Jump to content

Internet + Cloud Care issue (3rd party firewall/internet conection lost)


Recommended Posts

Ok, from now on I'm comming here first:

I'm using Cloud Care as a anti-virus/internet filtering program

This issue started a couple days ago, first problem being that Cloud Care complained that it's services weren't running, effectively disabling the internet. I tried restarting, which got rid of that issue for a little while, but every few times I would try to load a page it would try to load for about 10 to 15 seconds and then come up with a Cloud Care error stating that the page was blocked because of a third party firewall or a lost internet connection. It is not the internet connection, because sometimes I can refresh the page and it will load instantly. Also, a few other programs have been acting oddly, locking up at weird times. I said I would come here first because after trying Malwarebytes I also tried several other programs on my own, and I don't have enough experience to solve these kinds of problems on my own, so I'll come here first if anything like this happens again. One more thing you might want to know, although it is likely completely irrelevant, is that I have been messing around with SDL_net, I tried downloading the newest version, but it didn't work. I searched around and found a lower version which did work, although some of the files are newer than the newest version...

Thanks for any help,

QubicComputers

Here are the DDS files:

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1

Run by Shawn at 15:23:58 on 2013-02-02

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8175.5979 [GMT -8:00]

.

AV: CloudCare *Disabled/Updated* {BABEE769-087B-572E-AD62-21FF46C86F61}

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

SP: CloudCare AntiSpyware *Disabled/Updated* {01DF068D-2E41-58A0-97D2-1A8D3D4F25DC}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files\IDT\WDM\STacSV64.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\Windows\system32\atieclxx.exe

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files\IDT\WDM\AESTSr64.exe

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Bsecure\InetCtrl.exe

C:\Program Files (x86)\Bsecure\BsecAV.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe

C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe

C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe

C:\Program Files (x86)\PDF Complete\pdfsvc.exe

C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

C:\Program Files\Macrium\Reflect\ReflectService.exe

C:\Program Files (x86)\Photodex\ProShow\ScsiAccess.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe

C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe

C:\Windows\system32\taskhost.exe

C:\Program Files (x86)\Bsecure\BSecAMX.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Windows\SysWOW64\vmnat.exe

C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe

C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe

C:\Windows\system32\Dwm.exe

C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe

C:\Windows\Explorer.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe

C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe

C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Program Files\IDT\WDM\sttray64.exe

C:\Program Files (x86)\Steam\Steam.exe

C:\Windows\SysWOW64\vmnetdhcp.exe

C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\Bsecure\BsecTray.exe

C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe

C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Windows\System32\svchost.exe -k secsvcs

C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Windows\System32\WUDFHost.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

uInternet Settings,ProxyOverride = *.local;192.168.*.*

mSearchAssistant = hxxp://start.facemoods.com/?a=fmtgl&s={searchTerms}&f=4

mWinlogon: Userinit=userinit.exe,

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll

TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll

TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

uRun: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent

mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe

mRun: [CloudCare] C:\Program Files (x86)\Bsecure\BsecTray.exe

mRun: [iJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

mRun: [sDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"

StartupFolder: C:\Users\SHAWN~1.MIC\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\EGGTIM~1.LNK - C:\Program Files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe

StartupFolder: C:\Users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\note.txt

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll

LSP: %ProgramFiles%\Bsecure\InetCtrl57.dll

LSP: %SystemRoot%\system32\vsocklib.dll

DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

TCP: DhcpNameServer = 192.168.0.1 205.171.3.25

TCP: Interfaces\{A35758A6-7465-4C0F-997C-3651CED8C8D2} : DhcpNameServer = 192.168.0.1 205.171.3.25

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

Notify: SDWinLogon - SDWinLogon.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll

BHO-X64: Canon Easy-WebPrint EX BHO - No File

BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll

BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll

TB-X64: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll

TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File

TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

mRun-x64: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

mRun-x64: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe

mRun-x64: [CloudCare] C:\Program Files (x86)\Bsecure\BsecTray.exe

mRun-x64: [iJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe

mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

mRun-x64: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun-x64: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

mRun-x64: [sDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

Hosts: 127.0.0.1 www.spywareinfo.com

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Shawn.Michael-HP\AppData\Roaming\Mozilla\Firefox\Profiles\dbh3faig.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll

FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\nphdplg.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll

.

============= SERVICES / DRIVERS ===============

.

R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]

R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]

R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-1-5 89600]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]

R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]

R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]

R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-1-28 44808]

R2 Bsecure;CloudCare;C:\Program Files (x86)\Bsecure\InetCtrl.exe [2011-8-13 66344]

R2 BsecureAV;CloudCare AntiVirus;C:\Program Files (x86)\Bsecure\BsecAV.exe [2011-8-13 161776]

R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]

R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]

R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]

R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-1-29 398184]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-1-29 682344]

R2 Motorola Device Manager;Motorola Device Manager Service;C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-7-17 116632]

R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-1-5 1119768]

R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]

R2 ReflectService.exe;Macrium Reflect Image Mounting Service;C:\Program Files\Macrium\Reflect\ReflectService.exe [2011-11-9 301720]

R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-2-2 1103392]

R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-2-2 1369624]

R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-2-2 168384]

R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]

R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-1-5 2655768]

R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-29 846448]

R2 vmware-converter-agent;VMware vCenter Converter Standalone Agent;C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe [2011-8-19 423536]

R2 vmware-converter-server;VMware vCenter Converter Standalone Server;C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-8-19 423536]

R2 vmware-converter-worker;VMware vCenter Converter Standalone Worker;C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-8-19 423536]

R3 BSecACFltr;BSecACFltr;C:\Windows\System32\drivers\BSecACFltr.sys [2013-2-1 21624]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 MEIx64;Intel® Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]

R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]

R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]

R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]

R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]

R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]

R3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]

R3 WSDScan;WSD Scan Support via UMB;C:\Windows\system32\DRIVERS\WSDScan.sys --> C:\Windows\system32\DRIVERS\WSDScan.sys [?]

