Jump to content

rigsby1208

Honorary Members
  • Posts

    57
  • Joined

  • Last visited

Posts posted by rigsby1208

  1. Hi

    I keep seeing a process appearing called Sp.exe in Windows task manager.  It seems to be taking a lot of CPU .

    Is it normal or is it something I should be worried about? I normally notice it when my machines seems to be running a little slow, but no other noticeable symptoms.

    I have downloaded and run the latest malwarebytes software and database, which just identified several PUPs which I have now quarrantined

  2. ok, results below

     

     Results of screen317's Security Check version 0.99.79  
     Windows 7 Service Pack 1 x86 (UAC is enabled)  
     Internet Explorer 11  
    ``````````````Antivirus/Firewall Check:``````````````
     Windows Firewall Disabled!  
    Kaspersky Internet Security   
     Antivirus out of date!  
    `````````Anti-malware/Other Utilities Check:`````````
     Norton Ghost    
     Malwarebytes Anti-Malware version 1.75.0.1300  
     CCleaner     
     Java 6 Update 30  
     Java version out of Date!
     Adobe Flash Player     12.0.0.44  
     Adobe Reader 10.1.3 Adobe Reader out of Date!  
     Mozilla Firefox (27.0.1)
    ````````Process Check: objlist.exe by Laurent````````  
     Malwarebytes Anti-Malware mbamservice.exe  
     Malwarebytes Anti-Malware mbamgui.exe  
     Malwarebytes' Anti-Malware mbamscheduler.exe   
     Kaspersky Lab Kaspersky Internet Security 2013 avp.exe  
    `````````````````System Health check`````````````````
     Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````
     

  3. Hi thanks

     

    adwcleaner and malware logs below..

     

    # AdwCleaner v3.018 - Report created 16/02/2014 at 18:29:46
    # Updated 28/01/2014 by Xplode
    # Operating System : Windows 7 Professional Service Pack 1 (32 bits)
    # Username : Darren - DARREN-PC-SHED
    # Running from : C:\Users\Darren\Downloads\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : C:\ProgramData\boost_interprocess
    Folder Deleted : C:\ProgramData\GameTap Web Player
    Folder Deleted : C:\ProgramData\Tarma Installer
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it!
    Folder Deleted : C:\Program Files\Conduit
    Folder Deleted : C:\Program Files\GameTap Web Player
    Folder Deleted : C:\Program Files\myfree codec
    Folder Deleted : C:\Program Files\openit
    Folder Deleted : C:\Program Files\Retrogamer_4w
    Folder Deleted : C:\Program Files\Yontoo Layers Runtime
    Folder Deleted : C:\Users\Darren\AppData\Local\Conduit
    Folder Deleted : C:\Users\Darren\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\Darren\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
    Folder Deleted : C:\Users\lukas\AppData\LocalLow\AskToolbar
    Folder Deleted : C:\Users\Henry\AppData\LocalLow\AskToolbar
    Folder Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\Extensions\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8}
    Folder Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\Extensions\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8}
    Folder Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\Extensions\ffxtlbr@mysearchdial.com
    Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\GameTapPlayer@gametap.com
    File Deleted : C:\Users\Public\Desktop\Open It!.lnk
    File Deleted : C:\Users\Darren\AppData\Local\Temp\Uninstall.exe
    File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\searchplugins\Askcom.xml
    File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\searchplugins\Conduit.xml
    File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\searchplugins\Mysearchdial.xml
    File Deleted : C:\Users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\n54r5ozr.default\searchplugins\Mysearchdial.xml
    File Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\searchplugins\Mysearchdial.xml
    File Deleted : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\user.js
    File Deleted : C:\Users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\n54r5ozr.default\user.js
    File Deleted : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\user.js

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
    Key Deleted : HKLM\SOFTWARE\Classes\RewardsArcade.BHO
    Key Deleted : HKLM\SOFTWARE\Classes\RewardsArcade.Sandbox
    Key Deleted : HKLM\SOFTWARE\Classes\RewardsArcade.Sandbox.1
    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api
    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
    Value Deleted : HKLM\SOFTWARE\mozilla\Firefox\Extensions [crossriderapp498@crossrider.com]
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03123BB6-A811-407E-B323-66CF0BE510B1}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D757DBFC-1494-4647-A8B3-ABD654988DD8}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3392CFEC-56F8-41EE-BDB4-4E301EFD2C93}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
    Key Deleted : HKCU\Software\Conduit
    Key Deleted : HKCU\Software\Cr_Installer
    Key Deleted : HKCU\Software\dsiteproducts
    Key Deleted : HKCU\Software\IGearSettings
    Key Deleted : HKCU\Software\Myfree Codec
    Key Deleted : HKCU\Software\YahooPartnerToolbar
    Key Deleted : HKCU\Software\AppDataLow\Software\RewardsArcade
    Key Deleted : HKCU\Software\AppDataLow\Software\Toolbar
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\Myfree Codec
    Key Deleted : HKLM\Software\Tarma Installer
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86C0E2A3-1EDA-4F01-A43D-80DA8642813C}_is1
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenIt Open It!

    ***** [ Browsers ] *****

    -\\ Internet Explorer v0.0.0.0

    Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

    -\\ Mozilla Firefox v27.0.1 (en-GB)

    [ File : C:\Users\Darren\AppData\Roaming\Mozilla\Firefox\Profiles\7tyee22d.default\prefs.js ]

    Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
    Line Deleted : user_pref("browser.search.defaultenginename", "Mysearchdial");
    Line Deleted : user_pref("browser.search.defaultthis.engineName", "Web Search");

    Line Deleted : user_pref("browser.search.order.1", "Mysearchdial");
    Line Deleted : user_pref("browser.search.selectedEngine", "Mysearchdial");

    Line Deleted : user_pref("extensions.enabledItems", "{66E978CD-981F-47DF-AC42-E3CF417C1467}:0.4.3,{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6,{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6,{a0d7ccb3-214d-498b-b4aa-0e[...]
    Line Deleted : user_pref("extensions.mysearchdial.AL", 2);
    Line Deleted : user_pref("extensions.mysearchdial.aflt", "dsites0103");
    Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
    Line Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
    Line Deleted : user_pref("extensions.mysearchdial.cntry", "GB");
    Line Deleted : user_pref("extensions.mysearchdial.cr", "698970755");
    Line Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
    Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
    Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
    Line Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
    Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
    Line Deleted : user_pref("extensions.mysearchdial.hdrMd5", "CF6E2C83B64F9DF7DB7D88ECDA4EC98C");
    Line Deleted : user_pref("extensions.mysearchdial.hmpg", true);

    Line Deleted : user_pref("extensions.mysearchdial.id", "00235439D208F5EC");
    Line Deleted : user_pref("extensions.mysearchdial.instlDay", "16095");
    Line Deleted : user_pref("extensions.mysearchdial.instlRef", "");

    Line Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.21.022:46:1");

    Line Deleted : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
    Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.sg", "none");
    Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");

    Line Deleted : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
    Line Deleted : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
    Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
    Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
    Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
    Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.022:46:1");
    Line Deleted : user_pref("extentions.y2layers.defaultEnableAppsList", "Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,BestVideoDownloader,");
    Line Deleted : user_pref("extentions.y2layers.installId", "8383dfc0-275d-42b5-afb8-50d347326a82");
    Line Deleted : user_pref("extentions.y2layers.lastDnsTest", 371588);

    [ File : C:\Users\lukas\AppData\Roaming\Mozilla\Firefox\Profiles\n54r5ozr.default\prefs.js ]

    Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
    Line Deleted : user_pref("browser.search.defaultenginename", "Mysearchdial");
    Line Deleted : user_pref("browser.search.order.1", "Ask.com");
    Line Deleted : user_pref("browser.search.selectedEngine", "Mysearchdial");
    Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");


    [ File : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\mw409dkx.default\prefs.js ]

    Line Deleted : user_pref("browser.search.defaultengine", "Ask.com");
    Line Deleted : user_pref("browser.search.defaultenginename", "Mysearchdial");
    Line Deleted : user_pref("browser.search.order.1", "Mysearchdial");
    Line Deleted : user_pref("browser.search.selectedEngine", "Mysearchdial");
    Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
    Line Deleted : user_pref("extensions.enabledAddons", "%7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%7D:9.5.3,ffxtlbr%40mysearchdial.com:1.6.0,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0");
    Line Deleted : user_pref("extensions.mysearchdial.AL", 2);
    Line Deleted : user_pref("extensions.mysearchdial.aflt", "dsites0103");
    Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
    Line Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
    Line Deleted : user_pref("extensions.mysearchdial.cntry", "GB");
    Line Deleted : user_pref("extensions.mysearchdial.cr", "698970755");
    Line Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
    Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
    Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
    Line Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
    Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
    Line Deleted : user_pref("extensions.mysearchdial.hdrMd5", "491E27C441D89F0363B0DF7E42700AFD");
    Line Deleted : user_pref("extensions.mysearchdial.hmpg", true);

    Line Deleted : user_pref("extensions.mysearchdial.id", "00235439D208F5EC");
    Line Deleted : user_pref("extensions.mysearchdial.instlDay", "16095");
    Line Deleted : user_pref("extensions.mysearchdial.instlRef", "");

    Line Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", "");

    Line Deleted : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
    Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.sg", "{smplGrp}");
    Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
    Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");

    Line Deleted : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
    Line Deleted : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
    Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
    Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
    Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
    Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.022:46:1");

    *************************

    AdwCleaner[R0].txt - [19137 octets] - [16/02/2014 18:24:51]
    AdwCleaner[s0].txt - [19151 octets] - [16/02/2014 18:29:46]

    ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [19212 octets] ##########
     

     

     

     

    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Database version: v2014.02.16.04

    Windows 7 Service Pack 1 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Darren :: DARREN-PC-SHED [administrator]

    16/02/2014 18:46:02
    mbam-log-2014-02-16 (18-46-02).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 293169
    Time elapsed: 10 minute(s), 58 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     

     

  4. Thanks for helping . Rogue killer results..

     

     

    RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
    Started in : Normal mode
    User : Darren [Admin rights]
    Mode : Scan -- Date : 02/16/2014 00:17:21
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 1 ¤¤¤
    [HJNAME] dllhost.exe -- C:\Windows\winsxs\x86_microsoft-windows-com-surrogate_31bf3856ad364e35_6.1.7600.16385_none_43fa44d954d596e7\dllhost.exe [7] -> KILLED [TermThr]

    ¤¤¤ Registry Entries : 4 ¤¤¤
    [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
    [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_TrackProgs (0) -> FOUND
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Scheduled tasks : 2 ¤¤¤
    [V1][sUSP PATH] Digital Sites.job : C:\Users\Darren\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND
    [V2][sUSP PATH] Digital Sites : C:\Users\Darren\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ Browser Addons : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ External Hives: ¤¤¤

    ¤¤¤ Infection :  ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts




    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HD103UJ ATA Device +++++
    --- User ---
    [MBR] dee76aaee0c09ff438ff5519019e02a9
    [bSP] 9377b04036c050cc028155580dd4c63e : Windows 7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 199900 Mo
    2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409602048 | Size: 753867 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) SAMSUNG HD103SI ATA Device +++++
    --- User ---
    [MBR] 8278f456f89c1bd77d7e76f1e9e3662f
    [bSP] 2bdee771291ce8990d07229f3a71f8c6 : Empty MBR Code
    Partition table:
    0 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 16065 | Size: 953859 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ IDE) SAMSUNG HD154UI ATA Device +++++
    --- User ---
    [MBR] cfa9ce03f2c65df473d39a62df60d82e
    [bSP] 6b643498de7e5c62b12120b7db36c3f2 : Windows XP MBR Code
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 1430796 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[0]_S_02162014_001721.txt >>



     

  5. hi

    everytime I start firefox I'm redirected to a suspicious search page looking a bit like google but its not, its url is mysearchdial.com.  I have run malware bytes and removed a few issus but my problem remains.  Even if I set my homepage back to googe, next time I restart firefox i get taken to the mysearchdial page.

    DDS logs below

     

    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer:   BrowserJavaVersion: 1.6.0_30
    Run by Darren at 20:10:52 on 2014-02-15
    Microsoft Windows 7 Professional   6.1.7601.1.1252.44.1033.18.3327.1266 [GMT 0:00]
    .
    AV: Kaspersky Internet Security *Enabled/Outdated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
    SP: Kaspersky Internet Security *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Kaspersky Internet Security *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
    .
    ============== Running Processes ================
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\ASUS\Disk Unlocker\ASPFSVS.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe
    C:\Program Files\Intel\iCLS Client\HeciServer.exe
    C:\Windows\system32\IProsetMonitor.exe
    C:\Program Files\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Norton Ghost\Agent\VProSvc.exe
    C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Program Files\Ask.com\Updater\Updater.exe
    C:\Program Files\Logitech\SetPointP\SetPoint.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
    C:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
    C:\Program Files\Norton Ghost\Agent\VProTray.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
    C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
    C:\Users\Darren\AppData\Roaming\Spotify\spotify.exe
    C:\Program Files\Plex\Plex Media Server\Plex Media Server.exe
    C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
    C:\Users\Darren\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe
    C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
    C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
    C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
    C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
    C:\Program Files\Plex\Plex Media Server\PlexDlnaServer.exe
    C:\Users\Darren\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
    C:\Windows\system32\sppsvc.exe
    C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
    \\?\C:\Windows\system32\wbem\WMIADAP.EXE
    C:\Program Files\TrueCrypt\TrueCrypt.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
    C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\System32\svchost.exe -k secsvcs
    .
    ============== Pseudo HJT Report ===============
    .


    uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-502F5495E5FC} - c:\program files\ask.com\GenericAskToolbar.dll
    uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll
    uURLSearchHooks: <No Name>: {4cff1016-c2e2-4fdd-9c67-e32200c25ff9} - c:\program files\retrogamer_4w\bar\1.bin\4wSrcAs.dll
    mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll
    BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\contentblocker\ie_content_blocker_plugin.dll
    BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
    BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
    BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\onlinebanking\online_banking_bho.dll
    BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
    BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll
    BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
    TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: Vuze Remote Toolbar: {BA14329E-9550-4989-B3F2-9732E92D17CC} - c:\program files\vuze_remote\prxtbVuze.dll
    TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll
    TB: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - c:\program files\conduitengine\prxConduitEngine.dll
    TB: Retrogamer: {3392cfec-56f8-41ee-bdb4-4e301efd2c93} - c:\program files\retrogamer_4w\bar\1.bin\4wbar.dll
    TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
    uRun: [spotify Web Helper] "c:\users\darren\appdata\roaming\spotify\data\SpotifyWebHelper.exe"
    uRun: [spotify] "c:\users\darren\appdata\roaming\spotify\Spotify.exe" /uri spotify:autostart
    uRun: [Plex Media Server] "c:\program files\plex\plex media server\Plex Media Server.exe"
    mRun: [NUSB3MON] "c:\program files\nec electronics\usb 3.0 host controller driver\application\nusb3mon.exe"
    mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
    mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
    mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
    mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
    mRun: [RtHDVBg_DTS] c:\program files\realtek\audio\hda\RtHDVBg.exe /DTSU2P
    mRun: [uSB3MON] "c:\program files\intel\intel® usb 3.0 extensible host controller driver\application\iusb3mon.exe"
    mRun: [igfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [Norton Ghost 15.0] "c:\program files\norton ghost\agent\VProTray.exe"
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe"
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    dRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    StartupFolder: c:\users\darren\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\darren\appdata\roaming\dropbox\bin\Dropbox.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.8.130\SSScheduler.exe
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2013\ie_banner_deny.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~1\micros~1\office14\ONBttnIE.dll/105
    IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
    IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll




    TCP: NameServer = 194.168.4.100 194.168.8.100
    TCP: Interfaces\{BEDBC439-ECEF-4314-8AEF-93F6223AD375} : DHCPNameServer = 194.168.4.100 194.168.8.100
    TCP: Interfaces\{EBB0FEDC-C9FD-4EEA-8A12-25AAFD1AE6EB} : DHCPNameServer = 194.168.4.100 194.168.8.100
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
    Notify: igfxcui - igfxdev.dll
    Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    SSODL: WebCheck - <orphaned>
    SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
    mASetup: {61E3FE32-07B9-4563-A3E0-2DE2D620FE10} - c:\program files\pixiepack codec pack\InstallerHelper.exe
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\darren\appdata\roaming\mozilla\firefox\profiles\7tyee22d.default\

    FF - prefs.js: browser.search.selectedEngine - Mysearchdial

    FF - prefs.js: keyword.URL -
    FF - component: c:\program files\mozilla firefox\extensions\kavantibanner@kaspersky.ru\components\abhelperxpcom.dll
    FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
    FF - plugin: c:\progra~1\micros~1\office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\micros~1\office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\canon\mycamera download plugin\NPCIG.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll
    FF - plugin: c:\program files\intel\intel® management engine components\ipt\npIntelWebAPIIPT.dll
    FF - plugin: c:\program files\intel\intel® management engine components\ipt\npIntelWebAPIUpdater.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\mcafee security scan\3.8.130\npMcAfeeMSS.dll
    FF - plugin: c:\program files\microsoft silverlight\5.1.20913.0\npctrlui.dll
    FF - plugin: c:\program files\retrogamer_4w\bar\1.bin\NP4wStub.dll
    FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_12_0_0_44.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: extentions.y2layers.installId - 8383dfc0-275d-42b5-afb8-50d347326a82
    FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,BestVideoDownloader,
    FF - user.js: extensions.mysearchdial.hmpg - true

    FF - user.js: extensions.mysearchdial.dfltSrch - true
    FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial
    FF - user.js: extensions.mysearchdial.dnsErr - true
    FF - user.js: extensions.mysearchdial_i.newTab - false


