Jump to content

rigsby1208

Honorary Members
  • Posts

    57
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Hi I keep seeing a process appearing called Sp.exe in Windows task manager. It seems to be taking a lot of CPU . Is it normal or is it something I should be worried about? I normally notice it when my machines seems to be running a little slow, but no other noticeable symptoms. I have downloaded and run the latest malwarebytes software and database, which just identified several PUPs which I have now quarrantined
  2. thanks Mr c. Its good to know there are some good guys out there to protect the stupid guys from the bad guys!!

  3. ok, results below Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Disabled! Kaspersky Internet Security Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` Norton Ghost Malwarebytes Anti-Malware version 1.75.0.1300 CCleaner Java 6 Update 30 Java version out of Date! Adobe Flash Player 12.0.0.44 Adobe Reader 10.1.3 Adobe Reader out of Date! Mozilla Firefox (27.0.1) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe Kaspersky Lab Kaspersky Internet Security 2013 avp.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 0% ````````````````````End of Log``````````````````````
  4. seems better. I can now st firefox homepage to google and it stays set to it. Thanks for your help
  5. Hi thanks adwcleaner and malware logs below.. # AdwCleaner v3.018 - Report created 16/02/2014 at 18:29:46 # Updated 28/01/2014 by Xplode # Operating System : Windows 7 Professional Service Pack 1 (32 bits) # Username : Darren - DARREN-PC-SHED # Running from : C:\Users\Darren\Downloads\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\boost_interprocess Folder Deleted : C:\ProgramData\GameTap Web Player Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it! Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\GameTap Web Player Folder Deleted : C:\Program Files\myfree codec Folder Deleted : C:\Program Files\openit Folder Deleted : C:\Program Files\Retrogamer_4w Folder Deleted : C:\Program Files\Yontoo Layers Runtime Folder Deleted : C:\Users\Darren\AppData\Local\Conduit Folder Deleted : C:\Users\Darren\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Darren\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z Folder Deleted : C:\Users\lukas\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\Henry\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\Extensions\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8} Folder Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\Extensions\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8} Folder Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\Extensions\ffxtlbr@mysearchdial.com Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\GameTapPlayer@gametap.com File Deleted : C:\Users\Public\Desktop\Open It!.lnk File Deleted : C:\Users\Darren\AppData\Local\Temp\Uninstall.exe File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\searchplugins\Askcom.xml File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\searchplugins\Conduit.xml File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\searchplugins\Mysearchdial.xml File Deleted : C:\Users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\n54r5ozr.default\searchplugins\Mysearchdial.xml File Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\searchplugins\Mysearchdial.xml File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\user.js File Deleted : C:\Users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\n54r5ozr.default\user.js File Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\user.js ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Classes\RewardsArcade.BHO Key Deleted : HKLM\SOFTWARE\Classes\RewardsArcade.Sandbox Key Deleted : HKLM\SOFTWARE\Classes\RewardsArcade.Sandbox.1 Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Value Deleted : HKLM\SOFTWARE\mozilla\Firefox\Extensions [crossriderapp498@crossrider.com] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03123BB6-A811-407E-B323-66CF0BE510B1} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D757DBFC-1494-4647-A8B3-ABD654988DD8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3392CFEC-56F8-41EE-BDB4-4E301EFD2C93} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}] Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\Cr_Installer Key Deleted : HKCU\Software\dsiteproducts Key Deleted : HKCU\Software\IGearSettings Key Deleted : HKCU\Software\Myfree Codec Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Software\RewardsArcade Key Deleted : HKCU\Software\AppDataLow\Software\Toolbar Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Myfree Codec Key Deleted : HKLM\Software\Tarma Installer Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86C0E2A3-1EDA-4F01-A43D-80DA8642813C}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenIt Open It! ***** [ Browsers ] ***** -\\ Internet Explorer v0.0.0.0 Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] -\\ Mozilla Firefox v27.0.1 (en-GB) [ File : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\prefs.js ] Line Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Line Deleted : user_pref("browser.search.defaultenginename", "Mysearchdial"); Line Deleted : user_pref("browser.search.defaultthis.engineName", "Web Search"); Line Deleted : user_pref("browser.search.order.1", "Mysearchdial"); Line Deleted : user_pref("browser.search.selectedEngine", "Mysearchdial"); Line Deleted : user_pref("extensions.enabledItems", "{66E978CD-981F-47DF-AC42-E3CF417C1467}:0.4.3,{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6,{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6,{a0d7ccb3-214d-498b-b4aa-0e[...] Line Deleted : user_pref("extensions.mysearchdial.AL", 2); Line Deleted : user_pref("extensions.mysearchdial.aflt", "dsites0103"); Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); Line Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R"); Line Deleted : user_pref("extensions.mysearchdial.cntry", "GB"); Line Deleted : user_pref("extensions.mysearchdial.cr", "698970755"); Line Deleted : user_pref("extensions.mysearchdial.dfltLng", ""); Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true); Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true); Line Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...] Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false); Line Deleted : user_pref("extensions.mysearchdial.hdrMd5", "CF6E2C83B64F9DF7DB7D88ECDA4EC98C"); Line Deleted : user_pref("extensions.mysearchdial.hmpg", true); Line Deleted : user_pref("extensions.mysearchdial.id", "00235439D208F5EC"); Line Deleted : user_pref("extensions.mysearchdial.instlDay", "16095"); Line Deleted : user_pref("extensions.mysearchdial.instlRef", ""); Line Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.21.022:46:1"); Line Deleted : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}"); Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial"); Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); Line Deleted : user_pref("extensions.mysearchdial.sg", "none"); Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base"); Line Deleted : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0"); Line Deleted : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0"); Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true); Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false); Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none"); Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.022:46:1"); Line Deleted : user_pref("extentions.y2layers.defaultEnableAppsList", "Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,BestVideoDownloader,"); Line Deleted : user_pref("extentions.y2layers.installId", "8383dfc0-275d-42b5-afb8-50d347326a82"); Line Deleted : user_pref("extentions.y2layers.lastDnsTest", 371588); [ File : C:\Users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\n54r5ozr.default\prefs.js ] Line Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Line Deleted : user_pref("browser.search.defaultenginename", "Mysearchdial"); Line Deleted : user_pref("browser.search.order.1", "Ask.com"); Line Deleted : user_pref("browser.search.selectedEngine", "Mysearchdial"); Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); [ File : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\prefs.js ] Line Deleted : user_pref("browser.search.defaultengine", "Ask.com"); Line Deleted : user_pref("browser.search.defaultenginename", "Mysearchdial"); Line Deleted : user_pref("browser.search.order.1", "Mysearchdial"); Line Deleted : user_pref("browser.search.selectedEngine", "Mysearchdial"); Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", ""); Line Deleted : user_pref("extensions.enabledAddons", "%7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%7D:9.5.3,ffxtlbr%40mysearchdial.com:1.6.0,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0"); Line Deleted : user_pref("extensions.mysearchdial.AL", 2); Line Deleted : user_pref("extensions.mysearchdial.aflt", "dsites0103"); Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); Line Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R"); Line Deleted : user_pref("extensions.mysearchdial.cntry", "GB"); Line Deleted : user_pref("extensions.mysearchdial.cr", "698970755"); Line Deleted : user_pref("extensions.mysearchdial.dfltLng", ""); Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true); Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true); Line Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...] Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false); Line Deleted : user_pref("extensions.mysearchdial.hdrMd5", "491E27C441D89F0363B0DF7E42700AFD"); Line Deleted : user_pref("extensions.mysearchdial.hmpg", true); Line Deleted : user_pref("extensions.mysearchdial.id", "00235439D208F5EC"); Line Deleted : user_pref("extensions.mysearchdial.instlDay", "16095"); Line Deleted : user_pref("extensions.mysearchdial.instlRef", ""); Line Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", ""); Line Deleted : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}"); Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial"); Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); Line Deleted : user_pref("extensions.mysearchdial.sg", "{smplGrp}"); Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base"); Line Deleted : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0"); Line Deleted : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0"); Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true); Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false); Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none"); Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.022:46:1"); ************************* AdwCleaner[R0].txt - [19137 octets] - [16/02/2014 18:24:51] AdwCleaner[s0].txt - [19151 octets] - [16/02/2014 18:29:46] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [19212 octets] ########## Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2014.02.16.04 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Darren :: DARREN-PC-SHED [administrator] 16/02/2014 18:46:02 mbam-log-2014-02-16 (18-46-02).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 293169 Time elapsed: 10 minute(s), 58 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