S2 CLKMSVC10_C6F09094;CyberLink Product - 2011/01/05 19:22:36;C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [2011-1-5 245232]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-6 136176]

S2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-2-21 1258856]

S2 VMwareHostd;VMware Workstation Server;C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-1-18 11839488]

S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]

S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]

S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]

S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-6 136176]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-9-20 30785672]

S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\system32\DRIVERS\motccgp.sys --> C:\Windows\system32\DRIVERS\motccgp.sys [?]

S3 motccgpfl;MotCcgpFlService;C:\Windows\system32\DRIVERS\motccgpfl.sys --> C:\Windows\system32\DRIVERS\motccgpfl.sys [?]

S3 motport;Motorola USB Diagnostic Port;C:\Windows\system32\DRIVERS\motport.sys --> C:\Windows\system32\DRIVERS\motport.sys [?]

S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S3 prwntdrv;prwntdrv;C:\Windows\System32\prwntdrv.sys [2012-10-14 13704]

S3 pwdrvio;pwdrvio;\??\C:\Windows\system32\pwdrvio.sys --> C:\Windows\system32\pwdrvio.sys [?]

S3 pwdspio;pwdspio;\??\C:\Windows\system32\pwdspio.sys --> C:\Windows\system32\pwdspio.sys [?]

S3 SIVDRIVER;SIV Kernel Driver;\??\C:\Windows\system32\Drivers\SIVX64.sys --> C:\Windows\system32\Drivers\SIVX64.sys [?]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 USBTINSP;TI-Nspire™ Handheld or TI Network Bridge Device Driver;C:\Windows\system32\DRIVERS\tinspusb.sys --> C:\Windows\system32\DRIVERS\tinspusb.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

S4 PST Service;PST Service;C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2012-11-2 65657]

.

=============== Created Last 30 ================

.

2074-05-19 00:44:52 607296 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires III Ancient\deformerdllyD.dll

2040-08-24 20:34:18 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-02 19:10:25 17272 ----a-w- C:\Windows\System32\sdnclean64.exe

2013-02-02 19:10:21 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2

2013-02-02 01:53:30 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy

2013-02-01 20:05:27 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Microsoft Shared

2013-02-01 20:05:26 58432 ----a-w- C:\Windows\System32\drivers\BsecFltr.sys

2013-02-01 20:05:26 49088 ----a-w- C:\Windows\SysWow64\drivers\BsecFltr.sys

2013-02-01 20:05:26 22832 ----a-w- C:\Windows\System32\drivers\BSecACFltr.sys

2013-02-01 20:05:26 21624 ----a-w- C:\Windows\SysWow64\drivers\BSecACFltr.sys

2013-02-01 19:56:34 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-02-01 14:15:44 9161176 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4C93BF7D-D194-42F6-B0EE-52A28CE1CAAF}\mpengine.dll

2013-01-31 04:28:57 -------- d-----w- C:\Users\Shawn.Michael-HP\HG

2013-01-31 04:21:22 -------- d-----w- C:\Program Files (x86)\Mercurial

2013-01-29 23:36:50 -------- d-----w- C:\Program Files (x86)\Royal Defense

2013-01-29 20:43:58 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Local\Programs

2013-01-29 20:38:09 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 20:38:04 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-01-29 20:38:04 -------- d-----w- C:\ProgramData\Malwarebytes

2013-01-29 20:38:04 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-01-29 01:49:43 984144 ----a-w- C:\Windows\System32\drivers\aswSnx.sys

2013-01-29 01:49:43 54072 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys

2013-01-29 01:49:42 71600 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys

2013-01-29 01:49:13 41224 ----a-w- C:\Windows\avastSS.scr

2013-01-29 01:49:06 -------- d-----w- C:\ProgramData\AVAST Software

2013-01-29 01:49:06 -------- d-----w- C:\Program Files\AVAST Software

2013-01-28 04:33:52 0 ----a-w- C:\Windows\SysWow64\sho50B7.tmp

2013-01-27 23:39:34 -------- d-----w- C:\Program Files (x86)\Narbacular Drop

2013-01-19 20:25:15 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Local\{A8CD06DA-879C-43D3-91C9-0AA78E6A65E3}

2013-01-18 14:25:58 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-01-15 23:25:39 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Local\{14CC761C-ECD5-4CEB-AF27-82BCB59EE592}

2013-01-15 14:29:46 -------- d-----w- C:\Include

2013-01-15 14:24:52 -------- d-----w- C:\Users\Shawn.Michael-HP\Tutorial Projects

2013-01-15 14:21:36 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-01-15 14:20:57 -------- d-----w- C:\Program Files (x86)\CodeBlocks

2013-01-09 23:39:00 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-09 15:07:52 68608 ----a-w- C:\Windows\System32\taskhost.exe

2013-01-09 15:07:52 3149824 ----a-w- C:\Windows\System32\win32k.sys

2013-01-06 03:09:36 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans

.

==================== Find3M ====================

.