    FF - user.js: extensions.mysearchdial.id - 00235439D208F5EC
    FF - user.js: extensions.mysearchdial.instlDay - 16095
    FF - user.js: extensions.mysearchdial.vrsn - 1.8.21.0
    FF - user.js: extensions.mysearchdial.vrsni - 1.8.21.0
    FF - user.js: extensions.mysearchdial_i.vrsnTs - 1.8.21.022:46:1
    FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial
    FF - user.js: extensions.mysearchdial.prdct - mysearchdial
    FF - user.js: extensions.mysearchdial.aflt - dsites0103
    FF - user.js: extensions.mysearchdial_i.smplGrp - none
    FF - user.js: extensions.mysearchdial.tlbrId - base
    FF - user.js: extensions.mysearchdial.instlRef -
    FF - user.js: extensions.mysearchdial.dfltLng -
    FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
    FF - user.js: extensions.mysearchdial.excTlbr - false
    FF - user.js: extensions.mysearchdial_i.hmpg - true
    FF - user.js: extensions.mysearchdial.cr - 698970755
    FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R
    FF - user.js: extensions.mysearchdial.AL - 2
    FF - user.js: extensions.irmysearch.aflt - dsites0103
    FF - user.js: extensions.irmysearch.instlRef -
    FF - user.js: extensions.irmysearch.cr - 698970755
    FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1QzutDtDtBtAyDyEtAzy0DtBtDzz0FyD0E0CtN0D0Tzu0SyByDyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 asahci32;asahci32;c:\windows\system32\drivers\asahci32.sys [2012-1-6 43104]
    R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys [2012-7-16 13592]
    R0 mv91xx;mv91xx;c:\windows\system32\drivers\mv91xx.sys [2010-3-17 261672]
    R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2012-8-2 25696]
    R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2012-6-8 44000]
    R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2012-8-13 145040]
    R1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\drivers\VDiskBus32.sys [2010-9-21 38016]
    R2 ASDiskUnlocker;ASDiskUnlocker;c:\program files\asus\disk unlocker\ASPFSVS.exe [2010-12-2 185984]
    R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe -r --> c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe -r [?]
    R2 DTSAudioSvc;DTSAudioSvc;c:\program files\realtek\audio\hda\DTSU2PAuSrv32.exe [2012-7-16 190832]
    R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\intel\icls client\HeciServer.exe [2012-2-2 458464]
    R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IPROSetMonitor.exe [2012-7-16 117920]
    R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files\intel\intel® management engine components\dal\Jhi_service.exe [2012-7-16 161560]
    R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2014-1-25 418376]
    R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2014-1-25 701512]
    R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2012-7-16 363800]
    R3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files\asus\disk unlocker\ASFLTDrv.sys [2010-9-16 17408]
    R3 GenericMount;Generic Mount Driver;c:\windows\system32\drivers\GenericMount.sys [2010-2-12 57840]
    R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2012-5-25 25696]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2012-7-25 25696]
    R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [2011-9-2 42648]
    R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [2011-9-2 12184]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-1-25 22856]
    R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2010-1-22 59904]
    R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2010-1-22 139648]
    R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2010-2-11 1964528]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files\samsung\allshare\allsharedms\AllShareDMS.exe [2012-1-19 25504]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2011-11-24 80184]
    S3 GenericMount Helper Service;GenericMount Helper Service;c:\program files\norton ghost\shared\drivers\GenericMountHelper.exe [2010-2-12 1574408]
    S3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2012-7-16 280576]
    S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys [2012-7-16 347928]
    S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys [2012-7-16 789272]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.8.130\McCHSvc.exe [2013-9-6 235216]
    S3 MEI;Intel® Management Engine Interface ;c:\windows\system32\drivers\HECI.sys [2012-7-16 46080]
    S3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files\samsung\allshare\AllShareSlideShowService.exe [2012-1-19 27584]
    S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2011-11-24 181432]
    S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
    S3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2009-7-13 7168]
    S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-21 52224]
    S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-12-11 1343400]
    .
    =============== Created Last 30 ================
    .
    2014-02-15 19:45:07    7760024    ----a-w-    c:\programdata\microsoft\windows defender\definition updates\{ffa385db-9e6c-463c-9cb7-917db6229c5a}\mpengine.dll
    2014-01-31 22:30:55    --------    d-----w-    c:\program files\ZipGenius 6
    2014-01-25 23:01:06    --------    d-----w-    c:\users\darren\appdata\roaming\Malwarebytes
    2014-01-25 23:01:00    22856    ----a-w-    c:\windows\system32\drivers\mbam.sys
    2014-01-25 23:01:00    --------    d-----w-    c:\programdata\Malwarebytes
    2014-01-25 23:00:59    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
    2014-01-25 22:46:10    --------    d-----w-    c:\users\darren\appdata\roaming\0D0S1L2Z1P1B0T1P1B2Z
    2014-01-25 22:46:02    --------    d-----w-    c:\users\darren\appdata\roaming\DigitalSites
    2014-01-25 22:46:00    --------    d-----w-    c:\program files\OpenIt
    2014-01-17 22:03:10    2349056    ----a-w-    c:\windows\system32\win32k.sys
    2014-01-17 22:03:08    240576    ----a-w-    c:\windows\system32\drivers\netio.sys
    2014-01-17 22:03:01    76288    ----a-w-    c:\windows\system32\drivers\usbccgp.sys
    2014-01-17 22:03:01    6016    ----a-w-    c:\windows\system32\drivers\usbd.sys
    2014-01-17 22:03:01    43520    ----a-w-    c:\windows\system32\drivers\usbehci.sys
    2014-01-17 22:03:01    284672    ----a-w-    c:\windows\system32\drivers\usbport.sys
    2014-01-17 22:03:01    258560    ----a-w-    c:\windows\system32\drivers\usbhub.sys
    2014-01-17 22:03:01    24064    ----a-w-    c:\windows\system32\drivers\usbuhci.sys
    2014-01-17 22:03:01    20480    ----a-w-    c:\windows\system32\drivers\usbohci.sys
    .
    ==================== Find3M  ====================
    .
    2014-02-09 19:35:06    71048    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
    2014-02-09 19:35:06    692616    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
    2013-12-18 06:13:56    231584    ------w-    c:\windows\system32\MpSigStub.exe
    2013-12-12 21:30:48    25696    ----a-w-    c:\windows\system32\drivers\klim6.sys
    2013-12-12 21:30:48    135776    ----a-w-    c:\windows\system32\drivers\kl1.sys
    2013-11-23 18:26:20    417792    ----a-w-    c:\windows\system32\WMPhoto.dll
    .
    ============= FINISH: 20:12:12.34 ===============
     

     

     

     

     

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows 7 Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 10/12/2010 17:28:24
    System Uptime: 15/02/2014 20:04:54 (0 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. |  | P5Q-PRO
    Processor: Intel® Core2 Quad CPU    Q6600  @ 2.40GHz | LGA 775 | 2403/266mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 736 GiB total, 480.156 GiB free.
    D: is FIXED (NTFS) - 195 GiB total, 42.186 GiB free.
    E: is CDROM ()
    F: is FIXED (NTFS) - 1397 GiB total, 1227.694 GiB free.
    G: is FIXED (NTFS) - 932 GiB total, 138.948 GiB free.
    Z: is FIXED (FAT32) - 325 GiB total, 9.163 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP318: 05/01/2014 20:45:50 - Windows Update
    RP319: 05/01/2014 22:10:33 - Plex Media Server
    RP320: 05/01/2014 22:13:40 - Plex Media Server
    RP321: 11/01/2014 20:05:35 - Windows Update
    RP322: 17/01/2014 22:03:08 - Windows Update
    RP323: 18/01/2014 02:37:36 - Windows Update
    RP324: 21/01/2014 18:34:25 - Windows Update
    RP325: 25/01/2014 18:08:41 - Windows Update
    RP326: 31/01/2014 22:15:54 - Windows Update
    RP327: 09/02/2014 18:36:11 - Windows Update
    RP328: 15/02/2014 19:44:25 - Windows Update
    .
    ==== Installed Programs ======================
    .
    Adobe AIR
    Adobe Flash Player 12 ActiveX
    Adobe Flash Player 12 Plugin
    Adobe Reader X (10.1.3)
    Air Playit 2.0.0
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft ShowBiz
    Ask Toolbar
    Ask Toolbar Updater
    Asmedia ASM106x SATA Host Controller Driver
    Bonjour
    CANON iMAGE GATEWAY MyCamera Download Plugin
    CANON iMAGE GATEWAY Task for ZoomBrowser EX
    Canon Internet Library for ZoomBrowser EX
    Canon MOV Decoder
    Canon MOV Encoder
    Canon MovieEdit Task for ZoomBrowser EX
    Canon My Printer
    Canon RAW Codec
    Canon Utilities CameraWindow
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    Canon Utilities Digital Photo Professional 3.9
    Canon Utilities EOS Utility
    Canon Utilities MyCamera
    Canon Utilities Original Data Security Tools
    Canon Utilities PhotoStitch
    Canon Utilities Picture Style Editor
    Canon Utilities RemoteCapture Task for ZoomBrowser EX
    Canon Utilities WFT-E1/E2/E3/E4 Utility
    Canon Utilities ZoomBrowser EX
    Canon ZoomBrowser EX Memory Card Utility
    CCleaner
    Conduit Engine
    dBpoweramp DSP Effects
    dBpoweramp m4a Codec
    dBpoweramp m4a Nero AAC Encoder
    dBpoweramp Music Converter
    Debut Video Capture Software
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Disk Unlocker
    Dropbox
    DVDFab 8.1.9.8 (27/07/2012) Qt
    eReg
    Express Zip File Compression Software
    GameTap Web Player
    Google Earth
    Google Toolbar for Internet Explorer
    Google Update Helper
    HandBrake 0.9.8
    Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678)
    iCloud
    ImgBurn
    Intel® Management Engine Components
    Intel® Network Connections 16.6.126.0
    Intel® OpenCL CPU Runtime
    Intel® Processor Graphics
    Intel® USB 3.0 eXtensible Host Controller Driver
    Intel® Trusted Connect Service Client
    iTunes
    Java Auto Updater
    Java 6 Update 30
    Kaspersky Internet Security 2013
    LiveUpdate 3.2 (Symantec Corporation)
    Logitech SetPoint 6.32
    Malwarebytes Anti-Malware version 1.75.0.1300
    marvell 91xx driver
    McAfee Security Scan Plus
    Microsoft .NET Framework 4 Client Profile
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Groove MUI (English) 2010
    Microsoft Office InfoPath MUI (English) 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional Plus 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
    MobileMe Control Panel
    Mozilla Firefox 26.0 (x86 en-GB)
    Mozilla Maintenance Service
    MyFreeCodec
    NEC Electronics USB 3.0 Host Controller Driver
    Norton Ghost
    Open It!
    Photomatix Pro version 4.0.2
    PixiePack Codec Pack
    Plex Media Server
    QuickTime
    Realtek HDMI Audio Driver for ATI
    Realtek High Definition Audio Driver
    Retrogamer toolbar
    Samsung AllShare
    Samsung Kies
    SAMSUNG USB Driver for Mobile Phones
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
    Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
    Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition
    Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
    Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
    Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition
    Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
    Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
    Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
    Spotify
    TrueCrypt
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
    Update for Microsoft Office 2010 (KB2494150)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553092)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
    Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
    USB Video/Audio Device Driver
    VideoPad Video Editor
    VLC media player 2.1.3
    Vuze
    Vuze Remote Toolbar
    WinX DVD Ripper Platinum 6.9.0
    WinZip 17.0
    Wisdom-soft Set up ScreenHunter 5.1 Free
    WonderGate Server
    Yontoo Layers Runtime 1.10.01
    Zip Opener Packages
    ZipGenius 6.3
    .
    ==== Event Viewer Messages From Past Week ========
    .
    09/02/2014 18:24:30, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
    .
    ==== End Of File ===========================

     

     

    thanks for looking

     

  6. Its difficult to know if the underlying issue has been resolved.  The symptoms I saw were the home page being reset to Delta search, and new tabs opening to Delta search.  I have reset these back to Google now and have stayed set correctly.  I also noticed the other day that some of my firefox add-ons were also disabled such as Kaspersky URL adviser, WOT, safe money, content blocker, etc. which I presumed was the viruses work.  I dont seem to have an option to renable them.  I have subsequently renabled WOT, as that was at least throwing up a warning about the Delta search site when opening a new tab etc.

  7. All processes killed
    ========== OTL ==========
    Registry value HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
    HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
    Registry key HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
    Registry key HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Internet Explorer\SearchScopes\{700F9637-8FFE-4759-ACDA-902AA7E96400}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{700F9637-8FFE-4759-ACDA-902AA7E96400}\ not found.
    ========== FILES ==========
    < ipconfig /flushdns /c >
    Windows IP Configuration
    Successfully flushed the DNS Resolver Cache.
    E:\Users\darren\Desktop\cmd.bat deleted successfully.
    E:\Users\darren\Desktop\cmd.txt deleted successfully.
    ========== COMMANDS ==========
     
    [EMPTYTEMP]
     
    User: All Users
     
    User: darren
    ->Temp folder emptied: 2606049743 bytes
    ->Temporary Internet Files folder emptied: 242011278 bytes
    ->Java cache emptied: 986898 bytes
    ->Flash cache emptied: 1374 bytes
     
    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes
     
    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes
     
    User: Henry
    ->Temp folder emptied: 163330992 bytes
    ->Temporary Internet Files folder emptied: 671994315 bytes
    ->Java cache emptied: 193017 bytes
    ->FireFox cache emptied: 444042703 bytes
    ->Flash cache emptied: 39765 bytes
     
    User: Jo
    ->Temp folder emptied: 37658963 bytes
    ->Temporary Internet Files folder emptied: 598901786 bytes
    ->Java cache emptied: 2633961 bytes
    ->FireFox cache emptied: 80336096 bytes
    ->Flash cache emptied: 17529 bytes
     
    User: Public
    ->Temp folder emptied: 0 bytes
     
    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
     
    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 679120692 bytes
    RecycleBin emptied: 11844866632 bytes
     
    Total Files Cleaned = 16,567.00 mb
     
     
    OTL by OldTimer - Version 3.2.69.0 log created on 09172013_221920

    Files\Folders moved on Reboot...
    E:\Users\darren\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{25B86FBD-77FB-4340-A2DA-B27E09F9DF70}.tmp not found!
    File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{54288C23-B5AB-4E86-99AC-00D6B45BDE8F}.tmp not found!
    File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6D1683C6-CD7D-4D8E-8D6D-C3F94100A5E3}.tmp not found!
    File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6E3F9CF1-1405-4FC3-8FF1-016DE70FDDF5}.tmp not found!
    File\Folder E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{DE3F9145-3A1C-47D0-BB62-C312CA42E0D9}.tmp not found!
    E:\Users\darren\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
    File\Folder E:\Users\Henry\AppData\Local\Temp\~DFF786BE6FD9DBB338.TMP not found!
    File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{0F4A7821-C5FE-4975-88CD-0909A99EA4C5}.tmp not found!
    File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3F39B27B-DC47-4A8C-B437-2B9E4673C550}.tmp not found!
    File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C420126A-4312-4EFF-8898-3AEA5BFD9E25}.tmp not found!
    File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{ECC8E422-5370-4947-8CED-E8FCE97023C1}.tmp not found!
    File\Folder E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{EE2248A9-E50B-45E6-905E-B5FA43CAFE52}.tmp not found!
    E:\Users\Henry\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     

  8. Hi

    Apologies for the dely.  OTL reports below...