  6. Thanks for helping . Rogue killer results.. RogueKiller V8.8.7 [Feb 11 2014] by Tigzy mail : tigzyRK<at>gmail<dot>com Feedback : http://forum.adlice.com Website : http://www.adlice.com/softwares/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version Started in : Normal mode User : Darren [Admin rights] Mode : Scan -- Date : 02/16/2014 00:17:21 | ARK || FAK || MBR | ¤¤¤ Bad processes : 1 ¤¤¤ [HJNAME] dllhost.exe -- C:\Windows\winsxs\x86_microsoft-windows-com-surrogate_31bf3856ad364e35_6.1.7600.16385_none_43fa44d954d596e7\dllhost.exe [7] -> KILLED [TermThr] ¤¤¤ Registry Entries : 4 ¤¤¤ [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_TrackProgs (0) -> FOUND [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND ¤¤¤ Scheduled tasks : 2 ¤¤¤ [V1][sUSP PATH] Digital Sites.job : C:\Users\Darren\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND [V2][sUSP PATH] Digital Sites : C:\Users\Darren\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND ¤¤¤ Startup Entries : 0 ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ Browser Addons : 0 ¤¤¤ ¤¤¤ Particular Files / Folders: ¤¤¤ ¤¤¤ Driver : [LOADED] ¤¤¤ ¤¤¤ External Hives: ¤¤¤ ¤¤¤ Infection : ¤¤¤ ¤¤¤ HOSTS File: ¤¤¤ --> %SystemRoot%\System32\drivers\etc\hosts ¤¤¤ MBR Check: ¤¤¤ +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HD103UJ ATA Device +++++ --- User --- [MBR] dee76aaee0c09ff438ff5519019e02a9 [bSP] 9377b04036c050cc028155580dd4c63e : Windows 7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 199900 Mo 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409602048 | Size: 753867 Mo User = LL1 ... OK! User = LL2 ... OK! +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) SAMSUNG HD103SI ATA Device +++++ --- User --- [MBR] 8278f456f89c1bd77d7e76f1e9e3662f [bSP] 2bdee771291ce8990d07229f3a71f8c6 : Empty MBR Code Partition table: 0 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 16065 | Size: 953859 Mo User = LL1 ... OK! User = LL2 ... OK! +++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ IDE) SAMSUNG HD154UI ATA Device +++++ --- User --- [MBR] cfa9ce03f2c65df473d39a62df60d82e [bSP] 6b643498de7e5c62b12120b7db36c3f2 : Windows XP MBR Code Partition table: 0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 1430796 Mo User = LL1 ... OK! User = LL2 ... OK! Finished : << RKreport[0]_S_02162014_001721.txt >>
  7. hi everytime I start firefox I'm redirected to a suspicious search page looking a bit like google but its not, its url is mysearchdial.com. I have run malware bytes and removed a few issus but my problem remains. Even if I set my homepage back to googe, next time I restart firefox i get taken to the mysearchdial page. DDS logs below DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: BrowserJavaVersion: 1.6.0_30 Run by Darren at 20:10:52 on 2014-02-15 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.3327.1266 [GMT 0:00] . AV: Kaspersky Internet Security *Enabled/Outdated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} SP: Kaspersky Internet Security *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\ASUS\Disk Unlocker\ASPFSVS.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe C:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Windows\system32\IProsetMonitor.exe C:\Program Files\Intel\Intel® Management Engine Components\DAL\jhi_service.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskhost.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe C:\Program Files\Ask.com\Updater\Updater.exe C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe C:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE C:\Program Files\Norton Ghost\Agent\VProTray.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Users\Darren\AppData\Roaming\Spotify\spotify.exe C:\Program Files\Plex\Plex Media Server\Plex Media Server.exe C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe C:\Users\Darren\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Windows\system32\taskeng.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe C:\Windows\system32\conhost.exe C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files\Plex\Plex Media Server\PlexDlnaServer.exe C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe C:\Windows\system32\sppsvc.exe C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Program Files\TrueCrypt\TrueCrypt.exe C:\Windows\servicing\TrustedInstaller.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\System32\svchost.exe -k secsvcs . ============== Pseudo HJT Report =============== . uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-502F5495E5FC} - c:\program files\ask.com\GenericAskToolbar.dll uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll uURLSearchHooks: <No Name>: {4cff1016-c2e2-4fdd-9c67-e32200c25ff9} - c:\program files\retrogamer_4w\bar\1.bin\4wSrcAs.dll mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\contentblocker\ie_content_blocker_plugin.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\onlinebanking\online_banking_bho.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Vuze Remote Toolbar: {BA14329E-9550-4989-B3F2-9732E92D17CC} - c:\program files\vuze_remote\prxtbVuze.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll TB: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files\conduitengine\prxConduitEngine.dll TB: Retrogamer: {3392cfec-56f8-41ee-bdb4-4e301efd2c93} - c:\program files\retrogamer_4w\bar\1.bin\4wbar.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE" uRun: [spotify Web Helper] "c:\users\darren\appdata\roaming\spotify\data\SpotifyWebHelper.exe" uRun: [spotify] "c:\users\darren\appdata\roaming\spotify\Spotify.exe" /uri spotify:autostart uRun: [Plex Media Server] "c:\program files\plex\plex media server\Plex Media Server.exe" mRun: [NUSB3MON] "c:\program files\nec electronics\usb 3.0 host controller driver\application\nusb3mon.exe" mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe" mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s mRun: [RtHDVBg_DTS] c:\program files\realtek\audio\hda\RtHDVBg.exe /DTSU2P mRun: [uSB3MON] "c:\program files\intel\intel® usb 3.0 extensible host controller driver\application\iusb3mon.exe" mRun: [igfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Norton Ghost 15.0] "c:\program files\norton ghost\agent\VProTray.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun StartupFolder: c:\users\darren\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\darren\appdata\roaming\dropbox\bin\Dropbox.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.8.130\SSScheduler.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2013\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\micros~1\office14\ONBttnIE.dll/105 IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll TCP: NameServer = 194.168.4.100 194.168.8.100 TCP: Interfaces\{BEDBC439-ECEF-4314-8AEF-93F6223AD375} : DHCPNameServer = 194.168.4.100 194.168.8.100 TCP: Interfaces\{EBB0FEDC-C9FD-4EEA-8A12-25AAFD1AE6EB} : DHCPNameServer = 194.168.4.100 194.168.8.100 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Notify: igfxcui - igfxdev.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SSODL: WebCheck - <orphaned> SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL mASetup: {61E3FE32-07B9-4563-A3E0-2DE2D620FE10} - c:\program files\pixiepack codec pack\InstallerHelper.exe . ================= FIREFOX =================== . FF - ProfilePath - c:\users\darren\appdata\roaming\mozilla\firefox\profiles\7tyee22d.default\ FF - prefs.js: browser.search.selectedEngine - Mysearchdial FF - prefs.js: keyword.URL - FF - component: c:\program files\mozilla firefox\extensions\kavantibanner@kaspersky.ru\components\abhelperxpcom.dll FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll FF - plugin: c:\progra~1\micros~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\canon\mycamera download plugin\NPCIG.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll FF - plugin: c:\program files\intel\intel® management engine components\ipt\npIntelWebAPIIPT.dll FF - plugin: c:\program files\intel\intel® management engine components\ipt\npIntelWebAPIUpdater.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mcafee security scan\3.8.130\npMcAfeeMSS.dll FF - plugin: c:\program files\microsoft silverlight\5.1.20913.0\npctrlui.dll FF - plugin: c:\program files\retrogamer_4w\bar\1.bin\NP4wStub.