2013-01-17 09:28:58 273840 ------w- C:\Windows\System32\MpSigStub.exe

2013-01-12 15:34:18 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-12 15:34:18 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-12-19 21:33:10 859072 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2012-12-19 21:33:10 779704 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2012-12-16 17:11:22 46080 ----a-w- C:\Windows\System32\atmlib.dll

2012-12-16 14:45:03 367616 ----a-w- C:\Windows\System32\atmfd.dll

2012-12-16 14:13:28 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll

2012-12-16 14:13:20 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll

2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll

2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll

2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll

2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs

2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs

2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs

2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs

2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs

2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs

2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs

2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs

2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs

2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs

2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs

2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs

2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs

2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs

2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll

2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll

2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll

2012-11-30 05:45:14 215040 ----a-w- C:\Windows\System32\winsrv.dll

2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll

2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll

2012-11-30 04:54:00 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll

2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe

2012-11-30 02:44:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

2012-11-30 02:44:04 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

2012-11-30 02:44:04 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

2012-11-30 02:44:03 2048 ----a-w- C:\Windows\SysWow64\user.exe

2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll

2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll

2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll

2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll

2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll

2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll

2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll

2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2012-11-14 05:52:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll

2012-11-14 01:44:42 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2012-11-09 05:45:32 750592 ----a-w- C:\Windows\System32\win32spl.dll

2012-11-09 05:45:09 2048 ----a-w- C:\Windows\System32\tzres.dll

2012-11-09 04:43:04 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll

2012-11-09 04:42:49 2048 ----a-w- C:\Windows\SysWow64\tzres.dll

2012-11-08 19:29:12 1402312 ----a-w- C:\Windows\SysWow64\msxml4.dll

.

============= FINISH: 15:25:01.72 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 8/13/2011 2:31:01 AM

System Uptime: 2/2/2013 2:54:31 PM (1 hours ago)

.

Motherboard: PEGATRON CORPORATION | | 2AB6

Processor: Intel® Core™ i5-2400 CPU @ 3.10GHz | CPU 1 | 3101/100mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 1850 GiB total, 1275.844 GiB free.

D: is FIXED (NTFS) - 13 GiB total, 1.593 GiB free.

E: is CDROM (CDFS)

H: is Removable

I: is Removable

J: is Removable

K: is Removable

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP299: 2/2/2013 2:50:42 PM - S

.

==== Installed Programs ======================

.

.

"Minimal SYStem 1.0.11"

0xCELERATOR version 1.0

Abyss

Active@ Partition Recovery

Adobe AIR

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Reader X (10.1.5)

Adobe Shockwave Player 11.6

Agatha Christie - Peril at End House

Age of Empires III

Age of Empires III - The Asian Dynasties

Age of Empires III - The WarChiefs

Alice Greenfingers 1.06

Ancient Rome

Android SDK Tools

AnswerWorks 5.0 English Runtime

Aphotic Ascent

Apple Application Support

Apple Software Update

Atheros Client Installation Program

Attack of the 50ft Robot!

Audiokinetic Wwise v2011.2.2 build 4007

avast! Free Antivirus

Base Invaders Version 1.3

Bejeweled 2 Deluxe

Big Fish Games: Game Manager

Blackhawk Striker 2

Blank

Blasterball 3

Bontago

Bossinabox 1.0

Bounce Symphony

Build-a-lot 2

Cake Mania

Canon Easy-WebPrint EX

Canon G.726 WMP-Decoder

Canon IJ Network Scan Utility

Canon IJ Network Tool

Canon Inkjet Printer/Scanner/Fax Extended Survey Program

Canon MovieEdit Task for ZoomBrowser EX

Canon MP Navigator EX 3.0

Canon MP560 series User Registration

Canon RAW Image Task for ZoomBrowser EX

Canon Utilities CameraWindow

Canon Utilities CameraWindow DC

Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX

Canon Utilities Easy-PhotoPrint EX

Canon Utilities My Printer

Canon Utilities MyCamera

Canon Utilities MyCamera DC

Canon Utilities PhotoStitch

Canon Utilities RemoteCapture DC

Canon Utilities RemoteCapture Task for ZoomBrowser EX

Canon Utilities Solution Menu

Canon Utilities ZoomBrowser EX

Canon ZoomBrowser EX Memory Card Utility

Capitalism II Demo

Chocolatier: Decadence by Design

Chuzzle Deluxe

CloudCare

CodeBlocks

Coffee Tycoon (remove only)

Connectivity Library and TI-Nspire™ handheld drivers

Continuum Passage

Coreship v1.0

Coupon Printer for Windows

Crazy Machines Elements - DEMO

Crystalline 1.0

CyberLink DVD Suite Deluxe

D3DX10

Data Doctor Recovery Pen Drive (Demo)

Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition

Demolition, Inc. Demo

Diner Dash 2 Restaurant Rescue

Dora's World Adventure

Dreamside Maroon 1.0282.333

Duality 1.0

DVD Menu Pack for HP MediaSmart Video

EASEUS Partition Recovery 5.0.1

Egg Timer

Egg Timer Setup

Egg Timer version 1.0

Escape Rosecliff Island

Escape the Museum

Farm Frenzy

FATE

FileZilla Client 3.5.3

Final Drive Nitro

Garnet OS Development Suite

Gear Full Circle 10/31/2010 Build

GIMP 2.6.11

Glitch 1.3

Google Drive

Google Earth Plug-in

Google Update Helper

Grid Version 1.01g

Hack Attack 1.0

Heroes of Hellas 2 - Olympia

Hewlett-Packard ACLM.NET v1.1.2.0

HP Customer Experience Enhancements

HP Games

HP MediaSmart DVD

HP MediaSmart Music

HP MediaSmart Photo

HP MediaSmart Video

HP MediaSmart/TouchSmart Netflix

HP Odometer

HP Setup

HP Setup Manager

HP Support Assistant

HP Support Information

HP Update

Hulu Desktop

IDT Audio

Inno Setup version 5.5.0

Intel® Management Engine Components

Intel® Rapid Storage Technology

Java 7 Update 11

Java Auto Updater

Java™ 6 Update 31

JavaFX 2.1.1

Jewel Quest Solitaire 2

Junk Mail filter update

Kore Industries : Textures Pack

LabelPrint

Labyrinth version 0.9

LAME v3.98.3 for Audacity

Leshy Version 1.21

Life Quest®

LightScribe System Software

LogMeIn Hamachi

Magic DVD Ripper V5.4.2

Malwarebytes Anti-Malware version 1.70.0.1100

Marble Mayhem! 1.0

Mercurial 2.5.0 (x86)