     

    OTL logfile created on: 9/15/2013 7:23:13 PM - Run 1
    OTL by OldTimer - Version 3.2.69.0     Folder = E:\Users\darren\Desktop
     Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.10.9200.16686)
    Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
     
    3.47 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 68.68% Memory free
    6.94 Gb Paging File | 4.63 Gb Available in Paging File | 66.75% Paging File free
    Paging file location(s): d:\pagefile.sys 0 0 [binary data]
     
    %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files
    Drive C: | 1863.01 Gb Total Space | 91.47 Gb Free Space | 4.91% Space Free | Partition Type: NTFS
    Drive D: | 1863.01 Gb Total Space | 241.21 Gb Free Space | 12.95% Space Free | Partition Type: NTFS
    Drive E: | 119.23 Gb Total Space | 42.68 Gb Free Space | 35.80% Space Free | Partition Type: NTFS
    Drive F: | 1397.26 Gb Total Space | 547.87 Gb Free Space | 39.21% Space Free | Partition Type: NTFS
    Drive H: | 1397.26 Gb Total Space | 304.60 Gb Free Space | 21.80% Space Free | Partition Type: NTFS
    Drive I: | 1863.01 Gb Total Space | 789.75 Gb Free Space | 42.39% Space Free | Partition Type: NTFS
    Drive J: | 1863.01 Gb Total Space | 48.70 Gb Free Space | 2.61% Space Free | Partition Type: NTFS
     
    Computer Name: DARREN-PC | User Name: darren | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
     
    ========== Processes (All) ==========
     
    PRC - [2013/09/15 19:20:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL - Copy.exe
    PRC - [2013/08/22 14:00:26 | 001,093,464 | ---- | M] (Garmin Ltd or its subsidiaries) -- E:\Program Files\Garmin\Express Tray\ExpressTray.exe
    PRC - [2013/08/22 14:00:04 | 000,220,504 | ---- | M] (Garmin Ltd or its subsidiaries) -- E:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
    PRC - [2013/08/16 09:07:58 | 000,152,392 | ---- | M] (Apple Inc.) -- E:\Program Files\iTunes\iTunesHelper.exe
    PRC - [2013/08/16 09:07:50 | 000,553,288 | ---- | M] (Apple Inc.) -- E:\Program Files\iPod\bin\iPodService.exe
    PRC - [2013/08/03 18:09:18 | 000,409,776 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Microsoft Office\Office12\WINWORD.EXE
    PRC - [2013/08/02 01:52:57 | 000,271,360 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\conhost.exe
    PRC - [2013/07/06 11:20:13 | 004,640,768 | ---- | M] (Spotify Ltd) -- E:\Users\Henry\AppData\Roaming\Spotify\spotify.exe
    PRC - [2013/07/06 11:20:13 | 001,104,384 | ---- | M] (Spotify Ltd) -- E:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
    PRC - [2013/06/27 16:11:08 | 020,097,696 | ---- | M] (Google) -- E:\Program Files\Google\Drive\googledrivesync.exe
    PRC - [2013/06/21 00:52:00 | 007,345,664 | ---- | M] (Google Inc.) -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
    PRC - [2013/06/05 18:28:40 | 027,370,808 | ---- | M] (Dropbox, Inc.) -- E:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2013/06/05 18:28:40 | 027,370,808 | ---- | M] (Dropbox, Inc.) -- E:\Users\darren\AppData\Roaming\Dropbox\bin\Dropbox.exe
    PRC - [2013/06/03 17:25:26 | 000,033,928 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe
    PRC - [2013/06/03 17:25:24 | 001,563,784 | ---- | M] (Plex, Inc.) -- E:\Program Files\Plex\Plex Media Server\PlexDlnaServer.exe
    PRC - [2013/06/03 17:25:22 | 003,997,832 | ---- | M] (Plex, Inc.) -- E:\Program Files\Plex\Plex Media Server\Plex Media Server.exe
    PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
    PRC - [2013/03/19 03:49:16 | 000,069,632 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\smss.exe
    PRC - [2013/01/27 12:08:19 | 000,116,648 | ---- | M] (Google Inc.) -- E:\Users\darren\AppData\Local\Google\Update\GoogleUpdate.exe
    PRC - [2013/01/18 15:21:02 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- E:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    PRC - [2013/01/18 15:21:00 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- E:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    PRC - [2013/01/18 15:20:08 | 000,639,776 | ---- | M] (NVIDIA Corporation) -- E:\Windows\System32\nvvsvc.exe
    PRC - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    PRC - [2013/01/06 13:08:03 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
    PRC - [2013/01/05 23:09:31 | 000,116,648 | ---- | M] (Google Inc.) -- E:\Program Files\Google\Update\GoogleUpdate.exe
    PRC - [2012/12/21 16:27:46 | 000,057,008 | ---- | M] (Apple Inc.) -- E:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    PRC - [2012/12/06 12:14:42 | 000,056,416 | ---- | M] (Apple Inc.) -- E:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
    PRC - [2012/11/28 15:13:24 | 000,013,712 | ---- | M] (Apple Inc.) -- E:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
    PRC - [2012/11/23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\taskhost.exe
    PRC - [2012/09/17 07:39:30 | 000,171,600 | ---- | M] (Adobe Systems Incorporated) -- E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
    PRC - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2012/07/26 04:21:03 | 000,196,608 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\WUDFHost.exe
    PRC - [2012/06/12 11:18:56 | 000,224,960 | ---- | M] () -- E:\Program Files\Macrium\Reflect\ReflectService.exe
    PRC - [2012/03/28 02:28:44 | 000,735,168 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\Citrix\ICA Client\wfcrun32.exe
    PRC - [2012/03/28 02:27:06 | 000,309,184 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\Citrix\ICA Client\concentr.exe
    PRC - [2012/02/28 16:06:48 | 010,468,672 | ---- | M] () -- E:\Program Files\Digiarty\Air_Playit\airplayit.exe
    PRC - [2012/02/28 16:06:40 | 001,607,488 | ---- | M] (Digiarty, Inc.) -- E:\Program Files\Digiarty\Air_Playit\AirPS.exe
    PRC - [2012/02/22 06:59:18 | 001,493,120 | R--- | M] (ASUSTeK Computer Inc.) -- E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe
    PRC - [2012/02/17 07:26:00 | 000,149,120 | R--- | M] (ASUSTeK Computer Inc.) -- E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
    PRC - [2012/02/11 06:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\spoolsv.exe
    PRC - [2012/02/10 07:39:30 | 005,646,952 | ---- | M] (Realtek Semiconductor) -- E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
    PRC - [2012/02/02 10:56:35 | 000,951,936 | R--- | M] (ASUSTeK Computer Inc.) -- E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe
    PRC - [2012/01/23 15:28:50 | 000,190,832 | ---- | M] (DTS, Inc) -- E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe
    PRC - [2012/01/04 20:59:50 | 000,291,608 | R--- | M] (Intel Corporation) -- E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    PRC - [2011/11/17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\lsass.exe
    PRC - [2011/10/29 02:59:26 | 000,918,448 | R--- | M] () -- E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe
    PRC - [2011/08/31 00:05:02 | 000,390,504 | ---- | M] (Apple Inc.) -- E:\Program Files\Bonjour\mDNSResponder.exe
    PRC - [2011/08/15 18:38:50 | 000,117,920 | ---- | M] (Intel Corporation) -- E:\Windows\System32\IPROSetMonitor.exe
    PRC - [2011/06/16 18:00:28 | 000,315,256 | ---- | M] (Adobe Systems Incorporated) -- E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
    PRC - [2011/05/04 05:28:31 | 000,427,520 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\SearchIndexer.exe
    PRC - [2011/05/04 05:28:31 | 000,164,352 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\SearchProtocolHost.exe
    PRC - [2011/05/04 05:28:31 | 000,086,528 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\SearchFilterHost.exe
    PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- E:\Windows\explorer.exe
    PRC - [2010/11/20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Windows Media Player\wmpnetwk.exe
    PRC - [2010/11/20 13:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\wbem\WmiPrvSE.exe
    PRC - [2010/11/20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\winlogon.exe
    PRC - [2010/11/20 13:17:47 | 000,192,000 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\taskeng.exe
    PRC - [2010/11/20 13:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- E:\Program Files\Windows Sidebar\sidebar.exe
    PRC - [2010/11/20 13:17:16 | 000,267,776 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\lsm.exe
    PRC - [2010/11/20 13:17:16 | 000,010,752 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\LogonUI.exe
    PRC - [2009/07/14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\wininit.exe
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\svchost.exe  [comLaunch]
    PRC - [2009/07/14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\services.exe
    PRC - [2009/07/14 02:14:24 | 000,157,184 | ---- | M] (Microsoft Corporation) -- e:\Program Files\Windows Defender\MpCmdRun.exe
    PRC - [2009/07/14 02:14:19 | 000,092,672 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\dwm.exe
    PRC - [2009/07/14 02:14:16 | 000,006,144 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\csrss.exe
    PRC - [2007/04/04 02:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- E:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
     
     
    ========== Modules (No Company Name) ==========
     
    MOD - [2013/09/14 10:31:24 | 001,175,040 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._core_.pyd
    MOD - [2013/09/14 10:31:24 | 001,153,024 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_ssl.pyd
    MOD - [2013/09/14 10:31:24 | 001,062,400 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._controls_.pyd
    MOD - [2013/09/14 10:31:24 | 000,811,008 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._windows_.pyd
    MOD - [2013/09/14 10:31:24 | 000,805,888 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._gdi_.pyd
    MOD - [2013/09/14 10:31:24 | 000,735,232 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._misc_.pyd
    MOD - [2013/09/14 10:31:24 | 000,711,680 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_hashlib.pyd
    MOD - [2013/09/14 10:31:24 | 000,686,080 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\unicodedata.pyd
    MOD - [2013/09/14 10:31:24 | 000,557,056 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\pysqlite2._sqlite.pyd
    MOD - [2013/09/14 10:31:24 | 000,504,832 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\windows._cacheinvalidation.pyd
    MOD - [2013/09/14 10:31:24 | 000,364,544 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\pythoncom27.dll
    MOD - [2013/09/14 10:31:24 | 000,320,512 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32com.shell.shell.pyd
    MOD - [2013/09/14 10:31:24 | 000,128,512 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_elementtree.pyd
    MOD - [2013/09/14 10:31:24 | 000,127,488 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\pyexpat.pyd
    MOD - [2013/09/14 10:31:24 | 000,122,368 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._wizard.pyd
    MOD - [2013/09/14 10:31:24 | 000,119,808 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32file.pyd
    MOD - [2013/09/14 10:31:24 | 000,110,080 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\PyWinTypes27.dll
    MOD - [2013/09/14 10:31:24 | 000,108,544 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32security.pyd
    MOD - [2013/09/14 10:31:24 | 000,098,816 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32api.pyd
    MOD - [2013/09/14 10:31:24 | 000,087,040 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_ctypes.pyd
    MOD - [2013/09/14 10:31:24 | 000,070,656 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\wx._html2.pyd
    MOD - [2013/09/14 10:31:24 | 000,044,032 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_socket.pyd
    MOD - [2013/09/14 10:31:24 | 000,038,912 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32inet.pyd
    MOD - [2013/09/14 10:31:24 | 000,035,840 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32process.pyd
    MOD - [2013/09/14 10:31:24 | 000,026,624 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\_multiprocessing.pyd
    MOD - [2013/09/14 10:31:24 | 000,025,600 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32pdh.pyd
    MOD - [2013/09/14 10:31:24 | 000,022,528 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32ts.pyd
    MOD - [2013/09/14 10:31:24 | 000,018,432 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32event.pyd
    MOD - [2013/09/14 10:31:24 | 000,017,408 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32profile.pyd
    MOD - [2013/09/14 10:31:24 | 000,011,264 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\win32crypt.pyd
    MOD - [2013/09/14 10:31:24 | 000,010,240 | ---- | M] () -- E:\Users\darren\AppData\Local\Temp\_MEI38083\select.pyd
    MOD - [2013/08/22 03:05:06 | 001,226,752 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\4e7b7262234d31e42cb34d72ddb1a14b\System.WorkflowServices.ni.dll
    MOD - [2013/08/22 03:04:52 | 001,141,760 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b7ed4fb85e3e4d8b012dfd3a7c0435eb\System.ServiceModel.Discovery.ni.dll
    MOD - [2013/08/22 03:04:52 | 000,369,664 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\3a5eadca5d17af2aa06a4b5f40b588a6\System.ServiceModel.Routing.ni.dll
    MOD - [2013/08/22 03:04:51 | 000,082,432 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\1a335f477a925de13d86b720392a2b2e\System.ServiceModel.Channels.ni.dll
    MOD - [2013/08/22 03:04:45 | 001,394,176 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d301978a7b9dbe3f69c166bf00d5b858\System.ServiceModel.Activities.ni.dll
    MOD - [2013/08/22 03:04:43 | 018,101,760 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\8e155e090e2990b5afc341a2b068835b\System.ServiceModel.ni.dll
    MOD - [2013/08/22 03:04:43 | 001,078,272 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\d562a607bb4973993b59456d35f6307f\System.IdentityModel.ni.dll
    MOD - [2013/08/22 03:04:36 | 001,087,488 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\d7a30ba1e54ebb51f5bb79780aaf13e5\System.ServiceModel.Web.ni.dll
    MOD - [2013/08/22 03:03:52 | 001,021,952 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\0442e1dc48d826e9b795d1e67d552791\System.Runtime.DurableInstancing.ni.dll
    MOD - [2013/08/22 03:03:52 | 000,649,728 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\9f37a2a23772a8e9dcbef5c6b6ebe0ad\System.Transactions.ni.dll
    MOD - [2013/08/22 03:03:52 | 000,143,360 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\12d171dd78ad02e8561a46bf266c5394\SMDiagnostics.ni.dll
    MOD - [2013/08/22 03:03:51 | 002,647,552 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\0a3d8f846e42d481c0cc2200b7859858\System.Runtime.Serialization.ni.dll
    MOD - [2013/08/22 03:03:50 | 000,393,216 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\e77f989b5dae0c6d2367d534c73a31f9\System.Xml.Linq.ni.dll
    MOD - [2013/08/22 03:03:40 | 001,801,728 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\44d87641535e186f4a7fc9c469bc73dd\System.Xaml.ni.dll
    MOD - [2013/08/22 03:02:03 | 018,003,456 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a342a61dd88db0c26a11470ce6a4f167\PresentationFramework.ni.dll
    MOD - [2013/08/22 03:01:56 | 013,199,360 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\6da40f01a719972f3242d3c374e499c5\System.Windows.Forms.ni.dll
    MOD - [2013/08/22 03:01:56 | 011,451,904 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\42c02d5f442dea943fc7def7b864bb90\PresentationCore.ni.dll
    MOD - [2013/08/22 03:01:53 | 007,070,720 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\5c4f1eb1b2efdd138d137c5069a8bdf5\System.Core.ni.dll
    MOD - [2013/08/22 03:01:53 | 000,595,968 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\4f02f7d34c4fd0dc58ce1dffb5b424f9\PresentationFramework.Aero.ni.dll
    MOD - [2013/08/22 03:01:51 | 005,628,928 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\0835155203a99b6a9bb540629920da0d\System.Xml.ni.dll
    MOD - [2013/08/22 03:01:51 | 003,858,944 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\6a1d260372cda12056515b30b2bcf715\WindowsBase.ni.dll
    MOD - [2013/08/22 03:01:51 | 001,667,584 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\7e3570a0cc71998e14e7adb8e4ea0cbb\System.Drawing.ni.dll
    MOD - [2013/08/22 03:01:50 | 001,014,272 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\da18beba41f700dd4c71a3f5464c4342\System.Configuration.ni.dll
    MOD - [2013/08/22 03:01:49 | 009,099,776 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\System\fc16a5cafc433e6d942e9bd5b14fbeaf\System.ni.dll
    MOD - [2013/07/11 22:21:50 | 014,418,432 | ---- | M] () -- E:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\c799474a067f07ef3a167d75029fa012\mscorlib.ni.dll
    MOD - [2013/06/21 00:41:50 | 000,344,064 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll
    MOD - [2013/06/21 00:41:28 | 000,231,936 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll
    MOD - [2013/06/21 00:40:36 | 000,253,440 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libid3tag.dll
    MOD - [2013/06/21 00:40:00 | 000,117,248 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\libaacdec.dll
    MOD - [2013/06/03 17:26:02 | 000,033,416 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd
    MOD - [2013/06/03 17:26:00 | 000,196,232 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\lxml\objectify.pyd
    MOD - [2013/06/03 17:26:00 | 000,057,992 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\OpenSSL\crypto.pyd
    MOD - [2013/06/03 17:26:00 | 000,044,680 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\OpenSSL\SSL.pyd
    MOD - [2013/06/03 17:26:00 | 000,017,544 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\OpenSSL\rand.pyd
    MOD - [2013/06/03 17:25:58 | 000,841,864 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\Exts\lxml\etree.pyd
    MOD - [2013/06/03 17:25:58 | 000,825,480 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_ssl.pyd
    MOD - [2013/06/03 17:25:56 | 000,050,312 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_socket.pyd
    MOD - [2013/06/03 17:25:56 | 000,033,928 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_multiprocessing.pyd
    MOD - [2013/06/03 17:25:54 | 000,366,216 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_hashlib.pyd
    MOD - [2013/06/03 17:25:54 | 000,094,344 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\_ctypes.pyd
    MOD - [2013/06/03 17:25:52 | 000,590,472 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\unicodedata.pyd
    MOD - [2013/06/03 17:25:52 | 000,134,792 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\pyexpat.pyd
    MOD - [2013/06/03 17:25:52 | 000,017,544 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\DLLs\select.pyd
    MOD - [2013/06/03 17:25:50 | 000,072,840 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\zlib1.dll
    MOD - [2013/06/03 17:25:48 | 008,495,240 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\WebKit.dll
    MOD - [2013/06/03 17:25:48 | 000,629,384 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\tag.dll
    MOD - [2013/06/03 17:25:46 | 000,293,264 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\swscale-0.dll
    MOD - [2013/06/03 17:25:44 | 000,089,224 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\soci_core-vc80-3_0.dll
    MOD - [2013/06/03 17:25:44 | 000,051,848 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll
    MOD - [2013/06/03 17:25:40 | 000,173,704 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\libxslt.dll
    MOD - [2013/06/03 17:25:38 | 000,839,816 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\libxml2.dll
    MOD - [2013/06/03 17:25:36 | 000,063,624 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\libexslt.dll
    MOD - [2013/06/03 17:25:34 | 001,291,400 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\JavaScriptCore.dll
    MOD - [2013/06/03 17:25:30 | 001,038,984 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\cairo.dll
    MOD - [2013/06/03 17:25:30 | 000,952,968 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\CFLite.dll
    MOD - [2013/06/03 17:25:28 | 005,828,368 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\avcodec-52.dll
    MOD - [2013/06/03 17:25:28 | 001,255,128 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\avformat-52.dll
    MOD - [2013/06/03 17:25:28 | 000,272,072 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\avutil-50.dll
    MOD - [2013/06/03 17:25:26 | 000,033,928 | ---- | M] () -- E:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe
    MOD - [2013/03/13 21:48:52 | 024,978,944 | ---- | M] () -- E:\Users\darren\AppData\Roaming\Dropbox\bin\libcef.dll
    MOD - [2013/01/10 21:01:44 | 000,026,624 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll
    MOD - [2013/01/10 21:01:26 | 010,683,392 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll
    MOD - [2013/01/10 21:01:24 | 001,681,408 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll
    MOD - [2013/01/10 21:01:22 | 007,741,952 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtGui4.dll
    MOD - [2013/01/10 21:01:20 | 002,248,192 | ---- | M] () -- E:\Users\darren\AppData\Local\Programs\Google\MusicManager\QtCore4.dll
    MOD - [2012/11/14 00:32:50 | 003,558,400 | ---- | M] () -- E:\Users\darren\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
    MOD - [2012/08/17 22:38:56 | 000,479,160 | ---- | M] () -- E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
    MOD - [2012/05/30 21:06:48 | 000,087,912 | ---- | M] () -- E:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2012/05/30 21:06:30 | 001,242,512 | ---- | M] () -- E:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
     