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_12_0_0_44.dll . ---- FIREFOX POLICIES ---- FF - user.js: extentions.y2layers.installId - 8383dfc0-275d-42b5-afb8-50d347326a82 FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,BestVideoDownloader, FF - user.js: extensions.mysearchdial.hmpg - true FF - user.js: extensions.mysearchdial.dfltSrch - true FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial FF - user.js: extensions.mysearchdial.dnsErr - true FF - user.js: extensions.mysearchdial_i.newTab - false FF - user.js: extensions.mysearchdial.id - 00235439D208F5EC FF - user.js: extensions.mysearchdial.instlDay - 16095 FF - user.js: extensions.mysearchdial.vrsn - 1.8.21.0 FF - user.js: extensions.mysearchdial.vrsni - 1.8.21.0 FF - user.js: extensions.mysearchdial_i.vrsnTs - 1.8.21.022:46:1 FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial FF - user.js: extensions.mysearchdial.prdct - mysearchdial FF - user.js: extensions.mysearchdial.aflt - dsites0103 FF - user.js: extensions.mysearchdial_i.smplGrp - none FF - user.js: extensions.mysearchdial.tlbrId - base FF - user.js: extensions.mysearchdial.instlRef - FF - user.js: extensions.mysearchdial.dfltLng - FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8} FF - user.js: extensions.mysearchdial.excTlbr - false FF - user.js: extensions.mysearchdial_i.hmpg - true FF - user.js: extensions.mysearchdial.cr - 698970755 FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R FF - user.js: extensions.mysearchdial.AL - 2 FF - user.js: extensions.irmysearch.aflt - dsites0103 FF - user.js: extensions.irmysearch.instlRef - FF - user.js: extensions.irmysearch.cr - 698970755 FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R . ============= SERVICES / DRIVERS =============== . R0 asahci32;asahci32;c:\windows\system32\drivers\asahci32.sys [2012-1-6 43104] R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys [2012-7-16 13592] R0 mv91xx;mv91xx;c:\windows\system32\drivers\mv91xx.sys [2010-3-17 261672] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2012-8-2 25696] R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2012-6-8 44000] R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2012-8-13 145040] R1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\drivers\VDiskBus32.sys [2010-9-21 38016] R2 ASDiskUnlocker;ASDiskUnlocker;c:\program files\asus\disk unlocker\ASPFSVS.exe [2010-12-2 185984] R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe -r --> c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe -r [?] R2 DTSAudioSvc;DTSAudioSvc;c:\program files\realtek\audio\hda\DTSU2PAuSrv32.exe [2012-7-16 190832] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\intel\icls client\HeciServer.exe [2012-2-2 458464] R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IPROSetMonitor.exe [2012-7-16 117920] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files\intel\intel® management engine components\dal\Jhi_service.exe [2012-7-16 161560] R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2014-1-25 418376] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2014-1-25 701512] R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2012-7-16 363800] R3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files\asus\disk unlocker\ASFLTDrv.sys [2010-9-16 17408] R3 GenericMount;Generic Mount Driver;c:\windows\system32\drivers\GenericMount.sys [2010-2-12 57840] R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2012-5-25 25696] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2012-7-25 25696] R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [2011-9-2 42648] R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [2011-9-2 12184] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-1-25 22856] R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2010-1-22 59904] R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2010-1-22 139648] R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2010-2-11 1964528] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files\samsung\allshare\allsharedms\AllShareDMS.exe [2012-1-19 25504] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2011-11-24 80184] S3 GenericMount Helper Service;GenericMount Helper Service;c:\program files\norton ghost\shared\drivers\GenericMountHelper.exe [2010-2-12 1574408] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2012-7-16 280576] S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys [2012-7-16 347928] S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys [2012-7-16 789272] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.8.130\McCHSvc.exe [2013-9-6 235216] S3 MEI;Intel® Management Engine Interface ;c:\windows\system32\drivers\HECI.sys [2012-7-16 46080] S3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files\samsung\allshare\AllShareSlideShowService.exe [2012-1-19 27584] S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2011-11-24 181432] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992] S3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2009-7-13 7168] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-21 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-12-11 1343400] . =============== Created Last 30 ================ . 2014-02-15 19:45:07 7760024 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{ffa385db-9e6c-463c-9cb7-917db6229c5a}\mpengine.dll 2014-01-31 22:30:55 -------- d-----w- c:\program files\ZipGenius 6 2014-01-25 23:01:06 -------- d-----w- c:\users\darren\appdata\roaming\Malwarebytes 2014-01-25 23:01:00 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-01-25 23:01:00 -------- d-----w- c:\programdata\Malwarebytes 2014-01-25 23:00:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2014-01-25 22:46:10 -------- d-----w- c:\users\darren\appdata\roaming\0D0S1L2Z1P1B0T1P1B2Z 2014-01-25 22:46:02 -------- d-----w- c:\users\darren\appdata\roaming\DigitalSites 2014-01-25 22:46:00 -------- d-----w- c:\program files\OpenIt 2014-01-17 22:03:10 2349056 ----a-w- c:\windows\system32\win32k.sys 2014-01-17 22:03:08 240576 ----a-w- c:\windows\system32\drivers\netio.sys 2014-01-17 22:03:01 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2014-01-17 22:03:01 6016 ----a-w- c:\windows\system32\drivers\usbd.sys 2014-01-17 22:03:01 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys 2014-01-17 22:03:01 284672 ----a-w- c:\windows\system32\drivers\usbport.sys 2014-01-17 22:03:01 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys 2014-01-17 22:03:01 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2014-01-17 22:03:01 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys . ==================== Find3M ==================== . 2014-02-09 19:35:06 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-02-09 19:35:06 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-12-18 06:13:56 231584 ------w- c:\windows\system32\MpSigStub.exe 2013-12-12 21:30:48 25696 ----a-w- c:\windows\system32\drivers\klim6.sys 2013-12-12 21:30:48 135776 ----a-w- c:\windows\system32\drivers\kl1.sys 2013-11-23 18:26:20 417792 ----a-w- c:\windows\system32\WMPhoto.dll . ============= FINISH: 20:12:12.34 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Professional Boot Device: \Device\HarddiskVolume1 Install Date: 10/12/2010 17:28:24 System Uptime: 15/02/2014 20:04:54 (0 hours ago) . Motherboard: ASUSTeK Computer INC. | | P5Q-PRO Processor: Intel® Core2 Quad CPU Q6600 @ 2.40GHz | LGA 775 | 2403/266mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 736 GiB total, 480.156 GiB free. D: is FIXED (NTFS) - 195 GiB total, 42.186 GiB free. E: is CDROM () F: is FIXED (NTFS) - 1397 GiB total, 1227.694 GiB free. G: is FIXED (NTFS) - 932 GiB total, 138.948 GiB free. Z: is FIXED (FAT32) - 325 GiB total, 9.163 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP318: 05/01/2014 20:45:50 - Windows Update RP319: 05/01/2014 22:10:33 - Plex Media Server RP320: 05/01/2014 22:13:40 - Plex Media Server RP321: 11/01/2014 20:05:35 - Windows Update RP322: 17/01/2014 22:03:08 - Windows Update RP323: 18/01/2014 02:37:36 - Windows Update RP324: 21/01/2014 18:34:25 - Windows Update RP325: 25/01/2014 18:08:41 - Windows Update RP326: 31/01/2014 22:15:54 - Windows Update RP327: 09/02/2014 18:36:11 - Windows Update RP328: 15/02/2014 19:44:25 - Windows Update . ==== Installed Programs ====================== . Adobe AIR Adobe Flash Player 12 ActiveX Adobe Flash Player 12 Plugin Adobe Reader X (10.1.3) Air Playit 2.0.0 Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft ShowBiz Ask Toolbar Ask Toolbar Updater Asmedia ASM106x SATA Host Controller Driver Bonjour CANON iMAGE GATEWAY MyCamera Download Plugin CANON iMAGE GATEWAY Task for ZoomBrowser EX Canon Internet Library for ZoomBrowser EX Canon MOV Decoder Canon MOV Encoder Canon MovieEdit Task for ZoomBrowser EX Canon My Printer Canon RAW Codec Canon Utilities CameraWindow Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities Digital Photo Professional 3.9 Canon Utilities EOS Utility Canon Utilities MyCamera Canon Utilities Original Data Security Tools Canon Utilities PhotoStitch Canon Utilities Picture Style Editor Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities WFT-E1/E2/E3/E4 Utility Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CCleaner Conduit Engine dBpoweramp DSP Effects dBpoweramp m4a Codec dBpoweramp m4a Nero AAC Encoder dBpoweramp Music Converter Debut Video Capture Software Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Disk Unlocker Dropbox DVDFab 8.1.9.8 (27/07/2012) Qt eReg Express Zip File Compression Software GameTap Web Player Google Earth Google Toolbar for Internet Explorer Google Update Helper HandBrake 0.9.8 Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678) iCloud ImgBurn Intel® Management Engine Components Intel® Network Connections 16.6.126.0 Intel® OpenCL CPU Runtime Intel® Processor Graphics Intel® USB 3.0 eXtensible Host Controller Driver Intel® Trusted Connect Service Client iTunes Java Auto Updater Java 6 Update 30 Kaspersky Internet Security 2013 LiveUpdate 3.2 (Symantec Corporation) Logitech SetPoint 6.32 Malwarebytes Anti-Malware version 1.75.0.1300 marvell 91xx driver McAfee Security Scan Plus Microsoft .NET Framework 4 Client Profile Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 MobileMe Control Panel Mozilla Firefox 26.0 (x86 en-GB) Mozilla Maintenance Service MyFreeCodec NEC Electronics USB 3.0 Host Controller Driver Norton Ghost Open It! Photomatix Pro version 4.0.2 PixiePack Codec Pack Plex Media Server QuickTime Realtek HDMI Audio Driver for ATI Realtek High Definition Audio Driver Retrogamer toolbar Samsung AllShare Samsung Kies SAMSUNG USB Driver for Mobile Phones Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2) Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition Spotify TrueCrypt Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition USB Video/Audio Device Driver VideoPad Video Editor VLC media player 2.1.3 Vuze Vuze Remote Toolbar WinX DVD Ripper Platinum 6.9.0 WinZip 17.0 Wisdom-soft Set up ScreenHunter 5.1 Free WonderGate Server Yontoo Layers Runtime 1.10.01 Zip Opener Packages ZipGenius 6.3 . ==== Event Viewer Messages From Past Week ======== . 09/02/2014 18:24:30, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service. . ==== End Of File =========================== thanks for looking
  8. OK I guess, but like I said the only symptoms I had were the issues in firefox, but I have reset so new tabs and my homepage are back to Google. I guess if you cant see any issues all is well now.