Microsoft Office 2010

Microsoft Office 2010 Service Pack 1 (SP1)

Microsoft Office Access MUI (English) 2010

Microsoft Office Access Setup Metadata MUI (English) 2010

Microsoft Office Click-to-Run 2010

Microsoft Office Excel MUI (English) 2010

Microsoft Office File Validation Add-In

Microsoft Office Groove MUI (English) 2010

Microsoft Office InfoPath MUI (English) 2010

Microsoft Office OneNote MUI (English) 2010

Microsoft Office Outlook Connector

Microsoft Office Outlook MUI (English) 2010

Microsoft Office PowerPoint MUI (English) 2010

Microsoft Office Professional Plus 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (Spanish) 2010

Microsoft Office Proofing (English) 2010

Microsoft Office Publisher MUI (English) 2010

Microsoft Office Shared MUI (English) 2010

Microsoft Office Shared Setup Metadata MUI (English) 2010

Microsoft Office Starter 2010 - English

Microsoft Office Word MUI (English) 2010

Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit

Microsoft Rise Of Nations

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

Microsoft WSE 3.0 Runtime

MinGW-Get version 0.4-alpha-1

MiniTool Partition Wizard Home Edition 7.0

Momenta

Motorola Device Manager

Motorola Device Software Update

Mozilla Firefox 17.0.1 (x86 en-US)

MSVCRT

MSVCRT_amd64

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

MSXML 4.0 SP3 Parser

MSXML 4.0 SP3 Parser (KB2721691)

MSXML 4.0 SP3 Parser (KB2758694)

MSXML4 Parser

Myr Gold Build

Mystery P.I. - The London Caper

Myszere 1.0

Narbacular Drop version 1.4

Nitronic Rush (2012-06-19) version 20120619.0

Nous Ver: 1.04

NVIDIA PhysX

NVIDIA Stereoscopic 3D Driver

OneClickdigital Media Manager

OpenAL

Orblitz

PDF Complete Special Edition

Penguins!

Perspective 1.0

PHM Registry Editor

Photodex Presenter

PhotoNow!

Plants vs. Zombies

PlayReady PC Runtime x86

PMB

Poker Superstars III

Polar Bowler

Polar Golfer

Pong

Portal

portal-theme-v10-by-vitor-santo.themepack

Portal 2

Portal 2 Authoring Tools - Beta

Power2Go

PressReader

Project Albatross

ProShow

PTGui Pro Trial 9.1.3b

Quicken 2010

QuickTime

Recovery Manager

Rise of Nations Thrones and Patriots Trial Version

Royal Defense

Sansa Updater

SeaMonkey (1.1.11)

SeaMonkey (2.9.1)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553091)

Security Update for Microsoft Office 2010 (KB2553096)

Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition

Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition

Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition

Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition

Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition

Solace - February 2011

Source SDK

Source SDK Base 2007

SPORE™

Spybot - Search & Destroy

Steam

swMSM

Synaesthete (v1.0)

Tag - v1.1

TI-Nspire Student Software

TI-Nspire™ Computer Link Software

tools-freebsd

tools-linux

tools-netware

tools-solaris

tools-windows

tools-winPre2k

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2010 (KB2553065)

Update for Microsoft Office 2010 (KB2553092)

Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition

Update for Microsoft Office 2010 (KB2566458)

Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition

Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition

Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition

Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition

Update Installer for WildTangent Games App

VeNix 1.0

Virtual Families

Virtual Villagers 4 - The Tree of Life

VMware vCenter Converter Standalone

VMware Workstation

Void 1.0

Westward II: Heroes of the Frontier

Wheel of Fortune 2

WildTangent Games App (HP Games)

Windows Live Communications Platform

Windows Live Essentials

Windows Live Installer

Windows Live Mail

Windows Live Messenger

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Windows Mobile Developer Power Toys

WinRAR 4.01 (32-bit)

YAGARTO 4.6.2

Yahoo! Detect

Zinio Reader 4

Zoo Tycoon 2 - Zookeeper Collection

Zuma Deluxe

.

==== Event Viewer Messages From Past Week ========

.

2/2/2013 8:34:43 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.

2/2/2013 8:34:43 AM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

2/2/2013 8:34:43 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

2/2/2013 8:34:06 AM, Error: Service Control Manager [7024] - The VMware Workstation Server service terminated with service-specific error %%-1.

2/2/2013 2:58:43 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

2/2/2013 2:58:43 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.

2/2/2013 2:56:42 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

2/2/2013 2:56:25 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the VMware Authorization Service service to connect.

2/2/2013 2:56:25 PM, Error: Service Control Manager [7001] - The VMware Workstation Server service depends on the VMware Authorization Service service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.

2/2/2013 2:56:25 PM, Error: Service Control Manager [7000] - The VMware Authorization Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

2/1/2013 4:14:46 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk5\DR5.

2/1/2013 4:04:42 PM, Error: Microsoft-Windows-WMPNSS-Service [14365] - Proximity detection failed due to unknown error '0x80004004'. The best proximity time detected was -1 milliseconds.

2/1/2013 12:25:37 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the HP Client Services service to connect.

2/1/2013 1:52:17 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

1/31/2013 2:52:20 PM, Error: Service Control Manager [7034] - The CloudCare AntiVirus service terminated unexpectedly. It has done this 1 time(s).

1/31/2013 2:51:56 PM, Error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).