     
    ========== Services (SafeList) ==========
     
    SRV - [2013/09/10 18:13:13 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- E:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2013/08/22 14:00:04 | 000,220,504 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- E:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
    SRV - [2013/08/21 12:56:50 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2013/05/27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2013/02/26 00:22:34 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
    SRV - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
    SRV - [2013/01/06 13:08:03 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe -- (AVP)
    SRV - [2012/09/17 07:39:30 | 000,171,600 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor11.0)
    SRV - [2012/07/27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2012/07/21 14:18:11 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
    SRV - [2012/06/12 11:18:56 | 000,224,960 | ---- | M] () [Auto | Running] -- E:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService.exe)
    SRV - [2012/03/20 00:44:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- E:\Windows\System32\IntelCpHeciSvc.exe -- (cphs)
    SRV - [2012/02/22 06:59:18 | 001,493,120 | R--- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe -- (AsusFanControlService)
    SRV - [2012/02/17 07:26:00 | 000,149,120 | R--- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe -- (AsSysCtrlService)
    SRV - [2012/02/02 10:56:35 | 000,951,936 | R--- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe -- (asHmComSvc)
    SRV - [2012/01/23 15:28:50 | 000,190,832 | ---- | M] (DTS, Inc) [Auto | Running] -- E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe -- (DTSAudioSvc)
    SRV - [2011/10/29 02:59:26 | 000,918,448 | R--- | M] () [Auto | Running] -- E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe -- (asComSvc)
    SRV - [2011/09/27 20:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- E:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
    SRV - [2011/08/15 18:38:50 | 000,117,920 | ---- | M] (Intel Corporation) [Auto | Running] -- E:\Windows\System32\IPROSetMonitor.exe -- (Intel®
    SRV - [2011/05/27 11:07:36 | 000,160,768 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- E:\Program Files\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)
    SRV - [2009/07/14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\StorSvc.dll -- (StorSvc)
    SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\sensrsvc.dll -- (SensrSvc)
    SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
     
     
    ========== Driver Services (SafeList) ==========
     
    DRV - File not found [Kernel | On_Demand | Stopped] -- E:\Users\darren\AppData\Local\Temp\ALSysIO.sys -- (ALSysIO)
    DRV - [2013/09/11 20:25:57 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
    DRV - [2013/06/18 21:22:01 | 000,044,000 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- E:\Windows\System32\drivers\kltdi.sys -- (kltdi)
    DRV - [2013/04/22 09:04:15 | 000,594,528 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- E:\Windows\System32\drivers\klif.sys -- (KLIF)
    DRV - [2013/04/22 09:04:15 | 000,145,040 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- E:\Windows\System32\drivers\kneps.sys -- (kneps)
    DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- E:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
    DRV - [2013/02/26 00:22:06 | 008,939,296 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
    DRV - [2013/02/18 13:59:44 | 000,452,816 | ---- | M] (Paragon) [Kernel | System | Running] -- E:\Windows\System32\drivers\Uim_IM.sys -- (Uim_IM)
    DRV - [2013/02/18 13:59:44 | 000,283,600 | ---- | M] (Paragon) [Kernel | System | Running] -- E:\Windows\System32\drivers\Uim_Vim.sys -- (Uim_Vim)
    DRV - [2013/02/18 13:59:44 | 000,081,232 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | System | Running] -- E:\Windows\System32\drivers\UimBus.sys -- (UimBus)
    DRV - [2013/01/06 13:22:46 | 000,025,944 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
    DRV - [2013/01/06 13:22:46 | 000,025,944 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\klkbdflt.sys -- (klkbdflt)
    DRV - [2012/08/04 10:19:29 | 000,163,616 | ---- | M] (Digiarty Software, Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\DigiartyVirtualCDBus.sys -- (DigiartyVirtualCDBus)
    DRV - [2012/08/02 16:09:30 | 000,024,408 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- E:\Windows\System32\drivers\klim6.sys -- (KLIM6)
    DRV - [2012/07/21 14:11:15 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- E:\Windows\System32\drivers\truecrypt.sys -- (truecrypt)
    DRV - [2012/06/19 18:28:12 | 000,136,024 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\kl1.sys -- (KL1)
    DRV - [2012/06/12 11:19:08 | 000,016,064 | ---- | M] (Macrium Software) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\pssnap.sys -- (pssnap)
    DRV - [2012/03/19 09:18:46 | 000,064,800 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- E:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
    DRV - [2012/02/21 18:46:20 | 000,315,368 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\asmtxhci.sys -- (asmtxhci)
    DRV - [2012/02/21 18:46:18 | 000,102,888 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\asmthub3.sys -- (asmthub3)
    DRV - [2012/01/17 13:45:58 | 000,148,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
    DRV - [2012/01/06 11:44:30 | 000,043,104 | ---- | M] (Asmedia Technology) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\asahci32.sys -- (asahci32)
    DRV - [2012/01/04 20:58:50 | 000,789,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\iusb3xhc.sys -- (iusb3xhc)
    DRV - [2012/01/04 20:58:50 | 000,347,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\iusb3hub.sys -- (iusb3hub)
    DRV - [2012/01/04 20:58:50 | 000,013,592 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\iusb3hcs.sys -- (iusb3hcs)
    DRV - [2011/11/10 00:52:02 | 000,046,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\HECI.sys -- (MEI)
    DRV - [2011/09/20 05:25:28 | 000,037,448 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\ASUSFILTER.sys -- (ASUSFILTER)
    DRV - [2011/09/02 07:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
    DRV - [2011/09/02 07:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
    DRV - [2011/08/12 11:13:58 | 000,028,264 | R--- | M] (NT Kernel Resources) [Kernel | System | Running] -- E:\Windows\System32\drivers\ndisrd.sys -- (ndisrd)
    DRV - [2011/07/20 02:36:42 | 000,268,968 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\e1c6232.sys -- (e1cexpress)
    DRV - [2011/03/18 14:46:26 | 000,061,704 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
    DRV - [2011/03/18 14:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
    DRV - [2010/11/20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\vmbus.sys -- (vmbus)
    DRV - [2010/11/20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
    DRV - [2010/11/20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\storvsc.sys -- (storvsc)
    DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\winusb.sys -- (WinUsb)
    DRV - [2010/11/20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
    DRV - [2010/11/20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
    DRV - [2010/10/20 19:12:14 | 000,013,440 | ---- | M] (ASUSTek Computer Inc.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\AiCharger.sys -- (AiCharger)
    DRV - [2010/08/24 08:31:08 | 000,011,456 | R--- | M] () [Kernel | System | Running] -- E:\Windows\System32\drivers\AsIO.sys -- (AsIO)
    DRV - [2010/08/17 18:28:34 | 000,022,040 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- E:\Windows\System32\drivers\ICCWDT.sys -- (ICCWDT)
    DRV - [2010/08/03 06:20:56 | 000,011,832 | R--- | M] () [Kernel | System | Running] -- E:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO)
    DRV - [2009/07/14 00:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\serial.sys -- (Serial)
    DRV - [2002/04/02 17:30:16 | 000,033,024 | ---- | M] (Colorvision Inc) [Kernel | On_Demand | Stopped] -- E:\Windows\System32\drivers\cvspydr2.sys -- (cvspydr2)
     
     
    ========== Standard Registry (SafeList) ==========
     
     
    ========== Internet Explorer ==========
     
    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
     
     
    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
     
    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
     
    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
     
    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
     
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.uk/
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 1B C4 92 D0 66 CD 01  [binary data]
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
     
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.uk/
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 20 01 61 78 8B 70 CD 01  [binary data]
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes,DefaultScope = {700F9637-8FFE-4759-ACDA-902AA7E96400}
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=111434&tt=3012_7&babsrc=SP_ss&mntrId=6a229dba00000000000010bf48799c74
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\SearchScopes\{700F9637-8FFE-4759-ACDA-902AA7E96400}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_UK&apn_ptnrs=U3&apn_dtid=OSJ000YYGB&apn_uid=CC5C6200-CD42-424D-BB72-6AC5CA6A51AF&apn_sauid=F122E31C-AE4A-4E14-86F0-B8C33DBD31BE
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
     
     
    ========== FireFox ==========
     
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: E:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: E:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: E:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Users\darren\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Users\darren\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
     
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/21 20:44:00 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\url_advisor@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtual_keyboard@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\content_blocker@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\anti_banner@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\online_banking@kaspersky.com: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013/04/22 09:04:16 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2013/08/21 12:56:42 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2013/08/21 12:56:45 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/21 20:44:00 | 000,000,000 | ---D | M]
     
    [2012/08/23 21:13:10 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Extensions
    [2013/09/14 10:40:18 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions
    [2013/05/16 20:49:58 | 000,000,000 | ---D | M] (WOT) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
    [2013/08/28 10:58:10 | 000,000,000 | ---D | M] (DownloadHelper) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2013/09/14 10:40:18 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\staged
    [2013/09/05 21:59:57 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions
    [2013/08/21 12:56:42 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\browser\extensions
    [2013/08/21 12:56:51 | 000,000,000 | ---D | M] (Default) -- E:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    [2012/03/28 02:04:52 | 000,124,864 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\CCMSDK.dll
    [2012/03/28 02:06:54 | 000,071,104 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\CgpCore.dll
    [2012/03/28 02:05:52 | 000,092,096 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\confmgr.dll
    [2012/03/28 02:05:28 | 000,022,976 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\ctxlogging.dll
    [2008/06/19 10:16:24 | 000,118,784 | ---- | M] (CANON INC.) -- E:\Program Files\mozilla firefox\plugins\MyCamera.dll
    [2008/06/19 10:16:24 | 000,053,248 | ---- | M] (CANON INC.) -- E:\Program Files\mozilla firefox\plugins\NPCIG.dll
    [2012/03/28 02:48:16 | 000,489,384 | ---- | M] () -- E:\Program Files\mozilla firefox\plugins\npicaN.dll
    [2012/03/28 02:06:48 | 000,024,512 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\TcpPServ.dll
     
    O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
    O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
    O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
    O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
    O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
    O3 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [APSDaemon] E:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [AVP] E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
    O4 - HKLM..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
    O4 - HKLM..\Run: [ConnectionCenter] E:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
    O4 - HKLM..\Run: [RTHDVCPL] E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [uSB3MON] E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [GarminExpressTrayApp] E:\Program Files\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [GoogleDriveSync] E:\Program Files\Google\Drive\googledrivesync.exe (Google)
    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [MusicManager] E:\Users\darren\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [Plex Media Server] E:\Program Files\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004..\Run: [Digiarty_Software_AirPlayit] E:\Program Files\Digiarty\Air_Playit\airplayit.exe ()
    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004..\Run: [spotify] E:\Users\Henry\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd)
    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004..\Run: [spotify Web Helper] E:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
    O4 - Startup: E:\Users\darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = E:\Users\darren\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    O4 - Startup: E:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = E:\Users\darren\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Add to Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
    O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
    O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E61F5A10-0F68-4278-A870-B674D08ED3BF}: DhcpNameServer = 194.168.4.100 194.168.8.100
    O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (E:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\LBTWlgn: DllName - (e:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - e:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
     
    ========== Files/Folders - Created Within 30 Days ==========
     
    [2013/09/15 19:21:30 | 000,602,112 | ---- | C] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL - Copy.exe
    [2013/09/15 19:20:45 | 000,602,112 | ---- | C] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL.exe
    [2013/09/12 03:02:12 | 002,876,928 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll
    [2013/09/12 03:02:12 | 002,706,432 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
    [2013/09/12 03:02:12 | 000,391,168 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll
    [2013/09/12 03:02:12 | 000,061,440 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iesetup.dll
    [2013/09/12 03:02:12 | 000,039,424 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll
    [2013/09/12 03:02:11 | 000,493,056 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeeds.dll
    [2013/09/12 03:02:11 | 000,109,056 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iesysprep.dll
    [2013/09/12 03:02:11 | 000,071,680 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\RegisterIEPKEYs.exe
    [2013/09/12 03:02:11 | 000,042,496 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ie4uinit.exe
    [2013/09/12 03:02:11 | 000,033,280 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\iernonce.dll
    [2013/09/11 23:27:05 | 000,133,056 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\ataport.sys
    [2013/09/11 23:27:04 | 002,348,544 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys
    [2013/09/11 23:27:03 | 000,271,360 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\conhost.exe
    [2013/09/11 23:27:03 | 000,169,984 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\winsrv.dll
    [2013/09/11 23:27:03 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
    [2013/09/11 23:27:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- E:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
    [2013/09/11 20:25:42 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- E:\Windows\System32\drivers\mbamswissarmy.sys
    [2013/09/09 21:08:42 | 000,000,000 | ---D | C] -- E:\ProgramData\boost_interprocess
    [2013/09/09 21:02:53 | 000,000,000 | ---D | C] -- E:\AdwCleaner
    [2013/09/05 22:23:40 | 000,000,000 | ---D | C] -- E:\Users\darren\Documents\Garmin
    [2013/09/05 22:22:59 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
    [2013/09/05 22:22:56 | 000,000,000 | ---D | C] -- E:\Program Files\Garmin
    [2013/09/05 22:22:53 | 000,000,000 | ---D | C] -- E:\ProgramData\Package Cache
    [2013/09/05 22:04:14 | 000,000,000 | ---D | C] -- E:\Windows\ERUNT
    [2013/09/05 15:56:09 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2013/09/05 15:56:08 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- E:\Windows\System32\drivers\mbam.sys
    [2013/09/05 15:56:08 | 000,000,000 | ---D | C] -- E:\Program Files\Malwarebytes' Anti-Malware
    [2013/08/25 12:23:07 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    [2013/08/22 03:02:26 | 000,000,000 | ---D | C] -- E:\Windows\System32\MRT
    [2013/08/21 13:56:02 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2013/08/21 13:55:53 | 000,000,000 | ---D | C] -- E:\Program Files\iTunes
    [2013/08/21 13:55:53 | 000,000,000 | ---D | C] -- E:\Program Files\iPod
    [2013/08/21 13:55:53 | 000,000,000 | ---D | C] -- E:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
    [2013/08/21 12:56:41 | 000,000,000 | ---D | C] -- E:\Program Files\Mozilla Firefox
    [2013/08/21 12:15:08 | 003,968,960 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ntkrnlpa.exe
    [2013/08/21 12:15:08 | 003,913,664 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ntoskrnl.exe
    [2013/08/21 12:15:03 | 001,620,992 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\WMVDECOD.DLL
    [2013/08/21 12:14:53 | 000,002,048 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\tzres.dll
    [1 E:\Users\darren\Documents\*.tmp files -> E:\Users\darren\Documents\*.tmp -> ]
     
    ========== Files - Modified Within 30 Days ==========
     
    [2013/09/15 19:25:27 | 000,000,882 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013/09/15 19:24:56 | 000,000,860 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000Core.job
    [2013/09/15 19:20:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL.exe
    [2013/09/15 19:20:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL - Copy.exe
    [2013/09/15 19:19:45 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
    [2013/09/15 19:18:30 | 000,000,912 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000UA.job
    [2013/09/15 19:18:30 | 000,000,886 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013/09/15 19:18:05 | 000,000,830 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job
    [2013/09/14 12:23:42 | 003,750,790 | ---- | M] () -- E:\Windows\System32\perfh009.dat
    [2013/09/14 12:23:42 | 001,739,608 | ---- | M] () -- E:\Windows\System32\perfc009.dat
    [2013/09/14 10:38:19 | 000,013,456 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2013/09/14 10:38:19 | 000,013,456 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2013/09/14 10:31:09 | 2795,933,696 | -HS- | M] () -- E:\hiberfil.sys
    [2013/09/12 03:20:36 | 002,693,232 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT
    [2013/09/11 20:25:57 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- E:\Windows\System32\drivers\mbamswissarmy.sys
    [2013/09/10 18:13:13 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerApp.exe
    [2013/09/10 18:13:13 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerCPLApp.cpl
    [2013/09/09 21:02:49 | 001,037,278 | ---- | M] () -- E:\Users\darren\Desktop\AdwCleaner(1).exe
    [2013/09/05 22:22:59 | 000,001,895 | ---- | M] () -- E:\Users\Public\Desktop\Garmin Express.lnk
    [2013/09/05 15:56:09 | 000,001,104 | ---- | M] () -- E:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013/08/25 12:23:07 | 000,001,061 | ---- | M] () -- E:\Users\Public\Desktop\VLC media player.lnk
    [2013/08/22 20:05:53 | 000,002,042 | ---- | M] () -- E:\Users\darren\Desktop\Kies Air Discovery Service.lnk
    [2013/08/21 13:56:02 | 000,001,790 | ---- | M] () -- E:\Users\Public\Desktop\iTunes.lnk
    [1 E:\Users\darren\Documents\*.tmp files -> E:\Users\darren\Documents\*.tmp -> ]
     
