanDiskSecureAccess_Manager.exeScanShop for HP SuppliesSkypeâ„¢ 6.1SolutionCenterStatusSweetTunes Toolbar for IEswMSMSynaptics Pointing Device DriverTales of LagoonaThe Weather Channel AppToolboxTrayAppTrusteer Endpoint ProtectionUpdate Installer for WildTangent Games AppVacation Questâ„¢ - AustraliaVisual Studio 2010 x64 RedistributablesWebRegWildTangent GamesWildTangent Games AppWindows Live Communications PlatformWindows Live EssentialsWindows Live InstallerWindows Live Language SelectorWindows Live Movie MakerWindows Live Photo CommonWindows Live Photo GalleryWindows Live PIMT PlatformWindows Live SOXEWindows Live SOXE DefinitionsWindows Live UX PlatformWindows Live UX Platform Language PackWindows Live WriterWindows Live Writer ResourcesZuma's Revenge.==== Event Viewer Messages From Past Week ========.10/27/2013 8:22:00 PM, Error: Service Control Manager [7034] - The AVG WatchDog service terminated unexpectedly. It has done this 1 time(s).10/27/2013 8:21:09 PM, Error: Service Control Manager [7024] -10/27/2013 8:05:17 PM, Error: Service Control Manager [7022] - The AVG WatchDog service hung on starting..==== End Of File ===========================
-
DDS (Ver_2012-11-20.01) - NTFS_AMD64Internet Explorer: 10.0.9200.16537Run by Dave at 21:03:04 on 2013-10-27Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3682.2372 [GMT -6:00].AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}AV: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}.============== Running Processes ===============.C:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svchost.exe -k RPCSSC:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exeC:\Windows\system32\dwm.exeC:\Windows\system32\atiesrxx.exeC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\atieclxx.exeC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Program Files\IDT\WDM\STacSV64.exeC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeC:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exeC:\Windows\system32\svchost.exe -k apphostC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Windows\SysWOW64\svchost.exe -k hpdevmgmtC:\Windows\system32\dashost.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exeC:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exeC:\Windows\System32\svchost.exe -k HPZ12C:\Windows\System32\svchost.exe -k HPZ12C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exeC:\Windows\system32\svchost.exe -k imgsvcC:\Program Files\Synaptics\SynTP\SynTPEnh.exec:\Program Files\Microsoft Mouse and Keyboard Center\itype.exeC:\Windows\system32\taskhostex.exec:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exeC:\Windows\Explorer.EXEC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exeC:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exeC:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exeC:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exeC:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exeC:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exeC:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonationC:\Windows\system32\svchost.exe -k HPServiceC:\Windows\system32\SearchIndexer.exeC:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXEC:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exeC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exeC:\Program Files (x86)\Real\RealPlayer\Update\realsched.exeC:\Windows\System32\RuntimeBroker.exeC:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exeC:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exeC:\Windows\system32\svchost.exe -k SDRSVCC:\Windows\system32\taskhost.exeC:\Windows\system32\svchost.exe -k defragsvcC:\Windows\system32\SearchProtocolHost.exeC:\Windows\system32\SearchFilterHost.exeC:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Windows\System32\cscript.exe.============== Pseudo HJT Report ===============.mWinlogon: Userinit = userinit.exe,BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dllBHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dllBHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dlluRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrunuRun: [sanDiskSecureAccess_Manager.exe] C:\Users\Dave\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exemRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRunmRun: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /RmRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exemRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLYmRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exemRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottimemRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osbootdRun: [searchProtect] \SearchProtect\bin\cltmng.exeStartupFolder: C:\Users\Dave\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exeStartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ATHOME~1.LNK - C:\Program Files (x86)\AtHomeConnect\AtHomeConnect.exeStartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exeStartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exeStartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXEIE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dllIE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exeTCP: NameServer = 67.215.21.202 72.21.70.3TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06} : DHCPNameServer = 67.215.21.202 72.21.70.3TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}\375707562783 : DHCPNameServer = 68.87.77.130 68.87.72.130TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}\44166796466214C6F6E69716 : DHCPNameServer = 69.145.248.4 69.146.17.2 69.144.49.29TCP: Interfaces\{DC630F40-72F6-4549-BBE1-447BF8209C06}\C696E6B6379737 : DHCPNameServer = 67.215.21.202 72.21.70.3Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLLHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dllHandler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dllSSODL: WebCheck - <orphaned>mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chromemASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettingsx64-Run: [synTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exex64-Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exex64-Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - <orphaned>x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>x64-SSODL: WebCheck - <orphaned>.============= SERVICES / DRIVERS ===============.R0 amd_sata;amd_sata;C:\Windows\System32\Drivers\amd_sata.sys [2012-7-23 79528]R0 amd_xata;amd_xata;C:\Windows\System32\Drivers\amd_xata.sys [2012-7-23 26280]R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\Drivers\avgidsha.sys [2013-7-20 71480]R0 Avgloga;AVG Logging Driver;C:\Windows\System32\Drivers\avgloga.sys [2013-7-20 311608]R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\Drivers\avgmfx64.sys [2013-7-1 116536]R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\Drivers\avgrkx64.sys [2013-7-10 45880]R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\Drivers\avgidsdrivera.sys [2013-7-20 246072]R1 Avgwfpa;AVG Firewall Driver;C:\Windows\System32\Drivers\avgwfpa.sys [2013-7-9 248632]R1 CLVirtualDrive;CLVirtualDrive;C:\Windows\System32\Drivers\CLVirtualDrive.sys [2012-9-15 92536]R1 RapportCerberus_56758;RapportCerberus_56758;C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [2013-8-21 589872]R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-9-10 265872]R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-8-2 239616]R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-8-10 85504]R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-7-9 35232]R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-9-15 2451456]R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe [2009-8-5 284016]R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-10-26 418376]R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-10-26 701512]R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-9-10 1435928]R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-8-14 39056]R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-10-26 25928]R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2013-4-15 2482960]R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\Drivers\RtsPStor.sys [2012-9-15 339600]R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-9-15 683664]R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\Drivers\usbfilter.sys [2012-9-15 57000]R3 WirelessButtonDriver;HP Wireless Button Driver Service;C:\Windows\System32\Drivers\WirelessButtonDriver64.sys [2012-8-3 20288]S0 Avgboota;AVG Early Launch Anti-Malware Driver;C:\Windows\System32\Drivers\avgboota.sys [2012-10-26 20912]S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\Drivers\avgldx64.sys [2013-7-20 206648]S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-7-4 4939312]S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-7-23 283136]S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-2-5 235216]S3 RapportHades64;RapportHades64;C:\Windows\System32\Drivers\RapportHades64.sys [2012-12-26 266928]S3 RapportKE64;RapportKE64;C:\Windows\System32\Drivers\RapportKE64.sys [2012-12-26 295696]S3 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-9-10 384432]S3 SmbDrv;SmbDrv;C:\Windows\System32\Drivers\Smb_driver_AMDASF.sys [2012-9-15 41272]S3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2012-9-15 43832].=============== File Associations ===============.FileExt: .txt: textfile="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1" [userChoice].=============== Created Last 30 ================.2013-10-28 02:03:07 -------- d-----w- C:\Users\Dave\AppData\Local\Avg20132013-10-27 05:07:30 -------- d-----w- C:\Users\Dave\AppData\Roaming\Malwarebytes2013-10-27 05:07:08 -------- d-----w- C:\ProgramData\Malwarebytes2013-10-27 05:07:04 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys2013-10-27 05:07:04 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware2013-10-27 04:13:00 -------- d-----w- C:\Windows\ERUNT2013-10-27 04:05:45 -------- d-----w- C:\AdwCleaner2013-10-15 19:44:43 78296 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl2013-10-15 19:44:43 694232 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe2013-10-13 03:39:54 1374208 ----a-w- C:\Windows\System32\wdc.dll2013-10-13 03:39:53 566784 ----a-w- C:\Windows\System32\wvc.dll2013-10-13 03:39:45 1245696 ----a-w- C:\Windows\SysWow64\wdc.dll2013-10-13 03:39:44 462336 ----a-w- C:\Windows\System32\sysmon.ocx2013-10-13 03:39:42 399360 ----a-w- C:\Windows\SysWow64\sysmon.ocx2013-10-13 03:39:41 437248 ----a-w- C:\Windows\SysWow64\wvc.dll2013-10-13 03:36:01 10116608 ----a-w- C:\Windows\System32\twinui.dll2013-10-10 