1/31/2013 2:51:44 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

1/29/2013 7:22:41 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the VMware vCenter Converter Standalone Agent service to connect.

1/29/2013 7:22:41 AM, Error: Service Control Manager [7000] - The VMware vCenter Converter Standalone Agent service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

1/29/2013 7:21:31 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x0000000000000800, 0x0000000000000002, 0x0000000000000000, 0xfffff800030cefaa). A dump was saved in: C:\Windows\Minidump\012913-21044-01.dmp. Report Id: 012913-21044-01.

1/29/2013 7:15:57 AM, Error: Service Control Manager [7022] - The Intel® Management and Security Application User Notification Service service hung on starting.

1/29/2013 6:12:54 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Apple Mobile Device service to connect.

1/29/2013 6:12:54 AM, Error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

1/29/2013 1:42:45 PM, Error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).

1/29/2013 1:42:32 PM, Error: Service Control Manager [7034] - The PDF Document Manager service terminated unexpectedly. It has done this 1 time(s).

1/29/2013 1:42:28 PM, Error: Service Control Manager [7034] - The LogMeIn Hamachi Tunneling Engine service terminated unexpectedly. It has done this 1 time(s).

1/29/2013 1:19:45 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.

1/28/2013 5:16:21 PM, Error: Service Control Manager [7001] - The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:15:59 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:41 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

1/28/2013 5:14:41 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

1/28/2013 5:14:35 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}

1/28/2013 5:14:35 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}

1/28/2013 5:14:34 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

1/28/2013 5:14:28 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

1/28/2013 5:14:21 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vmm vwififlt Wanarpv6 WfpLwf ws2ifsl

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The VMware Workstation Server service depends on the Workstation service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The VMware vCenter Converter Standalone Server service depends on the Workstation service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The PST Service service depends on the Workstation service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The CloudCare service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The CloudCare AntiVirus service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

1/28/2013 5:14:21 PM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: The dependency service or group failed to start.

1/28/2013 5:10:53 PM, Error: Service Control Manager [7031] - The PST Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 6000 milliseconds: Restart the service.

1/28/2013 11:47:36 AM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.

1/28/2013 11:47:30 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Application Virtualization Client service to connect.

1/28/2013 11:47:30 AM, Error: Service Control Manager [7000] - The Application Virtualization Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

.

==== End Of File ===========================

Link to post
Share on other sites

:welcome: I am TheDarkKnight and will be assisting you. Please ask questions if anything is unclear. :)

OK security programs first. You are running two antivirus programs:

  • avast!
  • CloudCare

Running more than one antivirus program can cause conflicts and actually reduce your security. I strongly recommend removing one of those antivirus programs. avast! is a very good free antivirus program, so unless you really like CloudCare I recommend removing it. Alternatively you can disable one and just use it occasionally for offline scanning.

You also have quite a few security programs running. Spybot is outdated, Windows Defender is considered okay, and then your two antivirus programs both offer other capabilities as well. I recommend removing Spybot, disabling Windows Defender and removing one of your antivirus programs. If you run avast! or CloudCare with MBAM you will have a very good security setup.

=====

Your logs show signs of an IP address which could be causing issues, as well as browser changes I doubt you authorised.

Please follow these instructions to run ComboFix.exe. Please visit this webpage for download links and instructions for running this tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix (CF).

Please go here to see a list of programs that need to be disabled.

**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall.**

**Note 2: If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.**

Please include the C:\ComboFix.txt in your next reply for further review.

=====

Also, please download AdwCleaner by Xplode onto your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.

=====

In your reply please provide the contents of the following:

  • ComboFix.txt.
  • AdwCleaner[R1].txt.

Do you need any help removing your security programs? How is the computer running?

Link to post
Share on other sites

Problem: I uninstalled avast! and Spybots and ran ComboFix. I have to keep Cloud Care (Bsecure) because my family uses it for website filtering. After I ran ComboFix the computer restarted and the log appeared, but there was no internet. I performed a system restore to get the internet back (which it did), so avast! and Spybots are back and ComboFix changes have likley reverted. I have not run AdwCleaner yet, I need your advice on how to proceed based on this information.

Here is the ComboFix log I got:

ComboFix 13-02-03.03 - Shawn 02/03/2013 13:48:50.1.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8175.5849 [GMT -8:00]

Running from: c:\users\Shawn.Michael-HP\Desktop\ComboFix.exe

AV: CloudCare *Disabled/Updated* {BABEE769-087B-572E-AD62-21FF46C86F61}

SP: CloudCare AntiSpyware *Disabled/Updated* {01DF068D-2E41-58A0-97D2-1A8D3D4F25DC}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\a

c:\a\Import.vmdk

c:\a\Import.vmsd

c:\a\Import.vmx

c:\a\Import.vmxf

C:\Install.exe

C:\Thumbs.db

c:\users\Michael\mp560swin102ea24.exe

c:\users\Michael\mp560swin105ea24.exe

c:\users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\tbinst

c:\users\Patrick\AppData\Roaming\0ad

c:\users\Patrick\AppData\Roaming\0ad\cache\temp.0adsave

c:\users\Patrick\AppData\Roaming\0ad\config\user.cfg

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0001.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0002.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0003.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0004.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0005.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0006.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0007.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0008.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0009.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0010.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0011.0adsave

c:\users\Patrick\AppData\Roaming\0ad\data\saves\quicksave-0012.0adsave

c:\users\Patrick\AppData\Roaming\0ad\logs\interestinglog.html

c:\users\Patrick\AppData\Roaming\0ad\logs\mainlog.html

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\1044-1\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\1044\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\1944\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\3088\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\4076-1\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\4076\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\460-1\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\460-2\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\460\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\4992-1\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\4992\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\6840\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\sim_log\7192\commands.txt

c:\users\Patrick\AppData\Roaming\0ad\logs\system_info.txt

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\cache\temp.0adsave

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\config\user.cfg

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\data\saves\quicksave-0001.0adsave

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\data\saves\quicksave-0002.0adsave

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\data\saves\quicksave-0003.0adsave

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\data\saves\quicksave-0004.0adsave

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\data\saves\quicksave-0005.0adsave

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\logs\interestinglog.html

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\logs\mainlog.html

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\logs\sim_log\2452\commands.txt

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\logs\system_info.txt

c:\users\Shawn.Michael-HP\Documents\~WRL0005.tmp

.