    ========== Files Created - No Company Name ==========
     
    [2013/09/09 21:02:42 | 001,037,278 | ---- | C] () -- E:\Users\darren\Desktop\AdwCleaner(1).exe
    [2013/09/05 22:22:59 | 000,001,895 | ---- | C] () -- E:\Users\Public\Desktop\Garmin Express.lnk
    [2013/09/05 15:56:09 | 000,001,104 | ---- | C] () -- E:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013/08/22 20:05:53 | 000,002,042 | ---- | C] () -- E:\Users\darren\Desktop\Kies Air Discovery Service.lnk
    [2012/09/12 22:58:37 | 005,221,448 | ---- | C] () -- E:\Windows\System32\SpoonUninstall.exe
    [2012/08/21 20:41:25 | 000,164,567 | ---- | C] () -- E:\Windows\hpoins27.dat
    [2012/08/21 20:41:25 | 000,000,442 | ---- | C] () -- E:\Windows\hpomdl27.dat
    [2012/08/19 14:49:03 | 002,953,448 | ---- | C] () -- E:\Windows\System32\nvcoproc.bin
    [2012/08/02 23:47:39 | 001,048,576 | ---- | C] () -- E:\Windows\PE_Rom.dll
    [2012/08/02 22:22:00 | 000,056,140 | ---- | C] () -- E:\Windows\Ascd_log.ini
    [2012/08/02 22:21:27 | 000,011,456 | R--- | C] () -- E:\Windows\System32\drivers\AsIO.sys
    [2012/08/02 22:21:25 | 000,011,832 | ---- | C] () -- E:\Windows\System32\drivers\AsInsHelp64.sys
    [2012/07/21 22:32:35 | 000,066,048 | ---- | C] () -- E:\Windows\System32\PrintBrmUi.exe
    [2012/07/21 13:48:54 | 000,017,408 | ---- | C] () -- E:\Users\darren\AppData\Local\WebpageIcons.db
    [2012/07/21 00:29:42 | 000,001,332 | R--- | C] () -- E:\Windows\System32\drivers\DTSU2P.DAT
    [2012/07/21 00:29:33 | 000,238,448 | ---- | C] () -- E:\Windows\System32\drivers\RTAIODAT.DAT
    [2012/07/21 00:27:24 | 000,001,769 | ---- | C] () -- E:\Windows\Language_trs.ini
    [2012/07/21 00:27:12 | 000,041,993 | ---- | C] () -- E:\Windows\Ascd_tmp.ini
    [2012/03/20 00:37:12 | 000,755,188 | ---- | C] () -- E:\Windows\System32\igkrng700.bin
    [2012/03/20 00:37:12 | 000,561,508 | ---- | C] () -- E:\Windows\System32\igfcg700m.bin
    [2012/03/20 00:25:58 | 000,058,880 | ---- | C] () -- E:\Windows\System32\igdde32.dll
    [2012/03/19 23:23:38 | 013,024,256 | ---- | C] () -- E:\Windows\System32\ig7icd32.dll
    [2012/03/19 23:11:22 | 000,009,216 | ---- | C] ( ) -- E:\Windows\System32\IGFXDEVLib.dll
    [2012/03/19 23:09:28 | 000,000,264 | ---- | C] () -- E:\Windows\System32\GfxUI.exe.config
    [2012/03/19 23:09:08 | 000,094,208 | ---- | C] () -- E:\Windows\System32\IccLibDll.dll
     
    ========== ZeroAccess Check ==========
     
    [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- E:\Windows\assembly\Desktop.ini
     
    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
     
    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
     
    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment
     
    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free
     
    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
    "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    < End of report >
     

  9. Ah, sorry

    step 3 log attached..

     

    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Database version: v2013.09.11.07

    Windows 7 Service Pack 1 x86 NTFS
    Internet Explorer 10.0.9200.16660
    darren :: DARREN-PC [administrator]

    11/09/2013 20:26:20
    mbam-log-2013-09-11 (20-26-20).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 320364
    Time elapsed: 4 minute(s), 6 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     

  10. Hi Borislav

    Thank you very much for your time.

    Logs attached..

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 5.5.9 (09.07.2013:1)
    OS: Windows 7 Professional x86
    Ran by darren on 09/09/2013 at 20:53:53.62
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values



    ~~~ Registry Keys



    ~~~ Files



    ~~~ Folders

    Failed to delete: [Folder] "E:\ProgramData\boost_interprocess"
    Failed to delete: [Folder] "E:\ProgramData\application data\boost_interprocess"



    ~~~ Event Viewer Logs were cleared





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 09/09/2013 at 20:56:09.99
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     

     

     

     

    # AdwCleaner v3.003 - Report created 09/09/2013 at 21:07:21
    # Updated 07/09/2013 by Xplode
    # Operating System : Windows 7 Professional Service Pack 1 (32 bits)
    # Username : darren - DARREN-PC
    # Running from : E:\Users\darren\Desktop\AdwCleaner(1).exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : E:\ProgramData\boost_interprocess

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****


    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16660


    -\\ Mozilla Firefox v23.0.1 (en-US)

    [ File : E:\Users\Jo\AppData\Roaming\Mozilla\Firefox\Profiles\29paubt4.default\prefs.js ]


    [ File : E:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\8hcnb902.default\prefs.js ]


    *************************

    AdwCleaner[R0].txt - [2487 octets] - [09/09/2013 21:02:56]
    AdwCleaner[R1].txt - [1042 octets] - [09/09/2013 21:07:10]
    AdwCleaner[s0].txt - [2490 octets] - [09/09/2013 21:03:57]
    AdwCleaner[s1].txt - [969 octets] - [09/09/2013 21:07:21]

    ########## EOF - E:\AdwCleaner\AdwCleaner[s1].txt - [1028 octets] ##########
     

  11. HI

    I have the Delta Search infection, which resets my browser home page to Delta search, also any new tabs get redirected to delta search. I downloaded and ran Malwarbytes which found some issues which I removed. I have reset my homepages, but still have the issue with new tabs being diverted to delta search.

    I tried to download DDS to run and attach my scripts buy I got the following error, not sure if the infection is blocking it?

    E:\Users\darren\AppData\Local\Temp\_M1h+Z3G.scr.part could not be saved, because the source file could not be read.

    Try again later, or contact the server administrator.

    Please help.

    OK, I've managed to get DDS downoaded and the logs are below.

    DDS (Ver_2012-11-20.01) - NTFS_x86

    Internet Explorer: 10.0.9200.16660 BrowserJavaVersion: 10.9.2

    Run by darren at 17:10:03 on 2013-09-08

    Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.3555.1334 [GMT 1:00]

    .

    AV: Kaspersky Internet Security *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}

    SP: Kaspersky Internet Security *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}

    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    FW: Kaspersky Internet Security *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}

    .

    ============== Running Processes ================

    .

    E:\Windows\system32\wininit.exe

    E:\Windows\system32\lsm.exe

    E:\Windows\system32\nvvsvc.exe

    E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    E:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

    E:\Windows\system32\nvvsvc.exe

    E:\Windows\System32\spoolsv.exe

    E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    E:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe

    E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe

    E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe

    E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe

    E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe

    E:\Program Files\Bonjour\mDNSResponder.exe

    E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe

    E:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe

    E:\Windows\system32\IProsetMonitor.exe

    E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe

    E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    E:\Program Files\Macrium\Reflect\ReflectService.exe

    E:\Windows\System32\WUDFHost.exe

    E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    E:\Windows\system32\Dwm.exe

    E:\Windows\Explorer.EXE

    E:\Windows\system32\taskhost.exe

    E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe

    E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

    E:\Program Files\Citrix\ICA Client\concentr.exe

    E:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

    E:\Program Files\Citrix\ICA Client\wfcrun32.exe

    E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe

    E:\Program Files\iTunes\iTunesHelper.exe

    E:\Program Files\Google\Drive\googledrivesync.exe

    E:\Program Files\Windows Sidebar\sidebar.exe

    E:\Users\darren\AppData\Local\Programs\Google\MusicManager\MusicManager.exe

    E:\Program Files\Plex\Plex Media Server\Plex Media Server.exe

    E:\Program Files\Garmin\Express Tray\ExpressTray.exe

    E:\Users\darren\AppData\Roaming\Dropbox\bin\Dropbox.exe

    E:\Program Files\Google\Drive\googledrivesync.exe

    E:\Program Files\NVIDIA Corporation\Display\nvtray.exe

    E:\Program Files\iPod\bin\iPodService.exe

    E:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe

    E:\Windows\system32\conhost.exe

    E:\Windows\system32\SearchIndexer.exe

    E:\Program Files\Windows Media Player\wmpnetwk.exe

    E:\Program Files\Plex\Plex Media Server\PlexDlnaServer.exe

    E:\Program Files\Mozilla Firefox\firefox.exe

    E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

    E:\Windows\system32\Dwm.exe

    E:\Windows\Explorer.EXE

    E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe

    E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

    E:\Program Files\Citrix\ICA Client\concentr.exe

    E:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

    E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe

    E:\Program Files\Citrix\ICA Client\wfcrun32.exe

    E:\Program Files\iTunes\iTunesHelper.exe

    E:\Program Files\Digiarty\Air_Playit\airplayit.exe

    E:\Program Files\Windows Sidebar\sidebar.exe

    E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    E:\Windows\system32\DllHost.exe

    E:\Program Files\Digiarty\Air_Playit\AirPS.exe

    E:\Windows\system32\conhost.exe

    E:\Program Files\Internet Explorer\iexplore.exe

    E:\Program Files\Internet Explorer\iexplore.exe

    E:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

    E:\Windows\system32\nvvsvc.exe

    E:\Windows\system32\taskhost.exe

    E:\Windows\system32\SearchProtocolHost.exe

    E:\Windows\system32\taskeng.exe

    E:\Windows\system32\SearchFilterHost.exe

    E:\Windows\system32\DllHost.exe

    E:\Windows\system32\DllHost.exe

    E:\Windows\system32\conhost.exe

    E:\Windows\system32\wbem\wmiprvse.exe

    E:\Windows\system32\svchost.exe -k DcomLaunch

    E:\Windows\system32\svchost.exe -k RPCSS

    E:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    E:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    E:\Windows\system32\svchost.exe -k LocalService

    E:\Windows\system32\svchost.exe -k netsvcs

    E:\Windows\system32\svchost.exe -k NetworkService

    E:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    E:\Windows\system32\svchost.exe -k hpdevmgmt

    E:\Windows\System32\svchost.exe -k HPZ12

    E:\Windows\System32\svchost.exe -k HPZ12

    E:\Windows\system32\svchost.exe -k imgsvc

    E:\Windows\System32\svchost.exe -k secsvcs

    E:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    E:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    E:\Windows\System32\svchost.exe -k LocalServicePeerNet

    .

    ============== Pseudo HJT Report ===============

    .

    BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll

    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

    BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - e:\program files\kaspersky lab\kaspersky internet security 2013\ieext\contentblocker\ie_content_blocker_plugin.dll

    BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - e:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll

    BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - e:\program files\java\jre7\bin\ssv.dll

    BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - e:\program files\kaspersky lab\kaspersky internet security 2013\ieext\onlinebanking\online_banking_bho.dll

    BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - e:\program files\java\jre7\bin\jp2ssv.dll

    BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - e:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll

    BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

    EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll

    uRun: [GoogleDriveSync] "e:\program files\google\drive\googledrivesync.exe" /autostart

    uRun: [sidebar] e:\program files\windows sidebar\sidebar.exe /autoRun

    uRun: [Google Update] "e:\users\darren\appdata\local\google\update\GoogleUpdate.exe" /c

    uRun: [MusicManager] "e:\users\darren\appdata\local\programs\google\musicmanager\MusicManager.exe"

    uRun: [Plex Media Server] "e:\program files\plex\plex media server\Plex Media Server.exe"

    uRun: [GarminExpressTrayApp] "e:\program files\garmin\express tray\ExpressTray.exe"

    mRun: [RTHDVCPL] e:\program files\realtek\audio\hda\RtkNGUI.exe -s

    mRun: [uSB3MON] "e:\program files\intel\intel® usb 3.0 extensible host controller driver\application\iusb3mon.exe"

    mRun: [HotKeysCmds] e:\windows\system32\hkcmd.exe

    mRun: [Persistence] e:\windows\system32\igfxpers.exe

    mRun: [ConnectionCenter] "e:\program files\citrix\ica client\concentr.exe" /startup

    mRun: [CanonMyPrinter] e:\program files\canon\myprinter\BJMyPrt.exe /logon

    mRun: [APSDaemon] "e:\program files\common files\apple\apple application support\APSDaemon.exe"

    mRun: [AdobeAAMUpdater-1.0] "e:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"

    mRun: [AVP] "e:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe"

    mRun: [iTunesHelper] "e:\program files\itunes\iTunesHelper.exe"

    StartupFolder: e:\users\darren\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - e:\users\darren\appdata\roaming\dropbox\bin\Dropbox.exe

    uPolicies-Explorer: NoDrives = dword:0

    mPolicies-Explorer: NoDrives = dword:0

    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

    mPolicies-System: ConsentPromptBehaviorUser = dword:3

    mPolicies-System: EnableUIADesktopToggle = dword:0

    IE: Add to Anti-Banner - e:\program files\kaspersky lab\kaspersky internet security 2013\ie_banner_deny.htm

    IE: E&xport to Microsoft Excel - e:\progra~1\micros~2\office12\EXCEL.EXE/3000

    IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - e:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll

    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

    IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - e:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll

    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

    TCP: NameServer = 194.168.4.100 194.168.8.100

    TCP: Interfaces\{E61F5A10-0F68-4278-A870-B674D08ED3BF} : DHCPNameServer = 194.168.4.100 194.168.8.100

    Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - e:\program files\citrix\ica client\IcaMimeFilter.dll

    Notify: igfxcui - igfxdev.dll

    Notify: LBTWlgn - e:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

    .

    ================= FIREFOX ===================

    .

    FF - ProfilePath -

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 asahci32;asahci32;e:\windows\system32\drivers\asahci32.sys [2012-1-6 43104]

    R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;e:\windows\system32\drivers\iusb3hcs.sys [2012-7-21 13592]

    R0 pssnap;Paramount Software Snapshot Filter;e:\windows\system32\drivers\pssnap.sys [2012-6-12 16064]

    R1 AsUpIO;AsUpIO;e:\windows\system32\drivers\AsUpIO.sys [2010-8-3 11832]

    R1 ctxusbm;Citrix USB Monitor Driver;e:\windows\system32\drivers\ctxusbm.sys [2012-3-19 64800]

    R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;e:\windows\system32\drivers\klim6.sys [2012-8-2 24408]

    R1 kltdi;kltdi;e:\windows\system32\drivers\kltdi.sys [2012-6-8 44000]

    R1 kneps;kneps;e:\windows\system32\drivers\kneps.sys [2012-8-13 145040]

    R1 ndisrd;WinpkFilter LightWeight Filter;e:\windows\system32\drivers\ndisrd.sys [2012-8-2 28264]

    R1 Uim_Vim;UIM Virtual Image Plugin;e:\windows\system32\drivers\Uim_Vim.sys [2013-2-18 283600]

    R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11;e:\program files\adobe\elements 11 organizer\PhotoshopElementsFileAgent.exe [2012-9-17 171600]

    R2 asComSvc;ASUS Com Service;e:\program files\asus\axsp\1.00.18\atkexComSvc.exe [2011-10-29 918448]

    R2 asHmComSvc;ASUS HM Com Service;e:\program files\asus\aahm\1.00.20\aaHMSvc.exe [2012-2-2 951936]

    R2 AsSysCtrlService;ASUS System Control Service;e:\program files\asus\assysctrlservice\1.00.13\AsSysCtrlService.exe [2012-8-2 149120]

    R2 AsusFanControlService;AsusFanControlService;e:\program files\asus\asusfancontrolservice\1.00.25\AsusFanControlService.exe [2012-8-2 1493120]

    R2 AVP;Kaspersky Anti-Virus Service;e:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe -r --> e:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe -r [?]

    R2 DTSAudioSvc;DTSAudioSvc;e:\program files\realtek\audio\hda\DTSU2PAuSrv32.exe [2012-7-21 190832]

    R2 Garmin Core Update Service;Garmin Core Update Service;e:\program files\garmin\core update service\Garmin.Cartography.MapUpdate.CoreService.exe [2013-8-22 220504]

    R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;e:\windows\system32\IPROSetMonitor.exe [2012-7-21 117920]

    R2 MBAMScheduler;MBAMScheduler;e:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-9-5 418376]

    R2 MBAMService;MBAMService;e:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-9-5 701512]

    R2 ReflectService.exe;Macrium Reflect Image Mounting Service;e:\program files\macrium\reflect\ReflectService.exe [2012-6-12 224960]

    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;e:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-1-18 383264]

    R3 asmthub3;ASMedia USB3 Hub Service;e:\windows\system32\drivers\asmthub3.sys [2012-2-21 102888]

    R3 asmtxhci;ASMEDIA XHCI Service;e:\windows\system32\drivers\asmtxhci.sys [2012-2-21 315368]

    R3 ASUSFILTER;ASUSFILTER;e:\windows\system32\drivers\ASUSFILTER.sys [2011-9-20 37448]

    R3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);e:\windows\system32\drivers\ICCWDT.sys [2010-8-17 22040]

    R3 iusb3hub;Intel® USB 3.0 Hub Driver;e:\windows\system32\drivers\iusb3hub.sys [2012-7-21 347928]

    R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;e:\windows\system32\drivers\iusb3xhc.sys [2012-7-21 789272]

    R3 klkbdflt;Kaspersky Lab KLKBDFLT;e:\windows\system32\drivers\klkbdflt.sys [2012-5-25 25944]

    R3 klmouflt;Kaspersky Lab KLMOUFLT;e:\windows\system32\drivers\klmouflt.sys [2012-7-25 25944]

    R3 MBAMProtector;MBAMProtector;e:\windows\system32\drivers\mbam.sys [2013-9-5 22856]

    R3 MEI;Intel® Management Engine Interface ;e:\windows\system32\drivers\HECI.sys [2011-11-10 46080]

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

    S3 AiCharger;AiCharger;e:\windows\system32\drivers\AiCharger.sys [2012-8-2 13440]

    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;e:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

    S3 DigiartyVirtualCDBus;Digiarty Virtual Driver;e:\windows\system32\drivers\DigiartyVirtualCDBus.sys [2012-8-1 163616]

    S3 ICCS;Intel® Integrated Clock Controller Service - Intel® ICCS;e:\program files\intel\intel® integrated clock controller service\ICCProxy.exe [2012-8-2 160768]

    S3 StorSvc;Storage Service;e:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]

    S3 TsUsbFlt;TsUsbFlt;e:\windows\system32\drivers\TsUsbFlt.sys [2012-7-21 52224]

    S3 WatAdminSvc;Windows Activation Technologies Service;e:\windows\system32\wat\WatAdminSvc.exe [2012-7-21 1343400]

    .