  9. Hi Yes I can re install them, but I'm not clear, is the underlying virus which reset everything gone now?
  10. Its difficult to know if the underlying issue has been resolved. The symptoms I saw were the home page being reset to Delta search, and new tabs opening to Delta search. I have reset these back to Google now and have stayed set correctly. I also noticed the other day that some of my firefox add-ons were also disabled such as Kaspersky URL adviser, WOT, safe money, content blocker, etc. which I presumed was the viruses work. I dont seem to have an option to renable them. I have subsequently renabled WOT, as that was at least throwing up a warning about the Delta search site when opening a new tab etc.
  11. All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found. HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\SearchScopes\{700F9637-8FFE-4759-ACDA-902AA7E96400}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{700F9637-8FFE-4759-ACDA-902AA7E96400}\ not found. ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. E:\Users\darren\Desktop\cmd.bat deleted successfully. E:\Users\darren\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: darren ->Temp folder emptied: 2606049743 bytes ->Temporary Internet Files folder emptied: 242011278 bytes ->Java cache emptied: 986898 bytes ->Flash cache emptied: 1374 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Henry ->Temp folder emptied: 163330992 bytes ->Temporary Internet Files folder emptied: 671994315 bytes ->Java cache emptied: 193017 bytes ->FireFox cache emptied: 444042703 bytes ->Flash cache emptied: 39765 bytes User: Jo ->Temp folder emptied: 37658963 bytes ->Temporary Internet Files folder emptied: 598901786 bytes ->Java cache emptied: 2633961 bytes ->FireFox cache emptied: 80336096 bytes ->Flash cache emptied: 17529 bytes User: Public ->Temp folder emptied: 0 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 679120692 bytes RecycleBin emptied: 11844866632 bytes Total Files Cleaned = 16,567.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 09172013_221920 Files\Folders moved on Reboot... E:\Users\darren\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{25B86FBD-77FB-4340-A2DA-B27E09F9DF70}.tmp not found! File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{54288C23-B5AB-4E86-99AC-00D6B45BDE8F}.tmp not found! File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6D1683C6-CD7D-4D8E-8D6D-C3F94100A5E3}.tmp not found! File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6E3F9CF1-1405-4FC3-8FF1-016DE70FDDF5}.tmp not found! File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{DE3F9145-3A1C-47D0-BB62-C312CA42E0D9}.tmp not found! E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. File\Folder E:\Users\Henry\AppData\Local\Temp\~DFF786BE6FD9DBB338.TMP not found! File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{0F4A7821-C5FE-4975-88CD-0909A99EA4C5}.tmp not found! File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3F39B27B-DC47-4A8C-B437-2B9E4673C550}.tmp not found! File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C420126A-4312-4EFF-8898-3AEA5BFD9E25}.tmp not found! File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{ECC8E422-5370-4947-8CED-E8FCE97023C1}.tmp not found! File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{EE2248A9-E50B-45E6-905E-B5FA43CAFE52}.tmp not found! E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot...
  12. Hi Apologies for the dely. OTL reports below... OTL logfile created on: 9/15/2013 7:23:13 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = E:\Users\darren\Desktop Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16686) Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 3.47 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 68.68% Memory free 6.94 Gb Paging File | 4.63 Gb Available in Paging File | 66.75% Paging File free Paging file location(s): d:\pagefile.sys 0 0 [binary data] %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files Drive C: | 1863.01 Gb Total Space | 91.47 Gb Free Space | 4.91% Space Free | Partition Type: NTFS Drive D: | 1863.01 Gb Total Space | 241.21 Gb Free Space | 12.95% Space Free | Partition Type: NTFS Drive E: | 119.23 Gb Total Space | 42.68 Gb Free Space | 35.80% Space Free | Partition Type: NTFS Drive F: | 1397.26 Gb Total Space | 547.87 Gb Free Space | 39.21% Space Free | Partition Type: NTFS Drive H: | 1397.26 Gb Total Space | 304.60 Gb Free Space | 21.80% Space Free | Partition Type: NTFS Drive I: | 1863.01 Gb Total Space | 789.75 Gb Free Space | 42.39% Space Free | Partition Type: NTFS Drive J: | 1863.01 Gb Total Space | 48.70 Gb Free Space | 2.61% Space Free | Partition Type: NTFS Computer Name: DARREN-PC | User Name: darren | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (All) ========== PRC - [2013/09/15 19:20:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL - Copy.exe PRC - [2013/08/22 14:00:26 | 001,093,464 | ---- | M] (Garmin Ltd or its subsidiaries) -- E:\Program Files\Garmin\Express Tray\ExpressTray.exe PRC - [2013/08/22 14:00:04 | 000,220,504 | ---- | M] (Garmin Ltd or its subsidiaries) -- E:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe PRC - [2013/08/16 09:07:58 | 000,152,392 | ---- | M] (Apple Inc.) -- E:\Program Files\iTunes\iTunesHelper.exe PRC - [2013/08/16 09:07:50 | 000,553,288 | ---- | M] (Apple Inc.) -- E:\Program Files\iPod\bin\iPodService.exe PRC - [2013/08/03 18:09:18 | 000,409,776 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Microsoft Office\Office12\WINWORD.EXE PRC - [2013/08/02 01:52:57 | 000,271,360 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\conhost.exe PRC - [2013/07/06 11:20:13 | 004,640,768 | ---- | M] (Spotify Ltd) -- E:\Users\Henry\AppData\Roaming\Spotify\spotify.exe PRC - [2013/07/06 11:20:13 | 001,104,384 | ---- | M] (Spotify Ltd) -- E:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe PRC - [2013/06/27 16:11:08 | 020,097,696 | ---- | M] (Google) -- E:\Program Files\Google\Drive\googledrivesync.exe PRC - [2013/06/21 00:52:00 | 007,345,664 | ---- | M] (Google Inc.) -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\MusicManager.exe PRC - [2013/06/05 18:28:40 | 027,370,808 | ---- | M] (Dropbox, Inc.) -- E:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2013/06/05 18:28:40 | 027,370,808 | ---- | M] (Dropbox, Inc.) -- E:\Users\darren\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2013/06/03 17:25:26 | 000,033,928 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe PRC - [2013/06/03 17:25:24 | 001,563,784 | ---- | M] (Plex, Inc.) -- E:\Program Files\Plex\Plex Media Server\PlexDlnaServer.exe PRC - [2013/06/03 17:25:22 | 003,997,832 | ---- | M] (Plex, Inc.) -- E:\Program Files\Plex\Plex Media Server\Plex Media Server.exe PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2013/03/19 03:49:16 | 000,069,632 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\smss.exe PRC - [2013/01/27 12:08:19 | 000,116,648 | ---- | M] (Google Inc.) -- E:\Users\darren\AppData\Local\Google\Update\GoogleUpdate.exe PRC - [2013/01/18 15:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- E:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe PRC - [2013/01/18 15:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- E:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2013/01/18 15:20:08 | 000,639,776 | ---- | M] (NVIDIA Corporation) -- E:\Windows\System32\nvvsvc.exe PRC - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2013/01/06 13:08:03 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe PRC - [2013/01/05 23:09:31 | 000,116,648 | ---- | M] (Google Inc.) -- E:\Program Files\Google\Update\GoogleUpdate.exe PRC - [2012/12/21 16:27:46 | 000,057,008 | ---- | M] (Apple Inc.) -- E:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe PRC - [2012/12/06 12:14:42 | 000,056,416 | ---- | M] (Apple Inc.) -- E:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe PRC - [2012/11/28 15:13:24 | 000,013,712 | ---- | M] (Apple Inc.) -- E:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe PRC - [2012/11/23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\taskhost.exe PRC - [2012/09/17 07:39:30 | 000,171,600 | ---- | M] (Adobe Systems Incorporated) -- E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe PRC - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/26 04:21:03 | 000,196,608 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\WUDFHost.exe PRC - [2012/06/12 11:18:56 | 000,224,960 | ---- | M] () -- E:\Program Files\Macrium\Reflect\ReflectService.exe PRC - [2012/03/28 02:28:44 | 000,735,168 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\Citrix\ICA Client\wfcrun32.exe PRC - [2012/03/28 02:27:06 | 000,309,184 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\Citrix\ICA Client\concentr.exe PRC - [2012/02/28 16:06:48 | 010,468,672 | ---- | M] () -- E:\Program Files\Digiarty\Air_Playit\airplayit.exe PRC - [2012/02/28 16:06:40 | 001,607,488 | ---- | M] (Digiarty, Inc.) -- E:\Program Files\Digiarty\Air_Playit\AirPS.exe PRC - [2012/02/22 06:59:18 | 001,493,120 | R--- | M] (ASUSTeK Computer Inc.) -- E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe PRC - [2012/02/17 07:26:00 | 000,149,120 | R--- | M] (ASUSTeK Computer Inc.) -- E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe PRC - [2012/02/11 06:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\spoolsv.exe PRC - [2012/02/10 07:39:30 | 005,646,952 | ---- | M] (Realtek Semiconductor) -- E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe PRC - [2012/02/02 10:56:35 | 000,951,936 | R--- | M] (ASUSTeK Computer Inc.) -- E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe PRC - [2012/01/23 15:28:50 | 000,190,832 | ---- | M] (DTS, Inc) -- E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe PRC - [2012/01/04 20:59:50 | 000,291,608 | R--- | M] (Intel Corporation) -- E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe PRC - [2011/11/17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\lsass.exe PRC - [2011/10/29 02:59:26 | 000,918,448 | R--- | M] () -- E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe PRC - [2011/08/31 00:05:02 | 000,390,504 | ---- | M] (Apple Inc.) -- E:\Program Files\Bonjour\mDNSResponder.exe PRC - [2011/08/15 18:38:50 | 000,117,920 | ---- | M] (Intel Corporation) -- E:\Windows\System32\IPROSetMonitor.exe PRC - [2011/06/16 18:00:28 | 000,315,256 | ---- | M] (Adobe Systems Incorporated) -- E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe PRC - [2011/05/04 05:28:31 | 000,427,520 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\SearchIndexer.exe PRC - [2011/05/04 05:28:31 | 000,164,352 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\SearchProtocolHost.exe PRC - [2011/05/04 05:28:31 | 000,086,528 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\SearchFilterHost.exe PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- E:\Windows\explorer.exe PRC - [2010/11/20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Windows Media Player\wmpnetwk.exe PRC - [2010/11/20 13:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\wbem\WmiPrvSE.exe PRC - [2010/11/20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\winlogon.exe PRC - [2010/11/20 13:17:47 | 000,192,000 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\taskeng.exe PRC - [2010/11/20 13:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Windows Sidebar\sidebar.exe PRC - [2010/11/20 13:17:16 | 000,267,776 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\lsm.exe PRC - [2010/11/20 13:17:16 | 000,010,752 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\LogonUI.exe PRC - [2009/07/14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\wininit.exe PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\services.exe PRC - [2009/07/14 02:14:24 | 000,157,184 | ---- | M] (Microsoft Corporation) -- e:\Program Files\Windows Defender\MpCmdRun.exe PRC - [2009/07/14 02:14:19 | 000,092,672 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\dwm.exe PRC - [2009/07/14 02:14:16 | 000,006,144 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\csrss.exe PRC - [2007/04/04 02:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- E:\Program Files\Canon\MyPrinter\BJMYPRT.EXE ========== Modules (No Company Name) ========== MOD - [2013/09/14 10:31:24 | 001,175,040 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._core_.pyd MOD - [2013/09/14 10:31:24 | 001,153,024 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_ssl.pyd MOD - [2013/09/14 10:31:24 | 001,062,400 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._controls_.pyd MOD - [2013/09/14 10:31:24 | 000,811,008 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._windows_.pyd MOD - [2013/09/14 10:31:24 | 000,805,888 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._gdi_.pyd MOD - [2013/09/14 10:31:24 | 000,735,232 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._misc_.pyd MOD - [2013/09/14 10:31:24 | 000,711,680 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_hashlib.pyd MOD - [2013/09/14 10:31:24 | 000,686,080 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\unicodedata.pyd MOD - [2013/09/14 10:31:24 | 000,557,056 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\pysqlite2._sqlite.pyd MOD - [2013/09/14 10:31:24 | 000,504,832 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\windows._cacheinvalidation.pyd MOD - [2013/09/14 10:31:24 | 000,364,544 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\pythoncom27.dll MOD - [2013/09/14 10:31:24 | 000,320,512 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32com.shell.shell.pyd MOD - [2013/09/14 10:31:24 | 000,128,512 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_elementtree.pyd MOD - [2013/09/14 10:31:24 | 000,127,488 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\pyexpat.pyd MOD - [2013/09/14 10:31:24 | 000,122,368 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._wizard.pyd MOD - [2013/09/14 10:31:24 | 000,119,808 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32file.pyd MOD - [2013/09/14 10:31:24 | 000,110,080 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\PyWinTypes27.dll MOD - [2013/09/14 10:31:24 | 000,108,544 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32security.pyd MOD - [2013/09/14 10:31:24 | 000,098,816 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32api.pyd MOD - [2013/09/14 10:31:24 | 000,087,040 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_ctypes.pyd MOD - [2013/09/14 10:31:24 | 000,070,656 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._html2.pyd MOD - [2013/09/14 10:31:24 | 000,044,032 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_socket.pyd MOD - [2013/09/14 10:31:24 | 000,038,912 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32inet.pyd MOD - [2013/09/14 10:31:24 | 000,035,840 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32process.pyd MOD - [2013/09/14 10:31:24 | 000,026,624 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_multiprocessing.pyd MOD - [2013/09/14 10:31:24 | 000,025,600 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32pdh.pyd MOD - [2013/09/14 10:31:24 | 000,022,528 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32ts.pyd MOD - [2013/09/14 10:31:24 | 000,018,432 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32event.pyd MOD - [2013/09/14 10:31:24 | 000,017,408 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32profile.pyd MOD - [2013/09/14 10:31:24 | 000,011,264 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32crypt.pyd MOD - [2013/09/14 10:31:24 | 000,010,240 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\select.pyd MOD - [2013/08/22 03:05:06 | 001,226,752 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\4e7b7262234d31e42cb34d72ddb1a14b\System.WorkflowServices.ni.dll MOD - [2013/08/22 03:04:52 | 001,141,760 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b7ed4fb85e3e4d8b012dfd3a7c0435eb\System.ServiceModel.Discovery.ni.dll MOD - [2013/08/22 03:04:52 | 000,369,664 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\3a5eadca5d17af2aa06a4b5f40b588a6\System.ServiceModel.Routing.ni.dll MOD - [2013/08/22 03:04:51 | 000,082,432 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\1a335f477a925de13d86b720392a2b2e\System.ServiceModel.Channels.ni.dll MOD - [2013/08/22 03:04:45 | 001,394,176 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d301978a7b9dbe3f69c166bf00d5b858\System.ServiceModel.Activities.ni.dll MOD - [2013/08/22 03:04:43 | 018,101,760 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\8e155e090e2990b5afc341a2b068835b\System.ServiceModel.ni.dll MOD - [2013/08/22 03:04:43 | 001,078,272 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\d562a607bb4973993b59456d35f6307f\System.IdentityModel.ni.dll MOD - [2013/08/22 03:04:36 | 001,087,488 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d7a30ba1e54ebb51f5bb79780aaf13e5\System.ServiceModel.Web.ni.dll MOD - [2013/08/22 03:03:52 | 001,021,952 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\0442e1dc48d826e9b795d1e67d552791\System.Runtime.DurableInstancing.ni.dll MOD - [2013/08/22 03:03:52 | 000,649,728 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\9f37a2a23772a8e9dcbef5c6b6ebe0ad\System.Transactions.ni.dll MOD - [2013/08/22 03:03:52 | 000,143,360 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\12d171dd78ad02e8561a46bf266c5394\SMDiagnostics.ni.dll MOD - [2013/08/22 03:03:51 | 002,647,552 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\0a3d8f846e42d481c0cc2200b7859858\System.Runtime.Serialization.ni.dll MOD - [2013/08/22 03:03:50 | 000,393,216 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\e77f989b5dae0c6d2367d534c73a31f9\System.Xml.Linq.ni.dll MOD - [2013/08/22 03:03:40 | 001,801,728 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\44d87641535e186f4a7fc9c469bc73dd\System.Xaml.ni.dll MOD - [2013/08/22 03:02:03 | 018,003,456 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a342a61dd88db0c26a11470ce6a4f167\PresentationFramework.ni.dll MOD - [2013/08/22 03:01:56 | 013,199,360 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\6da40f01a719972f3242d3c374e499c5\System.Windows.Forms.ni.dll MOD - [2013/08/22 03:01:56 | 011,451,904 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\42c02d5f442dea943fc7def7b864bb90\PresentationCore.ni.dll MOD - [2013/08/22 03:01:53 | 007,070,720 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\5c4f1eb1b2efdd138d137c5069a8bdf5\System.Core.ni.dll MOD - [2013/08/22 03:01:53 | 000,595,968 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\4f02f7d34c4fd0dc58ce1dffb5b424f9\PresentationFramework.Aero.ni.dll MOD - [2013/08/22 03:01:51 | 005,628,928 