.

((((((((((((((((((((((((( Files Created from 2013-01-03 to 2013-02-03 )))))))))))))))))))))))))))))))

.

.

2074-05-19 00:44 . 2008-03-21 21:46 607296 ----a-w- c:\program files (x86)\Microsoft Games\Age of Empires III Ancient\deformerdllyD.dll

2040-08-24 20:34 . 2040-08-24 20:34 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-03 21:59 . 2013-02-03 21:59 -------- d-----w- c:\users\SHAWN~1~MIC\AppData\Local\temp

2013-02-03 21:59 . 2013-02-03 21:59 -------- d-----w- c:\users\Shawn\AppData\Local\temp

2013-02-03 21:59 . 2013-02-03 21:59 -------- d-----w- c:\users\Patrick\AppData\Local\temp

2013-02-03 21:59 . 2013-02-03 21:59 -------- d-----w- c:\users\Michael\AppData\Local\temp

2013-02-03 21:59 . 2013-02-03 21:59 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-02-03 21:59 . 2013-02-03 21:59 -------- d-----w- c:\users\Lisa\AppData\Local\temp

2013-02-03 21:59 . 2013-02-03 21:59 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-02-03 20:51 . 2013-02-03 20:51 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4C93BF7D-D194-42F6-B0EE-52A28CE1CAAF}\offreg.dll

2013-02-02 01:53 . 2013-02-02 19:54 -------- d-----w- c:\programdata\Spybot - Search & Destroy

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Roaming\digipen

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Local\digipen

2013-02-02 00:06 . 2013-02-02 00:06 -------- d-----w- c:\users\Lisa\AppData\Local\MagicSoftware

2013-02-02 00:01 . 2013-02-02 00:01 -------- d-----w- c:\users\Lisa\AppData\Roaming\Sony Corporation

2013-02-01 20:05 . 2013-02-01 20:05 -------- d-----w- c:\program files (x86)\Common Files\Windows Microsoft Shared

2013-02-01 20:05 . 2010-04-26 19:23 49088 ----a-w- c:\windows\SysWow64\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-04-26 19:23 58432 ----a-w- c:\windows\system32\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-02-05 17:40 21624 ----a-w- c:\windows\SysWow64\drivers\BSecACFltr.sys

2013-02-01 20:05 . 2010-02-03 17:57 22832 ----a-w- c:\windows\system32\drivers\BSecACFltr.sys

2013-02-01 19:56 . 2013-02-01 19:56 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-02-01 14:15 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4C93BF7D-D194-42F6-B0EE-52A28CE1CAAF}\mpengine.dll

2013-01-31 04:28 . 2013-01-31 04:37 -------- d-----w- c:\users\Shawn.Michael-HP\HG

2013-01-31 04:21 . 2013-01-31 04:21 -------- d-----w- c:\program files (x86)\Mercurial

2013-01-29 23:38 . 2013-01-29 23:38 -------- d-----w- c:\users\Patrick\AppData\Roaming\Game

2013-01-29 23:36 . 2013-01-29 23:36 -------- d-----w- c:\program files (x86)\Royal Defense

2013-01-29 20:43 . 2013-01-29 20:43 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Local\Programs

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 20:38 . 2013-01-29 21:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\programdata\Malwarebytes

2013-01-29 20:38 . 2012-12-15 00:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-01-29 01:49 . 2012-10-30 23:50 285328 ----a-w- c:\windows\system32\aswBoot.exe

2013-01-29 01:49 . 2013-02-03 21:36 -------- d-----w- c:\programdata\AVAST Software

2013-01-29 01:49 . 2013-01-29 01:49 -------- d-----w- c:\program files\AVAST Software

2013-01-28 04:33 . 2013-01-28 04:33 0 ----a-w- c:\windows\SysWow64\sho50B7.tmp

2013-01-27 23:39 . 2013-01-27 23:53 -------- d-----w- c:\program files (x86)\Narbacular Drop

2013-01-25 18:18 . 2013-01-25 18:18 -------- d-----w- c:\users\Michael\AppData\Roaming\Sony Corporation

2013-01-18 14:25 . 2013-01-12 11:30 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-01-17 16:00 . 2013-01-17 16:00 -------- d-----w- c:\users\Lisa\AppData\Roaming\Motorola Mobility

2013-01-15 14:29 . 2013-01-28 22:42 -------- d-----w- C:\Include

2013-01-15 14:24 . 2013-01-29 15:13 -------- d-----w- c:\users\Shawn.Michael-HP\Tutorial Projects

2013-01-15 14:21 . 2013-02-02 01:44 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-01-15 14:20 . 2013-01-15 14:21 -------- d-----w- c:\program files (x86)\CodeBlocks

2013-01-09 23:39 . 2013-01-10 00:05 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-09 15:07 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys

2013-01-09 15:07 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe

2013-01-06 03:09 . 2013-01-09 00:14 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-01-17 09:28 . 2011-08-13 21:46 273840 ------w- c:\windows\system32\MpSigStub.exe