    =============== File Associations ===============

    .

    ShellExec: PortraitProfessional.exe: open="e:\program files\portrait professional studio 11\PortraitProfessionalStudio.exe" /P "%1"

    .

    =============== Created Last 30 ================

    .

    2013-09-06 15:55:20 7166848 ----a-w- e:\programdata\microsoft\windows defender\definition updates\{37bb2029-d4b4-44fb-937e-3ba42f3082da}\mpengine.dll

    2013-09-05 21:22:56 -------- d-----w- e:\program files\Garmin

    2013-09-05 21:22:53 -------- d-----w- e:\programdata\Package Cache

    2013-09-05 21:04:14 -------- d-----w- e:\windows\ERUNT

    2013-09-05 21:02:16 -------- d-----w- e:\programdata\boost_interprocess

    2013-09-05 14:56:08 22856 ----a-w- e:\windows\system32\drivers\mbam.sys

    2013-09-05 14:56:08 -------- d-----w- e:\program files\Malwarebytes' Anti-Malware

    2013-08-22 02:02:26 -------- d-----w- e:\windows\system32\MRT

    2013-08-21 12:55:53 -------- d-----w- e:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1

    2013-08-21 12:55:53 -------- d-----w- e:\program files\iTunes

    2013-08-21 12:55:53 -------- d-----w- e:\program files\iPod

    2013-08-21 11:15:08 652800 ----a-w- e:\windows\system32\rpcrt4.dll

    2013-08-21 11:15:08 3968960 ----a-w- e:\windows\system32\ntkrnlpa.exe

    2013-08-21 11:15:08 3913664 ----a-w- e:\windows\system32\ntoskrnl.exe

    2013-08-21 11:15:08 1289096 ----a-w- e:\windows\system32\ntdll.dll

    2013-08-21 11:15:07 175104 ----a-w- e:\windows\system32\wintrust.dll

    2013-08-21 11:15:07 140288 ----a-w- e:\windows\system32\cryptsvc.dll

    2013-08-21 11:15:07 1166848 ----a-w- e:\windows\system32\crypt32.dll

    2013-08-21 11:15:07 103936 ----a-w- e:\windows\system32\cryptnet.dll

    2013-08-21 11:15:03 1620992 ----a-w- e:\windows\system32\WMVDECOD.DLL

    2013-08-21 11:15:03 1293760 ----a-w- e:\windows\system32\drivers\tcpip.sys

    2013-08-21 11:14:53 2048 ----a-w- e:\windows\system32\tzres.dll

    2013-08-21 11:14:52 31232 ----a-w- e:\windows\system32\drivers\tssecsrv.sys

    .

    ==================== Find3M ====================

    .

    2013-08-21 11:13:08 71048 ----a-w- e:\windows\system32\FlashPlayerCPLApp.cpl

    2013-08-21 11:13:08 692104 ----a-w- e:\windows\system32\FlashPlayerApp.exe

    2013-07-26 03:13:24 1767936 ----a-w- e:\windows\system32\wininet.dll

    2013-07-26 03:12:04 2877440 ----a-w- e:\windows\system32\jscript9.dll

    2013-07-26 03:12:00 61440 ----a-w- e:\windows\system32\iesetup.dll

    2013-07-26 03:12:00 109056 ----a-w- e:\windows\system32\iesysprep.dll

    2013-07-26 02:49:14 2706432 ----a-w- e:\windows\system32\mshtml.tlb

    2013-07-26 01:59:38 71680 ----a-w- e:\windows\system32\RegisterIEPKEYs.exe

    2013-06-18 20:22:01 44000 ----a-w- e:\windows\system32\drivers\kltdi.sys

    2013-06-18 20:04:39 16400 ----a-w- e:\windows\system32\drivers\LNonPnP.sys

    .

    ============= FINISH: 17:15:29.10 ===============

    .

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

    IF REQUESTED, ZIP IT UP & ATTACH IT

    .

    DDS (Ver_2012-11-20.01)

    .

    Microsoft Windows 7 Professional

    Boot Device: \Device\HarddiskVolume1

    Install Date: 21/07/2012 00:23:13

    System Uptime: 08/09/2013 15:14:06 (2 hours ago)

    .

    Motherboard: ASUSTeK COMPUTER INC. | | P8Z77-V PRO

    Processor: Intel® Core i5-3570K CPU @ 3.40GHz | LGA1155 | 3401/100mhz

    .

    ==== Disk Partitions =========================

    .

    C: is FIXED (NTFS) - 1863 GiB total, 91.469 GiB free.

    D: is FIXED (NTFS) - 1863 GiB total, 253.258 GiB free.

    E: is FIXED (NTFS) - 119 GiB total, 43.226 GiB free.

    F: is FIXED (NTFS) - 1397 GiB total, 547.868 GiB free.

    G: is CDROM ()

    H: is FIXED (NTFS) - 1397 GiB total, 304.596 GiB free.

    I: is FIXED (NTFS) - 1863 GiB total, 789.75 GiB free.

    J: is FIXED (NTFS) - 1863 GiB total, 48.703 GiB free.

    K: is Removable

    L: is Removable

    M: is Removable

    N: is Removable

    O: is Removable

    .

    ==== Disabled Device Manager Items =============

    .

    Class GUID:

    Description: SM Bus Controller

    Device ID: PCI\VEN_8086&DEV_1E22&SUBSYS_84CA1043&REV_04\3&11583659&0&FB

    Manufacturer:

    Name: SM Bus Controller

    PNP Device ID: PCI\VEN_8086&DEV_1E22&SUBSYS_84CA1043&REV_04\3&11583659&0&FB

    Service:

    .

    ==== System Restore Points ===================

    .

    No restore point in system.

    .

    ==== Installed Programs ======================

    .

    32 Bit HP CIO Components Installer

    Adobe AIR

    Adobe Download Assistant

    Adobe Flash Player 11 ActiveX

    Adobe Flash Player 11 Plugin

    Adobe Photoshop Elements 11

    Adobe Photoshop Lightroom 4.2

    Adobe Premiere Elements 11

    Adobe Reader X (10.1.4)

    Air Playit 2.0.0

    Apple Application Support

    Apple Mobile Device Support

    Apple Software Update

    Asmedia ASM104x USB 3.0 Host Controller Driver

    Asmedia ASM106x SATA Host Controller Driver

    bluefin Desktop

    bluefin Desktop 4.0

    Bonjour

    BufferChm

    CANON iMAGE GATEWAY Task for ZoomBrowser EX

    Canon Internet Library for ZoomBrowser EX

    Canon iP4500 series

    Canon iP4500 series User Registration

    Canon My Printer

    Canon RAW Codec

    Canon Utilities CameraWindow

    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX

    Canon Utilities Digital Photo Professional 3.11

    Canon Utilities EOS Utility

    Canon Utilities MyCamera

    Canon Utilities Original Data Security Tools

    Canon Utilities PhotoStitch

    Canon Utilities Picture Style Editor

    Canon Utilities RemoteCapture Task for ZoomBrowser EX

    Canon Utilities WFT-E1/E2/E3 Utility

    Canon Utilities ZoomBrowser EX

    Canon ZoomBrowser EX Memory Card Utility

    CCleaner

    CD-LabelPrint

    Citrix online plug-in - web

    Citrix online plug-in (DV)

    Citrix online plug-in (HDX)

    Citrix online plug-in (USB)

    Citrix online plug-in (Web)

    Copy

    Core Temp 1.0 RC3

    Destinations

    DeviceDiscovery

    DJ_AIO_03_F2200_Software_Min

    Dropbox

    Elements 11 Organizer

    Elevated Installer

    eReg

    ESET Online Scanner v3

    ExPVR

    F2200

    Garmin Express

    Garmin Express Tray

    Garmin Update Service

    Google Drive

    Google Earth Plug-in

    Google Update Helper

    GPBaseService2

    HandBrake 0.9.8

    HP Customer Participation Program 13.0

    HP Deskjet F2200 All-In-One Driver Software 13.0 Rel. 3

    HP Imaging Device Functions 13.0

    HP Photosmart Essential 3.5

    HP Smart Web Printing 4.51

    HP Solution Center 13.0

    HP Update

    HPPhotoGadget

    HPPhotoSmartDiscLabelContent1

    HPPhotosmartEssential

    HPProductAssistant

    Intel® Network Connections 16.6.126.0

    Intel® USB 3.0 eXtensible Host Controller Driver

    Intel® Watchdog Timer Driver (Intel® WDT)

    iTunes

    Java 7 Update 9

    Java Auto Updater

    Kaspersky Internet Security 2013

    Logitech SetPoint 6.32

    M4a/Flac/Ogg/Ape/Mpc Tag Support Plugin for Media Player v 1.1

    Macrium Reflect Free Edition

    Malwarebytes Anti-Malware version 1.75.0.1300

    MarketResearch

    Microsoft .NET Framework 4 Client Profile

    Microsoft .NET Framework 4 Extended

    Microsoft Camera Codec Pack

    Microsoft Office 2007 Service Pack 3 (SP3)

    Microsoft Office Access MUI (English) 2007

    Microsoft Office Access Setup Metadata MUI (English) 2007

    Microsoft Office Excel MUI (English) 2007

    Microsoft Office File Validation Add-In

    Microsoft Office InfoPath MUI (English) 2007

    Microsoft Office Outlook MUI (English) 2007

    Microsoft Office PowerPoint MUI (English) 2007

    Microsoft Office Professional Plus 2007

    Microsoft Office Proof (English) 2007

    Microsoft Office Proof (French) 2007

    Microsoft Office Proof (Spanish) 2007

    Microsoft Office Proofing (English) 2007

    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

    Microsoft Office Publisher MUI (English) 2007

    Microsoft Office Shared MUI (English) 2007

    Microsoft Office Shared Setup Metadata MUI (English) 2007

    Microsoft Office Word MUI (English) 2007

    Microsoft Silverlight

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

    Mozilla Firefox 23.0.1 (x86 en-US)

    Mozilla Maintenance Service

    MPC-HC 1.6.3.5818

    MSXML 4.0 SP2 (KB954430)

    MSXML 4.0 SP2 (KB973688)

    Music Manager

    NVIDIA 3D Vision Controller Driver 296.16

    NVIDIA 3D Vision Driver 311.06

    NVIDIA Control Panel 311.06

    NVIDIA Graphics Driver 311.06

    NVIDIA HD Audio Driver 1.3.12.0

    NVIDIA Install Application

    NVIDIA PhysX

    NVIDIA PhysX System Software 9.12.0213

    NVIDIA Stereoscopic 3D Driver

    NVIDIA Update 1.11.3

    NVIDIA Update Components

    Paragon Backup & Recovery™ 2013 Free

    Plex Media Server

    Portrait Professional Studio 10.8

    Portrait Professional Studio 11.1

    PRE11 STI Installer

    PS3 Media Server

    PSE11 STI Installer

    Realtek High Definition Audio Driver

    Revo Uninstaller 1.94

    Scan

    Screen Grab Pro

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)

    Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

    Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

    Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

    Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

    Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition

    Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition

    Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition

    Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition

    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition

    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition

    Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition

    Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition

    Sky Go Desktop

    SmartWebPrinting

    SolutionCenter

    Status

    Toolbox

    TrayApp

    TrueCrypt

    UnloadSupport

    Update for 2007 Microsoft Office System (KB967642)

    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

    Update for Microsoft .NET Framework 4 Client Profile (KB2836939)

    Update for Microsoft .NET Framework 4 Extended (KB2468871)

    Update for Microsoft .NET Framework 4 Extended (KB2533523)

    Update for Microsoft .NET Framework 4 Extended (KB2600217)

    Update for Microsoft .NET Framework 4 Extended (KB2836939)

    Update for Microsoft Office 2007 Help for Common Features (KB963673)

    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition

    Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition

    Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition

    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition

    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition

    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition

    Update for Microsoft Office Access 2007 Help (KB963663)

    Update for Microsoft Office Excel 2007 Help (KB963678)

    Update for Microsoft Office Infopath 2007 Help (KB963662)

    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition

    Update for Microsoft Office Outlook 2007 (KB2768023) 32-Bit Edition

    Update for Microsoft Office Outlook 2007 Help (KB963677)

    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817642) 32-Bit Edition

    Update for Microsoft Office Powerpoint 2007 Help (KB963669)

    Update for Microsoft Office Publisher 2007 Help (KB963667)

    Update for Microsoft Office Script Editor Help (KB963671)

    Update for Microsoft Office Word 2007 Help (KB963665)

    VLC media player 2.0.8

    WebReg

    Windows Driver Package - FTDI bluefin USB Driver (03/18/2011 2.08.14)

    Windows Driver Package - FTDI bluefin Virtual COM Port Driver (03/18/2011 2.08.14)

    WinX Blu-ray Decrypter 3.4.1

    WinX DVD Copy Pro 3.4.5

    WinX DVD Ripper Platinum 6.9.2

    WinX HD Video Converter Deluxe 3.12.2

    WinZip 17.0

    ZipGenius 6.3

    .

    ==== Event Viewer Messages From Past Week ========

    .

    08/09/2013 15:16:24, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

    08/09/2013 15:16:24, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.

    07/09/2013 02:56:57, Error: volsnap [35] - The shadow copies of volume E: were aborted because the shadow copy storage failed to grow.

    .

    ==== End Of File ===========================

  12. Hi

    ESET scan enclosed

    C:\Darren\Handicaps\sklogger.exe Win32/Spy.ActivityMonitor.D application

    D:\Windows Users\Darren\Downloads\cnet2_zipeg_win_exe.exe a variant of Win32/InstallCore.D application

    E:\Users\darren\Downloads\cbsidlm-tr1_7-Screen_Grab_Pro-ORG2-10068383.exe Win32/DownloadAdmin.D application

    E:\Users\darren\Downloads\cnet2_zipeg_win_exe.exe a variant of Win32/InstallCore.D application

    F:\old j drive\Handicaps\sklogger.exe Win32/Spy.ActivityMonitor.D application

  13. Hi apologies for the delay, not been at home to perform instructions.

    Now complete with logs below. The only issue was with running hijack this, got an error message, clicked ok and it just seemed to run anyway.

    mbam..

    Malwarebytes Anti-Malware (Trial) 1.65.1.1000

    www.malwarebytes.org

    Database version: v2012.11.19.09

    Windows 7 Service Pack 1 x86 NTFS

    Internet Explorer 9.0.8112.16421

    darren :: DARREN-PC [administrator]

    Protection: Enabled

    19/11/2012 22:21:59

    mbam-log-2012-11-19 (22-21-59).txt

    Scan type: Quick scan

    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

    Scan options disabled: P2P

    Objects scanned: 270264

    Time elapsed: 1 minute(s), 14 second(s)

    Memory Processes Detected: 0

    (No malicious items detected)

    Memory Modules Detected: 0

    (No malicious items detected)

    Registry Keys Detected: 0

    (No malicious items detected)

    Registry Values Detected: 0

    (No malicious items detected)

    Registry Data Items Detected: 0

    (No malicious items detected)

    Folders Detected: 0

    (No malicious items detected)

    Files Detected: 0

    (No malicious items detected)

    (end)

    hijack....