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\0835155203a99b6a9bb540629920da0d\System.Xml.ni.dll MOD - [2013/08/22 03:01:51 | 003,858,944 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\6a1d260372cda12056515b30b2bcf715\WindowsBase.ni.dll MOD - [2013/08/22 03:01:51 | 001,667,584 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\7e3570a0cc71998e14e7adb8e4ea0cbb\System.Drawing.ni.dll MOD - [2013/08/22 03:01:50 | 001,014,272 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\da18beba41f700dd4c71a3f5464c4342\System.Configuration.ni.dll MOD - [2013/08/22 03:01:49 | 009,099,776 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System\fc16a5cafc433e6d942e9bd5b14fbeaf\System.ni.dll MOD - [2013/07/11 22:21:50 | 014,418,432 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\c799474a067f07ef3a167d75029fa012\mscorlib.ni.dll MOD - [2013/06/21 00:41:50 | 000,344,064 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll MOD - [2013/06/21 00:41:28 | 000,231,936 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll MOD - [2013/06/21 00:40:36 | 000,253,440 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libid3tag.dll MOD - [2013/06/21 00:40:00 | 000,117,248 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libaacdec.dll MOD - [2013/06/03 17:26:02 | 000,033,416 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd MOD - [2013/06/03 17:26:00 | 000,196,232 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\lxml\objectify.pyd MOD - [2013/06/03 17:26:00 | 000,057,992 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\OpenSSL\crypto.pyd MOD - [2013/06/03 17:26:00 | 000,044,680 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\OpenSSL\SSL.pyd MOD - [2013/06/03 17:26:00 | 000,017,544 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\OpenSSL\rand.pyd MOD - [2013/06/03 17:25:58 | 000,841,864 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\lxml\etree.pyd MOD - [2013/06/03 17:25:58 | 000,825,480 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_ssl.pyd MOD - [2013/06/03 17:25:56 | 000,050,312 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_socket.pyd MOD - [2013/06/03 17:25:56 | 000,033,928 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_multiprocessing.pyd MOD - [2013/06/03 17:25:54 | 000,366,216 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_hashlib.pyd MOD - [2013/06/03 17:25:54 | 000,094,344 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_ctypes.pyd MOD - [2013/06/03 17:25:52 | 000,590,472 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\unicodedata.pyd MOD - [2013/06/03 17:25:52 | 000,134,792 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\pyexpat.pyd MOD - [2013/06/03 17:25:52 | 000,017,544 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\select.pyd MOD - [2013/06/03 17:25:50 | 000,072,840 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\zlib1.dll MOD - [2013/06/03 17:25:48 | 008,495,240 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\WebKit.dll MOD - [2013/06/03 17:25:48 | 000,629,384 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\tag.dll MOD - [2013/06/03 17:25:46 | 000,293,264 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\swscale-0.dll MOD - [2013/06/03 17:25:44 | 000,089,224 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\soci_core-vc80-3_0.dll MOD - [2013/06/03 17:25:44 | 000,051,848 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll MOD - [2013/06/03 17:25:40 | 000,173,704 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\libxslt.dll MOD - [2013/06/03 17:25:38 | 000,839,816 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\libxml2.dll MOD - [2013/06/03 17:25:36 | 000,063,624 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\libexslt.dll MOD - [2013/06/03 17:25:34 | 001,291,400 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\JavaScriptCore.dll MOD - [2013/06/03 17:25:30 | 001,038,984 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\cairo.dll MOD - [2013/06/03 17:25:30 | 000,952,968 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\CFLite.dll MOD - [2013/06/03 17:25:28 | 005,828,368 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\avcodec-52.dll MOD - [2013/06/03 17:25:28 | 001,255,128 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\avformat-52.dll MOD - [2013/06/03 17:25:28 | 000,272,072 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\avutil-50.dll MOD - [2013/06/03 17:25:26 | 000,033,928 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe MOD - [2013/03/13 21:48:52 | 024,978,944 | ---- | M] () -- E:\Users\darren\AppData\Roaming\Dropbox\bin\libcef.dll MOD - [2013/01/10 21:01:44 | 000,026,624 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll MOD - [2013/01/10 21:01:26 | 010,683,392 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll MOD - [2013/01/10 21:01:24 | 001,681,408 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll MOD - [2013/01/10 21:01:22 | 007,741,952 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtGui4.dll MOD - [2013/01/10 21:01:20 | 002,248,192 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtCore4.dll MOD - [2012/11/14 00:32:50 | 003,558,400 | ---- | M] () -- E:\Users\darren\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll MOD - [2012/08/17 22:38:56 | 000,479,160 | ---- | M] () -- E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll MOD - [2012/05/30 21:06:48 | 000,087,912 | ---- | M] () -- E:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012/05/30 21:06:30 | 001,242,512 | ---- | M] () -- E:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ========== Services (SafeList) ========== SRV - [2013/09/10 18:13:13 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- E:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/08/22 14:00:04 | 000,220,504 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- E:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service) SRV - [2013/08/21 12:56:50 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013/05/27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2013/02/26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2013/01/06 13:08:03 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe -- (AVP) SRV - [2012/09/17 07:39:30 | 000,171,600 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor11.0) SRV - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012/07/21 14:18:11 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2012/06/12 11:18:56 | 000,224,960 | ---- | M] () [Auto | Running] -- E:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService.exe) SRV - [2012/03/20 00:44:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- E:\Windows\System32\IntelCpHeciSvc.exe -- (cphs) SRV - [2012/02/22 06:59:18 | 001,493,120 | R--- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe -- (AsusFanControlService) SRV - [2012/02/17 07:26:00 | 000,149,120 | R--- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe -- (AsSysCtrlService) SRV - [2012/02/02 10:56:35 | 000,951,936 | R--- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe -- (asHmComSvc) SRV - [2012/01/23 15:28:50 | 000,190,832 | ---- | M] (DTS, Inc) [Auto | Running] -- E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe -- (DTSAudioSvc) SRV - [2011/10/29 02:59:26 | 000,918,448 | R--- | M] () [Auto | Running] -- E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe -- (asComSvc) SRV - [2011/09/27 20:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- E:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ) SRV - [2011/08/15 18:38:50 | 000,117,920 | ---- | M] (Intel Corporation) [Auto | Running] -- E:\Windows\System32\IPROSetMonitor.exe -- (Intel® SRV - [2011/05/27 11:07:36 | 000,160,768 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- E:\Program Files\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe -- (ICCS) SRV - [2009/07/14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\StorSvc.dll -- (StorSvc) SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- E:\Users\darren\AppData\Local\Temp\ALSysIO.sys -- (ALSysIO) DRV - [2013/09/11 20:25:57 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy) DRV - [2013/06/18 21:22:01 | 000,044,000 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- E:\Windows\System32\drivers\kltdi.sys -- (kltdi) DRV - [2013/04/22 09:04:15 | 000,594,528 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- E:\Windows\System32\drivers\klif.sys -- (KLIF) DRV - [2013/04/22 09:04:15 | 000,145,040 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- E:\Windows\System32\drivers\kneps.sys -- (kneps) DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- E:\Windows\System32\drivers\mbam.sys -- (MBAMProtector) DRV - [2013/02/26 00:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2013/02/18 13:59:44 | 000,452,816 | ---- | M] (Paragon) [Kernel | System | Running] -- E:\Windows\System32\drivers\Uim_IM.sys -- (Uim_IM) DRV - [2013/02/18 13:59:44 | 000,283,600 | ---- | M] (Paragon) [Kernel | System | Running] -- E:\Windows\System32\drivers\Uim_Vim.sys -- (Uim_Vim) DRV - [2013/02/18 13:59:44 | 000,081,232 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | System | Running] -- E:\Windows\System32\drivers\UimBus.sys -- (UimBus) DRV - [2013/01/06 13:22:46 | 000,025,944 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\klmouflt.sys -- (klmouflt) DRV - [2013/01/06 