2013-01-12 15:34 . 2012-04-01 03:11 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-01-12 15:34 . 2011-08-23 18:06 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-10 04:37 . 2011-08-14 14:52 67599240 ----a-w- c:\windows\system32\MRT.exe

2012-12-19 21:33 . 2012-07-14 00:14 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-12-19 21:33 . 2012-01-16 20:19 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-12-16 17:11 . 2012-12-21 16:12 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-16 14:45 . 2012-12-21 16:12 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-11-30 04:45 . 2013-01-09 15:08 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-11-14 07:06 . 2012-12-13 23:18 17811968 ----a-w- c:\windows\system32\mshtml.dll

2012-11-14 06:32 . 2012-12-13 23:18 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-11-14 06:11 . 2012-12-13 23:18 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-11-14 06:04 . 2012-12-13 23:18 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-11-14 06:04 . 2012-12-13 23:18 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-11-14 06:02 . 2012-12-13 23:18 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 06:02 . 2012-12-13 23:18 237056 ----a-w- c:\windows\system32\url.dll

2012-11-14 05:59 . 2012-12-13 23:18 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-11-14 05:58 . 2012-12-13 23:18 816640 ----a-w- c:\windows\system32\jscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 05:55 . 2012-12-13 23:18 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-11-14 05:55 . 2012-12-13 23:18 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-11-14 05:53 . 2012-12-13 23:18 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-11-14 05:52 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-11-14 05:46 . 2012-12-13 23:18 248320 ----a-w- c:\windows\system32\ieui.dll

2012-11-14 02:09 . 2012-12-13 23:18 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-11-14 01:58 . 2012-12-13 23:18 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-11-14 01:57 . 2012-12-13 23:18 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-11-14 01:49 . 2012-12-13 23:18 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-11-14 01:48 . 2012-12-13 23:18 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-11-14 01:44 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-11-09 05:45 . 2012-12-13 23:22 2048 ----a-w- c:\windows\system32\tzres.dll

2012-11-09 04:42 . 2012-12-13 23:22 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-11-08 19:29 . 2012-11-08 19:29 1402312 ----a-w- c:\windows\SysWow64\msxml4.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-12-03 1354736]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2010-09-28 664600]

"CloudCare"="c:\program files (x86)\Bsecure\BsecTray.exe" [2011-06-25 96040]

"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-05-20 136544]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-11-13 421736]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]

.

c:\users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Egg Timer.exe - Shortcut.lnk - c:\program files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe [2012-7-31 56832]

note.txt [2013-1-3 1759]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"mixer2"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]

@=""

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

.

R2 CLKMSVC10_C6F09094;CyberLink Product - 2011/01/05 19:22;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [2010-11-26 245232]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]

R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072]

R2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-07-17 116632]

R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]

R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]

R2 vmware-converter-agent;VMware vCenter Converter Standalone Agent;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe [2011-08-20 423536]

R2 vmware-converter-server;VMware vCenter Converter Standalone Server;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]

R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]

R3 bmdrvr;Modified Clusters Tracking Driver;SysWOW64\drivers\bmdrvr.sys [x]

R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]

R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2012-06-11 22016]

R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2012-01-25 9728]

R3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2012-06-08 31232]

R3 prwntdrv;prwntdrv;c:\windows\system32\prwntdrv.sys [2010-08-26 16776]

R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-09-03 19936]

R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-09-03 13280]

R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]

R3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]

R3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\Drivers\SIVX64.sys [2008-06-14 57312]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 USBTINSP;TI-Nspire Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [2010-03-30 142848]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-08-14 1255736]

R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]

R4 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]

S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-23 203264]

S2 Bsecure;CloudCare;c:\program files (x86)\Bsecure\InetCtrl.exe [2011-06-25 66344]

S2 BsecureAV;CloudCare AntiVirus;c:\program files (x86)\Bsecure\BsecAV.exe [2011-06-25 161776]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-11 2465712]

S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]

S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-15 398184]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-15 682344]

S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2010-09-28 1119768]

S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]

S2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2011-11-09 301720]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]

S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-30 846448]

S2 vmware-converter-worker;VMware vCenter Converter Standalone Worker;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]

S3 BSecACFltr;BSecACFltr;c:\windows\system32\DRIVERS\BSecACFltr.sys [2010-02-03 22832]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-15 24176]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - BsecureFilter

*Deregistered* - CLKMDRV10_C6F09094

.

Contents of the 'Scheduled Tasks' folder

.

2013-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003Core.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-02-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003UA.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-01-11 c:\windows\Tasks\HPCeeScheduleForMICHAEL-HP$.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-01-25 c:\windows\Tasks\HPCeeScheduleForMichael.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-02-01 c:\windows\Tasks\HPCeeScheduleForPatrick.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-01-28 c:\windows\Tasks\HPCeeScheduleForShawn.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]

"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-26 2184520]

"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-06-24 1128448]

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local;192.168.*.*

mSearchAssistant = hxxp://start.facemoods.com/?a=fmtgl&s={searchTerms}&f=4

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

LSP: %SystemRoot%\system32\vsocklib.dll

TCP: DhcpNameServer = 192.168.0.1 205.171.3.25

FF - ProfilePath - c:\users\Shawn.Michael-HP\AppData\Roaming\Mozilla\Firefox\Profiles\dbh3faig.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - ExtSQL: 2013-01-29 06:12; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF

.

- - - - ORPHANS REMOVED - - - -

.