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:26:38, on 19/11/2012

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v9.00 (9.00.8112.16455)

    Boot mode: Normal

    Running processes:

    E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    E:\Windows\system32\Dwm.exe

    E:\Windows\Explorer.EXE

    E:\Windows\system32\taskhost.exe

    E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe

    E:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe

    E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

    E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

    E:\Program Files\Logitech\SetPointP\SetPoint.exe

    E:\Program Files\iTunes\iTunesHelper.exe

    E:\Program Files\Citrix\ICA Client\concentr.exe

    E:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

    E:\Program Files\Citrix\ICA Client\wfcrun32.exe

    C:\Program Files\HP\HP Software Update\hpwuschd2.exe

    E:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE

    E:\Program Files\Windows Sidebar\sidebar.exe

    E:\Program Files\Digiarty\Air_Playit\airplayit.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    E:\Program Files\NVIDIA Corporation\Display\nvtray.exe

    E:\Program Files\Digiarty\Air_Playit\AirPS.exe

    E:\Windows\system32\conhost.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

    E:\Windows\system32\taskeng.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

    E:\Program Files\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr32.exe

    E:\Program Files\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

    E:\Program Files\ASUS\AI Suite II\EPU\EPUHelp.exe

    E:\Program Files\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe

    E:\Program Files\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe

    E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

    E:\Windows\system32\NOTEPAD.EXE

    E:\Windows\system32\taskhost.exe

    E:\Windows\system32\taskeng.exe

    E:\Users\darren\Desktop\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll

    O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll

    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O4 - HKLM\..\Run: [RTHDVCPL] E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe -s

    O4 - HKLM\..\Run: [RtHDVBg_DTS] E:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe /DTSU2P

    O4 - HKLM\..\Run: [uSB3MON] "E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"

    O4 - HKLM\..\Run: [AVP] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"

    O4 - HKLM\..\Run: [igfxTray] E:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] E:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] E:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: [EvtMgr6] E:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming

    O4 - HKLM\..\Run: [APSDaemon] "E:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [ConnectionCenter] "E:\Program Files\Citrix\ICA Client\concentr.exe" /startup

    O4 - HKLM\..\Run: [CanonSolutionMenu] E:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon

    O4 - HKLM\..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon

    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "E:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKCU\..\Run: [sidebar] E:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKCU\..\Run: [Digiarty_Software_AirPlayit] "E:\Program Files\Digiarty\Air_Playit\airplayit.exe" -min

    O4 - HKUS\S-1-5-21-1921215017-14310540-2123050349-1005\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')

    O4 - HKUS\S-1-5-21-1921215017-14310540-2123050349-1005\..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (User 'UpdatusUser')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: Add to Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll

    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll

    O23 - Service: Adobe Active File Monitor V11 (AdobeActiveFileMonitor11.0) - Adobe Systems Incorporated - E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

    O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - E:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - E:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Apple Mobile Device - Apple Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe

    O23 - Service: ASUS HM Com Service (asHmComSvc) - ASUSTeK Computer Inc. - E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe

    O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe

    O23 - Service: AsusFanControlService - ASUSTeK Computer Inc. - E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe

    O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

    O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - E:\Windows\system32\IntelCpHeciSvc.exe

    O23 - Service: DTSAudioSvc - DTS, Inc - E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Intel® Integrated Clock Controller Service - Intel® ICCS (ICCS) - Intel Corporation - E:\Program Files\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe

    O23 - Service: Intel® PROSet Monitoring Service - Intel Corporation - E:\Windows\system32\IProsetMonitor.exe

    O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - E:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - E:\Windows\system32\nvvsvc.exe

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: Macrium Reflect Image Mounting Service (ReflectService.exe) - Unknown owner - E:\Program Files\Macrium\Reflect\ReflectService.exe

    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    --

    End of file - 12368 bytes

  14. apologies for delay, run and log attached

    ========== OTL ==========

    Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.

    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

    Registry key HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Internet Explorer\SearchScopes\{700F9637-8FFE-4759-ACDA-902AA7E96400}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{700F9637-8FFE-4759-ACDA-902AA7E96400}\ not found.

    Registry key HKEY_USERS\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E327A750-C3A9-4AEF-928A-2D1CAAA3AF34}\ deleted successfully.

    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E327A750-C3A9-4AEF-928A-2D1CAAA3AF34}\ not found.

    E:\Users\darren\AppData\Local\funmoods-speeddial_sf.crx moved successfully.

    ========== FILES ==========

    < ipconfig /flushdns /c >

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    E:\Users\darren\Desktop\cmd.bat deleted successfully.

    E:\Users\darren\Desktop\cmd.txt deleted successfully.

    ========== COMMANDS ==========

    [EMPTYJAVA]

    User: All Users

    User: darren

    ->Java cache emptied: 0 bytes

    User: Default

    User: Default User

    User: Henry

    ->Java cache emptied: 0 bytes

    User: Jo

    ->Java cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Java Files Cleaned = 0.00 mb

    [EMPTYFLASH]

    User: All Users

    User: darren

    ->Flash cache emptied: 57312 bytes

    User: Default

    ->Flash cache emptied: 56504 bytes

    User: Default User

    ->Flash cache emptied: 0 bytes

    User: Henry

    ->Flash cache emptied: 10775 bytes

    User: Jo

    ->Flash cache emptied: 4712 bytes

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb

    OTL by OldTimer - Version 3.2.69.0 log created on 11172012_155512

  15. otl logs...

    OTL logfile created on: 11/17/2012 3:05:32 PM - Run 1

    OTL by OldTimer - Version 3.2.69.0 Folder = E:\Users\darren\Desktop

    Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

    Internet Explorer (Version = 9.0.8112.16421)

    Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    3.47 Gb Total Physical Memory | 2.34 Gb Available Physical Memory | 67.45% Memory free

    6.94 Gb Paging File | 5.45 Gb Available in Paging File | 78.45% Paging File free

    Paging file location(s): d:\pagefile.sys 0 0 [binary data]

    %SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files

    Drive C: | 1863.01 Gb Total Space | 66.56 Gb Free Space | 3.57% Space Free | Partition Type: NTFS

    Drive D: | 1863.01 Gb Total Space | 76.86 Gb Free Space | 4.13% Space Free | Partition Type: NTFS

    Drive E: | 119.23 Gb Total Space | 36.08 Gb Free Space | 30.26% Space Free | Partition Type: NTFS

    Drive F: | 1397.26 Gb Total Space | 151.66 Gb Free Space | 10.85% Space Free | Partition Type: NTFS

    Drive H: | 1397.26 Gb Total Space | 282.42 Gb Free Space | 20.21% Space Free | Partition Type: NTFS

    Drive I: | 1863.01 Gb Total Space | 169.17 Gb Free Space | 9.08% Space Free | Partition Type: NTFS

    Drive J: | 1863.01 Gb Total Space | 774.13 Gb Free Space | 41.55% Space Free | Partition Type: NTFS

    Computer Name: DARREN-PC | User Name: darren | Logged in as Administrator.

    Boot Mode: Normal | Scan Mode: All users

    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - E:\Users\darren\Desktop\OTL.exe (OldTimer Tools)

    PRC - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)

    PRC - E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

    PRC - E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)

    PRC - E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)

    PRC - E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)

    PRC - E:\Windows\System32\conhost.exe (Microsoft Corporation)

    PRC - E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)

    PRC - E:\Program Files\Macrium\Reflect\ReflectService.exe ()

    PRC - E:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)

    PRC - E:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)

    PRC - E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)

    PRC - E:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)

    PRC - E:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)

    PRC - E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)

    PRC - E:\Program Files\Digiarty\Air_Playit\airplayit.exe ()

    PRC - E:\Program Files\Digiarty\Air_Playit\AirPS.exe (Digiarty, Inc.)

    PRC - E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe (Realtek Semiconductor)

    PRC - E:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Realtek Semiconductor)

    PRC - E:\Program Files\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe (DTS, Inc)

    PRC - E:\Program Files\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)

    PRC - E:\Program Files\ASUS\AI Suite II\EPU\EPUHelp.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr32.exe (ASUSTeK Computer Inc.)

    PRC - E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe ()

    PRC - E:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)

    PRC - E:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)

    PRC - E:\Program Files\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe (ASUSTeK Computer Inc.)

    PRC - E:\Windows\System32\IPROSetMonitor.exe (Intel Corporation)

    PRC - E:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)

    PRC - E:\Program Files\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)

    PRC - E:\Windows\explorer.exe (Microsoft Corporation)

    PRC - E:\Program Files\ASUS\AI Suite II\AsRoutineController.exe (ASUSTeK Computer Inc.)

    PRC - E:\Windows\System32\taskhost.exe (Microsoft Corporation)

    PRC - E:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)

    PRC - E:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)

    ========== Modules (No Company Name) ==========

    MOD - E:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()

    MOD - E:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()

    MOD - E:\Program Files\Digiarty\Air_Playit\airplayit.exe ()

    MOD - E:\Program Files\ASUS\AI Suite II\Network iControl\NetSvcHelp\gep.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Sensor\Sensor.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Probe_II\ProbeII.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Network iControl\Network iControl.dll ()

    MOD - E:\Program Files\Digiarty\Air_Playit\ServerAdmin.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Network iControl\NetSvcHelp\func.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\USB BIOS Flashback\PEInfo.dll ()

    MOD - E:\Program Files\Digiarty\Air_Playit\Config.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\MyLogo\MyLogo.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\TurboV EVO\HookKey32.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\TabGadget\TabGadget.dll ()

    MOD - E:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\AI Charger+\AIChargerPlus.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\BarGadget\BarGadget.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Settings\Settings.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\TurboV EVO\pngio.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Splitter\Splitter.dll ()

    MOD - E:\Program Files\Digiarty\Air_Playit\CI.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\AssistFunc.dll ()

    MOD - E:\Program Files\Digiarty\Air_Playit\sqlite3.dll ()

    MOD - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtgui4.dll ()

    MOD - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtsql4.dll ()

    MOD - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtscript4.dll ()

    MOD - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtnetwork4.dll ()

    MOD - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtcore4.dll ()

    MOD - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\qtdeclarative4.dll ()

    MOD - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\pngio.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Network iControl\NetSvcHelp\pngio.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\ImageHelper.dll ()

    MOD - E:\Program Files\ASUS\AAHM\1.00.20\aaHMLib.dll ()

    MOD - E:\Program Files\ASUS\AI Suite II\Sensor\AlertHelper\pngio.dll ()

    ========== Services (SafeList) ==========

    SRV - (MozillaMaintenance) -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)

    SRV - (AVP) -- E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)

    SRV - (AdobeFlashPlayerUpdateSvc) -- E:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)

    SRV - (MBAMService) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)

    SRV - (MBAMScheduler) -- E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)

    SRV - (AdobeActiveFileMonitor11.0) -- E:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)

    SRV - (AdobeARMservice) -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)

    SRV - (FLEXnet Licensing Service) -- E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)

    SRV - (WatAdminSvc) -- E:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)

    SRV - (ReflectService.exe) -- E:\Program Files\Macrium\Reflect\ReflectService.exe ()

    SRV - (nvUpdatusService) -- E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)

    SRV - (Stereo Service) -- E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)

    SRV - (cphs) -- E:\Windows\System32\IntelCpHeciSvc.exe (Intel Corporation)

    SRV - (AsusFanControlService) -- E:\Program Files\ASUS\AsusFanControlService\1.00.25\AsusFanControlService.exe (ASUSTeK Computer Inc.)

    SRV - (AsSysCtrlService) -- E:\Program Files\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.)

    SRV - (asHmComSvc) -- E:\Program Files\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.)

    SRV - (DTSAudioSvc) -- E:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe (DTS, Inc)

    SRV - (asComSvc) -- E:\Program Files\ASUS\AXSP\1.00.18\atkexComSvc.exe ()

    SRV - (LBTServ) -- E:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)

    SRV - (Intel® -- E:\Windows\System32\IPROSetMonitor.exe (Intel Corporation)

    SRV - (McComponentHostService) -- E:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe (McAfee, Inc.)

    SRV - (ICCS) -- E:\Program Files\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)

    SRV - (StorSvc) -- E:\Windows\System32\StorSvc.dll (Microsoft Corporation)

    SRV - (SensrSvc) -- E:\Windows\System32\sensrsvc.dll (Microsoft Corporation)

    SRV - (PeerDistSvc) -- E:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)

    SRV - (WinDefend) -- E:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

    SRV - (AdobeActiveFileMonitor7.0) -- E:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)

    ========== Driver Services (SafeList) ==========

    DRV - (catchme) -- E:\Users\darren\AppData\Local\Temp\catchme.sys File not found

    DRV - (ALSysIO) -- E:\Users\darren\AppData\Local\Temp\ALSysIO.sys File not found

    DRV - (KLIF) -- E:\Windows\System32\drivers\klif.sys (Kaspersky Lab)

    DRV - (MBAMProtector) -- E:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)

    DRV - (DigiartyVirtualCDBus) -- E:\Windows\System32\drivers\DigiartyVirtualCDBus.sys (Digiarty Software, Inc.)

    DRV - (truecrypt) -- E:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)

    DRV - (pssnap) -- E:\Windows\System32\drivers\pssnap.sys (Macrium Software)

    DRV - (nvlddmkm) -- E:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)

    DRV - (ctxusbm) -- E:\Windows\System32\drivers\ctxusbm.sys (Citrix Systems, Inc.)

    DRV - (asmtxhci) -- E:\Windows\System32\drivers\asmtxhci.sys (ASMedia Technology Inc)

    DRV - (asmthub3) -- E:\Windows\System32\drivers\asmthub3.sys (ASMedia Technology Inc)

    DRV - (NVHDA) -- E:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)

    DRV - (asahci32) -- E:\Windows\System32\drivers\asahci32.sys (Asmedia Technology)

    DRV - (iusb3xhc) -- E:\Windows\System32\drivers\iusb3xhc.sys (Intel Corporation)

    DRV - (iusb3hub) -- E:\Windows\System32\drivers\iusb3hub.sys (Intel Corporation)

    DRV - (iusb3hcs) -- E:\Windows\System32\drivers\iusb3hcs.sys (Intel Corporation)

    DRV - (MEI) -- E:\Windows\System32\drivers\HECI.sys (Intel Corporation)

    DRV - (ASUSFILTER) -- E:\Windows\System32\drivers\ASUSFILTER.sys (MCCI Corporation)

    DRV - (LMouFilt) -- E:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)

    DRV - (LHidFilt) -- E:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)

    DRV - (ndisrd) -- E:\Windows\System32\drivers\ndisrd.sys (NT Kernel Resources)

    DRV - (e1cexpress) -- E:\Windows\System32\drivers\e1c6232.sys (Intel Corporation)

    DRV - (KLIM6) -- E:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)

    DRV - (kl2) -- E:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)

    DRV - (KL1) -- E:\Windows\System32\drivers\kl1.sys (Kaspersky Lab ZAO)

    DRV - (vmbus) -- E:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)

    DRV - (storflt) -- E:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)

    DRV - (storvsc) -- E:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)

    DRV - (TsUsbFlt) -- E:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)

    DRV - (WinUsb) -- E:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)

    DRV - (VMBusHID) -- E:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)

    DRV - (s3cap) -- E:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)

    DRV - (AiCharger) -- E:\Windows\System32\drivers\AiCharger.sys (ASUSTek Computer Inc.)

    DRV - (AsIO) -- E:\Windows\System32\drivers\AsIO.sys ()

    DRV - (ICCWDT) -- E:\Windows\System32\drivers\ICCWDT.sys (Intel Corporation)

    DRV - (AsUpIO) -- E:\Windows\System32\drivers\AsUpIO.sys ()

    DRV - (klmouflt) -- E:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)

    DRV - (Serial) -- E:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)

    ========== Standard Registry (SafeList) ==========

    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

    IE - HKLM\..\SearchScopes,DefaultScope =

    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 21 1B C4 92 D0 66 CD 01 [binary data]

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes\{700F9637-8FFE-4759-ACDA-902AA7E96400}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_UK&apn_ptnrs=U3&apn_dtid=OSJ000YYGB&apn_uid=CC5C6200-CD42-424D-BB72-6AC5CA6A51AF&apn_sauid=F122E31C-AE4A-4E14-86F0-B8C33DBD31BE

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\..\SearchScopes\{E327A750-C3A9-4AEF-928A-2D1CAAA3AF34}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    IE - HKU\S-1-5-21-1921215017-14310540-2123050349-1005\..\SearchScopes,DefaultScope =

    ========== FireFox ==========

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()

    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found

    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()

    FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: E:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)

    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: E:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)

    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: E:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)

    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)

    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: E:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: E:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)

    FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Users\darren\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)

    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Users\darren\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru [2012/10/24 19:30:02 | 000,000,000 | ---D | M]

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru [2012/10/24 19:30:02 | 000,000,000 | ---D | M]

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\KavAntiBanner@Kaspersky.ru: E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru [2012/10/24 19:30:02 | 000,000,000 | ---D | M]

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/21 19:44:00 | 000,000,000 | ---D | M]

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2012/10/31 14:09:02 | 000,000,000 | ---D | M]

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2012/10/31 14:09:01 | 000,000,000 | ---D | M]

    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/08/21 19:44:00 | 000,000,000 | ---D | M]

    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2012/10/31 14:09:02 | 000,000,000 | ---D | M]

    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2012/10/31 14:09:01 | 000,000,000 | ---D | M]

    [2012/08/23 20:13:10 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Extensions

    [2012/11/05 22:52:52 | 000,000,000 | ---D | M] (No name found) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions

    [2012/10/02 19:56:49 | 000,000,000 | ---D | M] (WOT) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}

    [2012/11/05 22:52:52 | 000,000,000 | ---D | M] (DownloadHelper) -- E:\Users\darren\AppData\Roaming\Mozilla\Profiles\1hw3rn2c.master\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

    [2012/10/31 14:09:00 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions

    [2012/10/31 14:09:02 | 000,261,600 | ---- | M] (Mozilla Foundation) -- E:\Program Files\mozilla firefox\components\browsercomps.dll

    [2012/03/28 01:04:52 | 000,124,864 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\CCMSDK.dll

    [2012/03/28 01:06:54 | 000,071,104 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\CgpCore.dll

    [2012/03/28 01:05:52 | 000,092,096 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\confmgr.dll

    [2012/03/28 01:05:28 | 000,022,976 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\ctxlogging.dll

    [2012/03/28 01:48:16 | 000,489,384 | ---- | M] () -- E:\Program Files\mozilla firefox\plugins\npicaN.dll

    [2012/03/28 01:06:48 | 000,024,512 | ---- | M] (Citrix Systems, Inc.) -- E:\Program Files\mozilla firefox\plugins\TcpPServ.dll

    [2012/09/12 20:34:58 | 000,002,465 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\bing.xml

    [2012/10/31 14:09:01 | 000,002,058 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\twitter.xml

    O1 HOSTS File: ([2009/06/10 21:39:37 | 000,000,824 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts

    O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)