21:53:07 652288 ----a-w- C:\Windows\System32\comctl32.dll2013-10-10 21:53:07 541696 ----a-w- C:\Windows\SysWow64\comctl32.dll2013-10-10 21:53:02 534528 ----a-w- C:\Windows\SysWow64\uxtheme.dll2013-10-10 21:53:02 44032 ----a-w- C:\Windows\SysWow64\UXInit.dll2013-10-10 21:53:01 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll2013-10-10 21:53:01 2706432 ----a-w- C:\Windows\System32\mshtml.tlb2013-10-10 21:51:05 3959296 ----a-w- C:\Windows\System32\jscript9.dll2013-10-10 21:51:01 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll2013-10-10 21:50:58 108032 ----a-w- C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll2013-10-08 01:19:07 -------- d-----w- C:\Users\Dave\AppData\Local\Programs2013-10-08 01:18:15 -------- d-----w- C:\Users\Dave\AppData\Local\WordOv2013-10-08 01:18:13 -------- d-----w- C:\Users\Dave\AppData\Roaming\RealNetworks2013-10-08 01:16:56 -------- d-----w- C:\Program Files (x86)\RealNetworks2013-10-08 01:16:45 -------- d-----w- C:\ProgramData\RealNetworks2013-10-08 01:14:47 -------- d-----w- C:\Program Files (x86)\Common Files\xing shared2013-10-04 19:17:05 -------- d-----w- C:\Program Files\iPod2013-10-04 19:17:04 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF692013-10-04 19:17:04 -------- d-----w- C:\Program Files\iTunes2013-10-04 19:17:04 -------- d-----w- C:\Program Files (x86)\iTunes.==================== Find3M ====================.2013-10-08 01:13:30 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll2013-10-08 01:13:30 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll2013-10-02 02:57:03 46368 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys2013-09-22 23:28:06 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll2013-09-22 22:55:10 2241024 ----a-w- C:\Windows\System32\wininet.dll2013-09-11 05:18:30 266928 ----a-w- C:\Windows\System32\drivers\RapportHades64.sys2013-09-11 05:18:28 295696 ----a-w- C:\Windows\System32\drivers\RapportKE64.sys2013-08-23 05:11:57 4040192 ----a-w- C:\Windows\System32\win32k.sys2013-08-16 05:41:13 58200 ----a-w- C:\Windows\System32\drivers\dam.sys2013-08-16 05:39:26 2371728 ----a-w- C:\Windows\System32\WSService.dll2013-08-16 05:32:48 209200 ----a-w- C:\Windows\System32\NotificationUI.exe2013-08-16 05:22:22 40448 ----a-w- C:\Windows\System32\wuapp.exe2013-08-16 05:22:11 4917760 ----a-w- C:\Windows\System32\sppsvc.exe2013-08-16 05:20:30 105984 ----a-w- C:\Windows\System32\WinSetupUI.dll2013-08-15 22:43:21 35328 ----a-w- C:\Windows\SysWow64\wuapp.exe2013-08-15 22:43:07 84992 ----a-w- C:\Windows\SysWow64\wudriver.dll2013-08-15 22:43:07 126976 ----a-w- C:\Windows\SysWow64\wuwebv.dll2013-08-15 22:43:03 562688 ----a-w- C:\Windows\SysWow64\WSShared.dll2013-08-15 22:43:03 159232 ----a-w- C:\Windows\SysWow64\WSSync.dll2013-08-15 22:43:02 83968 ----a-w- C:\Windows\SysWow64\OEMLicense.dll2013-08-15 22:43:02 167424 ----a-w- C:\Windows\SysWow64\WSClient.dll2013-08-15 22:43:02 143872 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll2013-08-15 22:43:02 124928 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll2013-08-15 22:42:52 76800 ----a-w- C:\Windows\SysWow64\setupcln.dll2013-08-15 22:42:47 91648 ----a-w- C:\Windows\SysWow64\sppc.dll2013-08-10 05:21:51 448512 ----a-w- C:\Windows\System32\SettingSync.dll2013-08-10 05:21:51 128512 ----a-w- C:\Windows\System32\SettingSyncInfo.dll2013-08-10 03:58:51 356352 ----a-w- C:\Windows\SysWow64\SettingSync.dll2013-08-07 05:15:02 144896 ----a-w- C:\Windows\System32\tssdisai.dll2013-08-02 06:26:53 2304512 ----a-w- C:\Windows\System32\authui.dll2013-08-02 05:08:18 8858112 ----a-w- C:\Windows\SysWow64\twinui.dll2013-08-02 05:06:50 2035712 ----a-w- C:\Windows\SysWow64\authui.dll2013-08-01 10:41:31 2233688 ----a-w- C:\Windows\System32\drivers\tcpip.sys.============= FINISH: 21:04:25.81 ===============
-
Results of screen317's Security Check version 0.99.74x64 (UAC is enabled)Internet Explorer 10``````````````Antivirus/Firewall Check:``````````````Windows Firewall Enabled!AVG AntiVirus Free Edition 2013Windows DefenderAntivirus up to date! (On Access scanning disabled!)`````````Anti-malware/Other Utilities Check:`````````Malwarebytes Anti-Malware version 1.75.0.1300Adobe Flash Player 11.9.900.117Adobe Reader XIGoogle Chrome 30.0.1599.101Google Chrome 30.0.1599.69````````Process Check: objlist.exe by Laurent````````Malwarebytes Anti-Malware mbamservice.exeMalwarebytes Anti-Malware mbamgui.exeMalwarebytes' Anti-Malware mbamscheduler.exe`````````````````System Health check`````````````````Total Fragmentation on Drive C: %````````````````````End of Log``````````````````````
-
alwarebytes Anti-Malware (Trial) 1.75.0.1300www.malwarebytes.orgDatabase version: v2013.10.27.01Windows 8 x64 NTFSInternet Explorer 10.0.9200.16721Dave :: LAPTOP [administrator]Protection: Enabled10/27/2013 8:06:08 PMmbam-log-2013-10-27 (20-06-08).txtScan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 226101Time elapsed: 11 minute(s), 40 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 0(No malicious items detected)Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 0(No malicious items detected)(end)
Chuck I need help I am running slow
in Malware Removal
Posted
Thats fine I was just wondering if there was something that could be running in the back ground sucking up my memory I will see what happens Thanks