13:22:46 | 000,025,944 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\klkbdflt.sys -- (klkbdflt) DRV - [2012/08/04 10:19:29 | 000,163,616 | ---- | M] (Digiarty Software, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\DigiartyVirtualCDBus.sys -- (DigiartyVirtualCDBus) DRV - [2012/08/02 16:09:30 | 000,024,408 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- E:\Windows\System32\drivers\klim6.sys -- (KLIM6) DRV - [2012/07/21 14:11:15 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- E:\Windows\System32\drivers\truecrypt.sys -- (truecrypt) DRV - [2012/06/19 18:28:12 | 000,136,024 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\kl1.sys -- (KL1) DRV - [2012/06/12 11:19:08 | 000,016,064 | ---- | M] (Macrium Software) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\pssnap.sys -- (pssnap) DRV - [2012/03/19 09:18:46 | 000,064,800 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- E:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm) DRV - [2012/02/21 18:46:20 | 000,315,368 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\asmtxhci.sys -- (asmtxhci) DRV - [2012/02/21 18:46:18 | 000,102,888 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\asmthub3.sys -- (asmthub3) DRV - [2012/01/17 13:45:58 | 000,148,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA) DRV - [2012/01/06 11:44:30 | 000,043,104 | ---- | M] (Asmedia Technology) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\asahci32.sys -- (asahci32) DRV - [2012/01/04 20:58:50 | 000,789,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\iusb3xhc.sys -- (iusb3xhc) DRV - [2012/01/04 20:58:50 | 000,347,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\iusb3hub.sys -- (iusb3hub) DRV - [2012/01/04 20:58:50 | 000,013,592 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\iusb3hcs.sys -- (iusb3hcs) DRV - [2011/11/10 00:52:02 | 000,046,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\HECI.sys -- (MEI) DRV - [2011/09/20 05:25:28 | 000,037,448 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\ASUSFILTER.sys -- (ASUSFILTER) DRV - [2011/09/02 07:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt) DRV - [2011/09/02 07:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt) DRV - [2011/08/12 11:13:58 | 000,028,264 | R--- | M] (NT Kernel Resources) [Kernel | System | Running] -- E:\Windows\System32\drivers\ndisrd.sys -- (ndisrd) DRV - [2011/07/20 02:36:42 | 000,268,968 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\e1c6232.sys -- (e1cexpress) DRV - [2011/03/18 14:46:26 | 000,061,704 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS) DRV - [2011/03/18 14:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K) DRV - [2010/11/20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010/11/20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010/11/20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010/11/20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010/11/20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010/10/20 19:12:14 | 000,013,440 | ---- | M] (ASUSTek Computer Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\AiCharger.sys -- (AiCharger) DRV - [2010/08/24 08:31:08 | 000,011,456 | R--- | M] () [Kernel | System | Running] -- E:\Windows\System32\drivers\AsIO.sys -- (AsIO) DRV - [2010/08/17 18:28:34 | 000,022,040 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\ICCWDT.sys -- (ICCWDT) DRV - [2010/08/03 06:20:56 | 000,011,832 | R--- | M] () [Kernel | System | Running] -- E:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO) DRV - [2009/07/14 00:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2002/04/02 17:30:16 | 000,033,024 | ---- | M] (Colorvision Inc) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\cvspydr2.sys -- (cvspydr2) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.uk/ IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 1B C4 92 D0 66 CD 01 [binary data] IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.uk/ IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 20 01 61 78 8B 70 CD 01 [binary data] IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes,DefaultScope = {700F9637-8FFE-4759-ACDA-902AA7E96400} IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=111434&tt=3012_7&babsrc=SP_ss&mntrId=6a229dba00000000000010bf48799c74 IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes\{700F9637-8FFE-4759-ACDA-902AA7E96400}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_UK&apn_ptnrs=U3&apn_dtid=OSJ000YYGB&apn_uid=CC5C6200-CD42-424D-BB72-6AC5CA6A51AF&apn_sauid=F122E31C-AE4A-4E14-86F0-B8C33DBD31BE IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: E:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: E:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: E:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Users\darren\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Users\darren\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/21 20:44:00 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\url_advisor@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtual_keyboard@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\content_blocker@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\anti_banner@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\online_banking@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2013/08/21 12:56:42 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2013/08/21 12:56:45 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/21 20:44:00 | 000,000,000 | ---D | M] [2012/08/23 21:13:10 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Extensions [2013/09/14 10:40:18 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions [2013/05/16 20:49:58 | 000,000,000 | ---D | M] (WOT) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013/08/28 10:58:10 | 000,000,000 | ---D | M] (DownloadHelper) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013/09/14 10:40:18 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\staged [2013/09/05 21:59:57 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions [2013/08/21 12:56:42 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\browser\extensions [2013/08/21 12:56:51 | 000,000,000 | ---D | M] (Default) -- E:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2012/03/28 02:04:52 | 000,124,864 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\CCMSDK.dll [2012/03/28 02:06:54 | 000,071,104 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\CgpCore.dll [2012/03/28 02:05:52 | 000,092,096 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\confmgr.dll [2012/03/28 02:05:28 | 000,022,976 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\ctxlogging.dll [2008/06/19 10:16:24 | 000,118,784 | ---- | M] (CANON INC.) -- E:\Program Files\mozilla firefox\plugins\MyCamera.dll [2008/06/19 10:16:24 | 000,053,248 | ---- | M] (CANON INC.) -- E:\Program Files\mozilla firefox\plugins\NPCIG.dll [2012/03/28 02:48:16 | 000,489,384 | ---- | M] () -- E:\Program Files\mozilla firefox\plugins\npicaN.dll [2012/03/28 02:06:48 | 000,024,512 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\TcpPServ.dll O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O3 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [APSDaemon] E:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [AVP] E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [ConnectionCenter] E:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.) O4 - HKLM..\Run: [RTHDVCPL] E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe (Realtek Semiconductor) O4 - HKLM..\Run: [uSB3MON] E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [GarminExpressTrayApp] E:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries) O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [GoogleDriveSync] E:\Program Files\Google\Drive\googledrivesync.exe (Google) O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [MusicManager] E:\Users\darren\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.) O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [Plex Media Server] E:\Program Files\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.) O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004..\Run: [Digiarty_Software_AirPlayit] E:\Program Files\Digiarty\Air_Playit\airplayit.exe () O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004..\Run: [spotify] E:\Users\Henry\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd) O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004..