    O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)

    O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)

    O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)

    O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)

    O4 - HKLM..\Run: [APSDaemon] E:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

    O4 - HKLM..\Run: [AVP] E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe (Kaspersky Lab ZAO)

    O4 - HKLM..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)

    O4 - HKLM..\Run: [CanonSolutionMenu] E:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)

    O4 - HKLM..\Run: [ConnectionCenter] E:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)

    O4 - HKLM..\Run: [EvtMgr6] E:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)

    O4 - HKLM..\Run: [RtHDVBg_DTS] E:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Realtek Semiconductor)

    O4 - HKLM..\Run: [RTHDVCPL] E:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe (Realtek Semiconductor)

    O4 - HKLM..\Run: [uSB3MON] E:\Program Files\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)

    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000..\Run: [Digiarty_Software_AirPlayit] E:\Program Files\Digiarty\Air_Playit\airplayit.exe ()

    O4 - HKU\S-1-5-21-1921215017-14310540-2123050349-1005..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)

    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present

    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

    O7 - HKU\S-1-5-21-1921215017-14310540-2123050349-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O8 - Extra context menu item: Add to Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm ()

    O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll (Kaspersky Lab ZAO)

    O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll (Kaspersky Lab ZAO)

    O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E61F5A10-0F68-4278-A870-B674D08ED3BF}: DhcpNameServer = 194.168.4.100 194.168.8.100

    O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - E:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)

    O20 - HKLM Winlogon: Shell - (Explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)

    O20 - HKLM Winlogon: UserInit - (E:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation)

    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)

    O20 - Winlogon\Notify\klogon: DllName - (E:\Windows\system32\klogon.dll) - E:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)

    O20 - Winlogon\Notify\LBTWlgn: DllName - (e:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - e:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)

    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

    O32 - HKLM CDRom: AutoRun - 1

    O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ]

    O34 - HKLM BootExecute: (autocheck autochk *)

    O35 - HKLM\..comfile [open] -- "%1" %*

    O35 - HKLM\..exefile [open] -- "%1" %*

    O37 - HKLM\...com [@ = ComFile] -- "%1" %*

    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/11/17 15:03:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL.exe

    [2012/11/17 14:29:10 | 000,000,000 | -HSD | C] -- E:\$RECYCLE.BIN

    [2012/11/17 13:52:41 | 000,000,000 | ---D | C] -- E:\Users\darren\Desktop\RK_Quarantine

    [2012/11/17 13:14:46 | 000,000,000 | ---D | C] -- E:\Windows\temp

    [2012/11/17 13:08:54 | 000,518,144 | ---- | C] (SteelWerX) -- E:\Windows\SWREG.exe

    [2012/11/17 13:08:54 | 000,406,528 | ---- | C] (SteelWerX) -- E:\Windows\SWSC.exe

    [2012/11/17 13:08:54 | 000,060,416 | ---- | C] (NirSoft) -- E:\Windows\NIRCMD.exe

    [2012/11/17 13:08:51 | 000,000,000 | ---D | C] -- E:\Qoobox

    [2012/11/17 13:08:45 | 000,000,000 | ---D | C] -- E:\Windows\erdnt

    [2012/11/17 13:01:17 | 005,002,404 | R--- | C] (Swearware) -- E:\Users\darren\Desktop\ComboFix.exe

    [2012/11/16 03:01:19 | 000,047,720 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\WdfLdr.sys

    [2012/11/16 03:01:19 | 000,009,728 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\Wdfres.dll

    [2012/11/16 03:01:07 | 000,172,032 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\WUDFPlatform.dll

    [2012/11/16 03:01:06 | 000,613,888 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\WUDFx.dll

    [2012/11/16 03:01:06 | 000,038,912 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\WUDFCoinstaller.dll

    [2012/11/16 03:00:58 | 002,382,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb

    [2012/11/16 03:00:58 | 000,176,640 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll

    [2012/11/16 03:00:58 | 000,142,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieUnatt.exe

    [2012/11/16 03:00:58 | 000,065,024 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll

    [2012/11/16 03:00:57 | 001,800,704 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll

    [2012/11/16 03:00:57 | 001,427,968 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\inetcpl.cpl

    [2012/11/16 03:00:57 | 000,607,744 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeeds.dll

    [2012/11/16 03:00:57 | 000,231,936 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\url.dll

    [2012/11/15 03:17:31 | 000,156,672 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ncsi.dll

    [2012/11/15 03:17:30 | 000,175,104 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\netcorehc.dll

    [2012/11/15 03:17:30 | 000,018,944 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\netevent.dll

    [2012/11/15 03:17:29 | 002,345,984 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys

    [2012/11/15 03:17:29 | 000,193,536 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\dhcpcore6.dll

    [2012/11/15 03:17:29 | 000,078,336 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\synceng.dll

    [2012/11/15 03:17:29 | 000,044,032 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\dhcpcsvc6.dll

    [2012/11/14 20:48:34 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager

    [2012/11/14 20:48:28 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Local\Programs

    [2012/11/13 22:45:40 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Traction Software

    [2012/11/13 22:45:40 | 000,000,000 | ---D | C] -- E:\Program Files\Traction Software

    [2012/11/13 22:45:06 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Local\Google

    [2012/11/12 22:39:19 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Roaming\CANON INC

    [2012/11/12 21:21:16 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Roaming\canon

    [2012/11/10 13:12:44 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Roaming\Malwarebytes

    [2012/11/10 13:12:41 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- E:\Windows\System32\drivers\mbam.sys

    [2012/11/10 13:12:41 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

    [2012/11/10 13:12:41 | 000,000,000 | ---D | C] -- E:\Program Files\Malwarebytes' Anti-Malware

    [2012/11/10 13:12:41 | 000,000,000 | ---D | C] -- E:\ProgramData\Malwarebytes

    [2012/11/10 13:02:48 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Local\LogMeIn Rescue Applet

    [2012/10/31 14:09:00 | 000,000,000 | ---D | C] -- E:\Program Files\Mozilla Firefox

    [2012/10/30 23:08:36 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Roaming\Canon_Inc_IC

    [2012/10/30 23:05:57 | 000,000,000 | ---D | C] -- E:\Program Files\Common Files\Canon_Inc_IC

    [2012/10/30 23:04:38 | 000,000,000 | ---D | C] -- E:\ProgramData\Canon_Inc_IC

    [2012/10/28 20:48:47 | 000,000,000 | ---D | C] -- E:\ProgramData\regid.1986-12.com.adobe

    [2012/10/24 22:33:19 | 000,000,000 | ---D | C] -- E:\Program Files\Common Files\PX Storage Engine

    [2012/10/24 22:16:30 | 000,000,000 | ---D | C] -- E:\Users\darren\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant

    [2012/10/24 22:16:23 | 000,000,000 | ---D | C] -- E:\Users\darren\Desktop\Adobe

    [2012/10/24 22:16:21 | 000,000,000 | ---D | C] -- E:\Program Files\Adobe Download Assistant

    [2012/10/24 22:16:20 | 000,000,000 | ---D | C] -- E:\Program Files\Common Files\Adobe AIR

    ========== Files - Modified Within 30 Days ==========

    [2012/11/17 15:03:44 | 000,013,456 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

    [2012/11/17 15:03:44 | 000,013,456 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

    [2012/11/17 15:01:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Users\darren\Desktop\OTL.exe

    [2012/11/17 14:57:36 | 001,048,576 | ---- | M] () -- E:\Windows\PE_Rom.dll

    [2012/11/17 14:56:39 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat

    [2012/11/17 14:56:38 | 2795,933,696 | -HS- | M] () -- E:\hiberfil.sys

    [2012/11/17 14:49:55 | 001,582,562 | ---- | M] () -- E:\Windows\System32\perfh009.dat

    [2012/11/17 14:49:55 | 000,668,552 | ---- | M] () -- E:\Windows\System32\perfc009.dat

    [2012/11/17 14:13:00 | 000,000,830 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job

    [2012/11/17 13:53:00 | 000,000,912 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000UA.job

    [2012/11/17 13:01:10 | 005,002,404 | R--- | M] (Swearware) -- E:\Users\darren\Desktop\ComboFix.exe

    [2012/11/17 12:02:12 | 000,725,504 | ---- | M] () -- E:\Users\darren\Desktop\RogueKiller.exe

    [2012/11/17 12:00:40 | 000,541,569 | ---- | M] () -- E:\Users\darren\Desktop\adwcleaner.exe

    [2012/11/17 12:00:16 | 000,881,833 | ---- | M] () -- E:\Users\darren\Desktop\SecurityCheck.exe

    [2012/11/16 20:53:00 | 000,000,860 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000Core.job

    [2012/11/16 18:31:22 | 000,001,140 | ---- | M] () -- E:\Users\darren\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk

    [2012/11/16 03:22:14 | 001,695,328 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT

    [2012/11/13 22:45:40 | 000,001,255 | ---- | M] () -- E:\Users\Public\Desktop\Screen Grab Pro.lnk

    [2012/11/13 22:45:00 | 000,290,500 | ---- | M] () -- E:\Users\darren\AppData\Local\funmoods-speeddial_sf.crx

    [2012/11/10 13:12:41 | 000,001,104 | ---- | M] () -- E:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

    [2012/10/31 00:09:03 | 000,001,138 | ---- | M] () -- E:\Windows\MB.idx

    [2012/10/31 00:08:20 | 000,000,551 | ---- | M] () -- E:\Windows\Path.idx

    [2012/10/30 23:07:05 | 000,001,187 | ---- | M] () -- E:\Users\Public\Desktop\ImageBrowser EX.lnk

    [2012/10/30 23:06:54 | 000,001,192 | ---- | M] () -- E:\Users\Public\Desktop\Picture Style Editor.lnk

    [2012/10/30 23:06:40 | 000,001,074 | ---- | M] () -- E:\Users\Public\Desktop\EOS Utility.lnk

    [2012/10/30 23:06:23 | 000,001,139 | ---- | M] () -- E:\Users\Public\Desktop\Digital Photo Professional.lnk

    [2012/10/24 22:33:26 | 000,001,866 | ---- | M] () -- E:\Users\Public\Desktop\Adobe Photoshop Elements 11.lnk

    [2012/10/24 22:18:58 | 000,002,092 | ---- | M] () -- E:\Users\Public\Desktop\Lightroom 4.2.lnk

    [2012/10/24 22:16:21 | 000,001,038 | ---- | M] () -- E:\Users\Public\Desktop\Adobe Download Assistant.lnk

    [2012/10/24 21:28:58 | 000,000,009 | ---- | M] () -- E:\END

    [2012/10/24 21:27:59 | 000,001,831 | ---- | M] () -- E:\Users\Public\Desktop\Vuze.lnk

    [2012/10/24 21:27:59 | 000,001,831 | ---- | M] () -- E:\Users\darren\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk

    [2012/10/24 19:30:01 | 000,586,072 | ---- | M] (Kaspersky Lab) -- E:\Windows\System32\drivers\klif.sys

    [2012/10/18 17:59:05 | 002,345,984 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys

    ========== Files Created - No Company Name ==========

    [2012/11/17 13:08:54 | 000,256,000 | ---- | C] () -- E:\Windows\PEV.exe

    [2012/11/17 13:08:54 | 000,208,896 | ---- | C] () -- E:\Windows\MBR.exe

    [2012/11/17 13:08:54 | 000,098,816 | ---- | C] () -- E:\Windows\sed.exe

    [2012/11/17 13:08:54 | 000,080,412 | ---- | C] () -- E:\Windows\grep.exe

    [2012/11/17 13:08:54 | 000,068,096 | ---- | C] () -- E:\Windows\zip.exe

    [2012/11/17 12:03:00 | 000,725,504 | ---- | C] () -- E:\Users\darren\Desktop\RogueKiller.exe

    [2012/11/17 12:02:42 | 000,881,833 | ---- | C] () -- E:\Users\darren\Desktop\SecurityCheck.exe

    [2012/11/17 12:02:33 | 000,541,569 | ---- | C] () -- E:\Users\darren\Desktop\adwcleaner.exe

    [2012/11/16 03:01:20 | 000,000,003 | ---- | C] () -- E:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf

    [2012/11/16 03:01:06 | 000,000,003 | ---- | C] () -- E:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf

    [2012/11/14 20:48:21 | 000,000,912 | ---- | C] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000UA.job

    [2012/11/14 20:48:21 | 000,000,860 | ---- | C] () -- E:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1921215017-14310540-2123050349-1000Core.job

    [2012/11/13 22:45:40 | 000,001,255 | ---- | C] () -- E:\Users\Public\Desktop\Screen Grab Pro.lnk

    [2012/11/13 22:45:07 | 000,290,500 | ---- | C] () -- E:\Users\darren\AppData\Local\funmoods-speeddial_sf.crx

    [2012/11/10 13:12:41 | 000,001,104 | ---- | C] () -- E:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

    [2012/10/30 23:07:05 | 000,001,187 | ---- | C] () -- E:\Users\Public\Desktop\ImageBrowser EX.lnk

    [2012/10/30 23:06:54 | 000,001,192 | ---- | C] () -- E:\Users\Public\Desktop\Picture Style Editor.lnk

    [2012/10/30 23:06:40 | 000,001,074 | ---- | C] () -- E:\Users\Public\Desktop\EOS Utility.lnk

    [2012/10/30 23:06:23 | 000,001,139 | ---- | C] () -- E:\Users\Public\Desktop\Digital Photo Professional.lnk

    [2012/10/24 22:33:26 | 000,001,882 | ---- | C] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 11.lnk

    [2012/10/24 22:33:26 | 000,001,866 | ---- | C] () -- E:\Users\Public\Desktop\Adobe Photoshop Elements 11.lnk

    [2012/10/24 22:18:58 | 000,002,104 | ---- | C] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4.2.lnk

    [2012/10/24 22:18:58 | 000,002,092 | ---- | C] () -- E:\Users\Public\Desktop\Lightroom 4.2.lnk

    [2012/10/24 22:16:21 | 000,001,050 | ---- | C] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk

    [2012/10/24 22:16:21 | 000,001,038 | ---- | C] () -- E:\Users\Public\Desktop\Adobe Download Assistant.lnk

    [2012/09/12 21:58:37 | 005,221,448 | ---- | C] () -- E:\Windows\System32\SpoonUninstall.exe

    [2012/08/21 19:41:25 | 000,164,567 | ---- | C] () -- E:\Windows\hpoins27.dat

    [2012/08/21 19:41:25 | 000,000,442 | ---- | C] () -- E:\Windows\hpomdl27.dat

    [2012/08/19 13:49:03 | 002,533,047 | ---- | C] () -- E:\Windows\System32\nvcoproc.bin

    [2012/08/02 22:47:39 | 001,048,576 | ---- | C] () -- E:\Windows\PE_Rom.dll

    [2012/08/02 21:22:00 | 000,056,140 | ---- | C] () -- E:\Windows\Ascd_log.ini

    [2012/08/02 21:21:27 | 000,011,456 | R--- | C] () -- E:\Windows\System32\drivers\AsIO.sys

    [2012/08/02 21:21:25 | 000,011,832 | ---- | C] () -- E:\Windows\System32\drivers\AsInsHelp64.sys

    [2012/07/21 21:32:35 | 000,066,048 | ---- | C] () -- E:\Windows\System32\PrintBrmUi.exe

    [2012/07/21 12:48:54 | 000,017,408 | ---- | C] () -- E:\Users\darren\AppData\Local\WebpageIcons.db

    [2012/07/21 12:48:33 | 000,116,189 | ---- | C] () -- E:\Windows\System32\drivers\klin.dat

    [2012/07/21 12:48:33 | 000,098,168 | ---- | C] () -- E:\Windows\System32\drivers\klick.dat

    [2012/07/20 23:29:42 | 000,001,332 | R--- | C] () -- E:\Windows\System32\drivers\DTSU2P.DAT

    [2012/07/20 23:29:33 | 000,238,448 | ---- | C] () -- E:\Windows\System32\drivers\RTAIODAT.DAT

    [2012/07/20 23:27:24 | 000,001,769 | ---- | C] () -- E:\Windows\Language_trs.ini

    [2012/07/20 23:27:12 | 000,041,993 | ---- | C] () -- E:\Windows\Ascd_tmp.ini

    [2012/03/25 15:35:06 | 000,417,600 | ---- | C] () -- E:\Windows\System32\nvStreaming.exe

    [2012/03/19 23:37:12 | 000,755,188 | ---- | C] () -- E:\Windows\System32\igkrng700.bin

    [2012/03/19 23:37:12 | 000,561,508 | ---- | C] () -- E:\Windows\System32\igfcg700m.bin

    [2012/03/19 23:25:58 | 000,058,880 | ---- | C] () -- E:\Windows\System32\igdde32.dll

    [2012/03/19 22:23:38 | 013,024,256 | ---- | C] () -- E:\Windows\System32\ig7icd32.dll

    [2012/03/19 22:11:22 | 000,009,216 | ---- | C] ( ) -- E:\Windows\System32\IGFXDEVLib.dll

    [2012/03/19 22:09:28 | 000,000,264 | ---- | C] () -- E:\Windows\System32\GfxUI.exe.config

    [2012/03/19 22:09:08 | 000,094,208 | ---- | C] () -- E:\Windows\System32\IccLibDll.dll

    [2011/03/11 12:43:54 | 000,029,763 | ---- | C] () -- E:\Windows\System32\drivers\klopp.dat

    ========== ZeroAccess Check ==========

    [2009/07/14 04:42:31 | 000,000,227 | RHS- | M] () -- E:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 04:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 12:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 01:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)

    "ThreadingModel" = Both

    < End of report >

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.