\Run: [spotify Web Helper] E:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) O4 - Startup: E:\Users\darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = E:\Users\darren\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O4 - Startup: E:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = E:\Users\darren\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Add to Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm () O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E61F5A10-0F68-4278-A870-B674D08ED3BF}: DhcpNameServer = 194.168.4.100 194.168.8.100 O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (E:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - Winlogon\Notify\LBTWlgn: DllName - (e:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - e:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/09/15 19:21:30 | 000,602,112 | ---- | C] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL - Copy.exe [2013/09/15 19:20:45 | 000,602,112 | ---- | C] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL.exe [2013/09/12 03:02:12 | 002,876,928 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll [2013/09/12 03:02:12 | 002,706,432 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb [2013/09/12 03:02:12 | 000,391,168 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll [2013/09/12 03:02:12 | 000,061,440 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iesetup.dll [2013/09/12 03:02:12 | 000,039,424 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll [2013/09/12 03:02:11 | 000,493,056 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeeds.dll [2013/09/12 03:02:11 | 000,109,056 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iesysprep.dll [2013/09/12 03:02:11 | 000,071,680 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\RegisterIEPKEYs.exe [2013/09/12 03:02:11 | 000,042,496 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ie4uinit.exe [2013/09/12 03:02:11 | 000,033,280 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iernonce.dll [2013/09/11 23:27:05 | 000,133,056 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\ataport.sys [2013/09/11 23:27:04 | 002,348,544 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys [2013/09/11 23:27:03 | 000,271,360 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\conhost.exe [2013/09/11 23:27:03 | 000,169,984 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\winsrv.dll [2013/09/11 23:27:03 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-security-base-l1-1-0.dll [2013/09/11 23:27:03 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-file-l1-1-0.dll [2013/09/11 23:27:03 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll [2013/09/11 23:27:03 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-util-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-string-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-io-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-console-l1-1-0.dll [2013/09/11 20:25:42 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- E:\Windows\System32\drivers\mbamswissarmy.sys [2013/09/09 21:08:42 | 000,000,000 | ---D | C] -- E:\ProgramData\boost_interprocess [2013/09/09 21:02:53 | 000,000,000 | ---D | C] -- E:\AdwCleaner [2013/09/05 22:23:40 | 000,000,000 | ---D | C] -- E:\Users\darren\Documents\Garmin [2013/09/05 22:22:59 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin [2013/09/05 22:22:56 | 000,000,000 | ---D | C] -- E:\Program Files\Garmin [2013/09/05 22:22:53 | 000,000,000 | ---D | C] -- E:\ProgramData\Package Cache [2013/09/05 22:04:14 | 000,000,000 | ---D | C] -- E:\Windows\ERUNT [2013/09/05 15:56:09 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013/09/05 15:56:08 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- E:\Windows\System32\drivers\mbam.sys [2013/09/05 15:56:08 | 000,000,000 | ---D | C] -- E:\Program Files\Malwarebytes' Anti-Malware [2013/08/25 12:23:07 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013/08/22 03:02:26 | 000,000,000 | ---D | C] -- E:\Windows\System32\MRT [2013/08/21 13:56:02 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2013/08/21 13:55:53 | 000,000,000 | ---D | C] -- E:\Program Files\iTunes [2013/08/21 13:55:53 | 000,000,000 | ---D | C] -- E:\Program Files\iPod [2013/08/21 13:55:53 | 000,000,000 | ---D | C] -- E:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 [2013/08/21 12:56:41 | 000,000,000 | ---D | C] -- E:\Program Files\Mozilla Firefox [2013/08/21 12:15:08 | 003,968,960 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ntkrnlpa.exe [2013/08/21 12:15:08 | 003,913,664 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ntoskrnl.exe [2013/08/21 12:15:03 | 001,620,992 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\WMVDECOD.DLL [2013/08/21 12:14:53 | 000,002,048 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\tzres.dll [1 E:\Users\darren\Documents\*.tmp files -> E:\Users\darren\Documents\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/09/15 19:25:27 | 000,000,882 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013/09/15 19:24:56 | 000,000,860 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000Core.job [2013/09/15 19:20:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL.exe [2013/09/15 19:20:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL - Copy.exe [2013/09/15 19:19:45 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat [2013/09/15 19:18:30 | 000,000,912 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000UA.job [2013/09/15 19:18:30 | 000,000,886 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013/09/15 19:18:05 | 000,000,830 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job [2013/09/14 12:23:42 | 003,750,790 | ---- | M] () -- E:\Windows\System32\perfh009.dat [2013/09/14 12:23:42 | 001,739,608 | ---- | M] () -- E:\Windows\System32\perfc009.dat [2013/09/14 10:38:19 | 000,013,456 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/09/14 10:38:19 | 000,013,456 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/09/14 10:31:09 | 2795,933,696 | -HS- | M] () -- E:\hiberfil.sys [2013/09/12 03:20:36 | 002,693,232 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT [2013/09/11 20:25:57 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- E:\Windows\System32\drivers\mbamswissarmy.sys [2013/09/10 18:13:13 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerApp.exe [2013/09/10 18:13:13 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerCPLApp.cpl [2013/09/09 21:02:49 | 001,037,278 | ---- | M] () -- E:\Users\darren\Desktop\AdwCleaner(1).exe [2013/09/05 22:22:59 | 000,001,895 | ---- | M] () -- E:\Users\Public\Desktop\Garmin Express.lnk [2013/09/05 15:56:09 | 000,001,104 | ---- | M] () -- E:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/08/25 12:23:07 | 000,001,061 | ---- | M] () -- E:\Users\Public\Desktop\VLC media player.lnk [2013/08/22 20:05:53 | 000,002,042 | ---- | M] () -- E:\Users\darren\Desktop\Kies Air Discovery Service.lnk [2013/08/21 13:56:02 | 000,001,790 | ---- | M] () -- E:\Users\Public\Desktop\iTunes.lnk [1 E:\Users\darren\Documents\*.tmp files -> E:\Users\darren\Documents\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/09/09 21:02:42 | 001,037,278 | ---- | C] () -- E:\Users\darren\Desktop\AdwCleaner(1).exe [2013/09/05 22:22:59 | 000,001,895 | ---- | C] () -- E:\Users\Public\Desktop\Garmin Express.lnk [2013/09/05 15:56:09 | 000,001,104 | ---- | C] () -- E:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/08/22 20:05:53 | 000,002,042 | ---- | C] () -- E:\Users\darren\Desktop\Kies Air Discovery Service.lnk [2012/09/12 22:58:37 | 005,221,448 | ---- | C] () -- E:\Windows\System32\SpoonUninstall.exe [2012/08/21 20:41:25 | 000,164,567 | ---- | C] () -- E:\Windows\hpoins27.dat [2012/08/21 20:41:25 | 000,000,442 | ---- | C] () -- E:\Windows\hpomdl27.dat [2012/08/19 14:49:03 | 002,953,448 | ---- | C] () -- E:\Windows\System32\nvcoproc.bin [2012/08/02 23:47:39 | 001,048,576 | ---- | C] () -- E:\Windows\PE_Rom.dll [2012/08/02 22:22:00 | 000,056,140 | ---- | C] () -- E:\Windows\Ascd_log.ini [2012/08/02 22:21:27 | 000,011,456 | R--- | C] () -- E:\Windows\System32\drivers\AsIO.sys [2012/08/02 22:21:25 | 000,011,832 | ---- | C] () -- E:\Windows\System32\drivers\AsInsHelp64.sys [2012/07/21 22:32:35 | 000,066,048 | ---- | C] () -- E:\Windows\System32\PrintBrmUi.exe [2012/07/21 13:48:54 | 000,017,408 | ---- | C] () -- E:\Users\darren\AppData\Local\WebpageIcons.db [2012/07/21 00:29:42 | 000,001,332 | R--- | C] () -- E:\Windows\System32\drivers\DTSU2P.DAT [2012/07/21 00:29:33 | 000,238,448 | ---- | C] () -- E:\Windows\System32\drivers\RTAIODAT.DAT [2012/07/21 00:27:24 | 000,001,769 | ---- | C] () -- E:\Windows\Language_trs.ini [2012/07/21 00:27:12 | 000,041,993 | ---- | C] () -- E:\Windows\Ascd_tmp.ini [2012/03/20 00:37:12 | 000,755,188 | ---- | C] () -- E:\Windows\System32\igkrng700.bin [2012/03/20 00:37:12 | 000,561,508 | ---- | C] () -- E:\Windows\System32\igfcg700m.bin [2012/03/20 00:25:58 | 000,058,880 | ---- | C] () -- E:\Windows\System32\igdde32.dll [2012/03/19 23:23:38 | 013,024,256 | ---- | C] () -- E:\Windows\System32\ig7icd32.dll [2012/03/19 23:11:22 | 000,009,216 | ---- | C] ( ) -- E:\Windows\System32\IGFXDEVLib.dll [2012/03/19 23:09:28 | 000,000,264 | ---- | C] () -- E:\Windows\System32\GfxUI.exe.config [2012/03/19 23:09:08 | 000,094,208 | ---- | C] () -- E:\Windows\System32\IccLibDll.dll ========== ZeroAccess Check ========== [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- E:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both < End of report >
  13. I still get diverted to the delta search page when I open a new tab in Firefox, it used to open on google. I suppose the virus may be gone, and its just a residual setting I need to update somehow in firefox, but I;m not sure how?
  14. Ah, sorry step 3 log attached.. Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.09.11.07 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16660 darren :: DARREN-PC [administrator] 11/09/2013 20:26:20 mbam-log-2013-09-11 (20-26-20).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 320364 Time elapsed: 4 minute(s), 6 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.