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe

AddRemove-Sansa Updater - c:\users\Shawn.Michael-HP\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdaterInstall.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]

"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-853655980-1941484234-785684605-1005\Software\SecuROM\License information*]

"datasecu"=hex:a9,1f,74,79,ab,40,60,ea,06,fd,68,99,75,08,36,4f,5f,b8,9a,73,62,

da,5c,9a,f4,0d,34,f1,29,03,75,72,56,46,8e,b5,07,33,00,d3,5b,06,55,e0,ac,99,\

"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*]

"v5Licence0"="15-3BWD-J5JA-Q87W-PSPD-EG7V-PAWT3ZW"

"Activated"="Y"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe

c:\program files (x86)\Photodex\ProShow\ScsiAccess.exe

c:\windows\SysWOW64\vmnat.exe

c:\windows\SysWOW64\vmnetdhcp.exe

c:\program files (x86)\Bsecure\BSecAMX.exe

c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

.

**************************************************************************

.

Completion time: 2013-02-03 14:11:52 - machine was rebooted

ComboFix-quarantined-files.txt 2013-02-03 22:11

.

Pre-Run: 1,370,269,532,160 bytes free

Post-Run: 1,372,376,158,208 bytes free

.

- - End Of File - - 7BC28FC259F6FA27B580E010DB173862

Link to post
Share on other sites

Internet still was disabled. Ran ComboFix and AdwCleaner this morning. Internet was disabled again (said something about service not running, ran troubleshooter, then it said could not automatically find proxy settings). For some reason I thought running ComboFix again would help, it didn't. (I would guess that was a really bad idea, and sorry if that is true :(). Had to do a system restore again, so avast! and Spybots are back again. Forgot to move the previous log before running the 2nd ComboFix but here is today's 2nd ComboFix log and AdwCleaner log:

ComboFix 13-02-03.03 - Shawn 02/04/2013 15:21:10.2.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8175.6391 [GMT -8:00]

Running from: C:\Users\Shawn.Michael-HP\Desktop\ComboFix.exe

AV: CloudCare *Disabled/Updated* {BABEE769-087B-572E-AD62-21FF46C86F61}

SP: CloudCare AntiSpyware *Disabled/Updated* {01DF068D-2E41-58A0-97D2-1A8D3D4F25DC}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

((((((((((((((((((((((((( Files Created from 2013-01-04 to 2013-02-04 )))))))))))))))))))))))))))))))

2074-05-19 00:44:52 . 2008-03-21 21:46:13 607296 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires III Ancient\deformerdllyD.dll

2040-08-24 20:34:18 . 2040-08-24 20:34:18 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-04 23:30:18 . 2013-02-04 23:30:18 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\temp

2013-02-04 23:30:18 . 2013-02-04 23:30:18 -------- d-----w- C:\Users\SHAWN~1~MIC\AppData\Local\temp

2013-02-04 23:30:18 . 2013-02-04 23:30:18 -------- d-----w- C:\Users\Shawn\AppData\Local\temp

2013-02-04 23:30:18 . 2013-02-04 23:30:18 -------- d-----w- C:\Users\Patrick\AppData\Local\temp

2013-02-04 23:30:18 . 2013-02-04 23:30:18 -------- d-----w- C:\Users\Michael\AppData\Local\temp

2013-02-04 23:30:18 . 2013-02-04 23:30:18 -------- d-----w- C:\Users\Lisa\AppData\Local\temp

2013-02-04 23:30:18 . 2013-02-04 23:30:18 -------- d-----w- C:\Users\Default\AppData\Local\temp

2013-02-02 19:10:25 . 2009-01-25 20:14:02 17272 ----a-w- C:\Windows\system32\sdnclean64.exe

2013-02-02 19:10:21 . 2013-02-04 15:03:47 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2

2013-02-02 01:53:30 . 2013-02-03 22:35:51 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy

2013-02-02 01:49:27 . 2013-02-02 01:49:27 -------- d-----w- C:\Users\Lisa\AppData\Roaming\digipen

2013-02-02 01:49:27 . 2013-02-02 01:49:27 -------- d-----w- C:\Users\Lisa\AppData\Local\digipen

2013-02-02 00:06:53 . 2013-02-02 00:06:53 -------- d-----w- C:\Users\Lisa\AppData\Local\MagicSoftware

2013-02-02 00:01:58 . 2013-02-02 00:01:58 -------- d-----w- C:\Users\Lisa\AppData\Roaming\Sony Corporation

2013-02-01 20:05:27 . 2013-02-01 20:05:27 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Microsoft Shared

2013-02-01 20:05:26 . 2010-04-26 19:23:50 49088 ----a-w- C:\Windows\SysWow64\drivers\BsecFltr.sys

2013-02-01 20:05:26 . 2010-04-26 19:23:30 58432 ----a-w- C:\Windows\system32\drivers\BsecFltr.sys

2013-02-01 20:05:26 . 2010-02-05 17:40:12 21624 ----a-w- C:\Windows\SysWow64\drivers\BSecACFltr.sys

2013-02-01 20:05:26 . 2010-02-03 17:57:21 22832 ----a-w- C:\Windows\system32\drivers\BSecACFltr.sys

2013-02-01 19:56:34 . 2013-02-01 19:56:34 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-02-01 14:15:44 . 2013-01-08 05:32:08 9161176 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4C93BF7D-D194-42F6-B0EE-52A28CE1CAAF}\mpengine.dll

2013-01-31 04:28:57 . 2013-01-31 04:37:15 -------- d-----w- C:\Users\Shawn.Michael-HP\HG

2013-01-31 04:21:22 . 2013-01-31 04:21:28 -------- d-----w- C:\Program Files (x86)\Mercurial

2013-01-29 23:38:38 . 2013-01-29 23:38:38 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Game

2013-01-29 23:36:50 . 2013-01-29 23:36:58 -------- d-----w- C:\Program Files (x86)\Royal Defense

2013-01-29 20:43:58 . 2013-01-29 20:43:58 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Local\Programs

2013-01-29 20:38:09 . 2013-01-29 20:38:09 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 20:38:04 . 2013-01-29 21:13:30 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-01-29 20:38:04 . 2013-01-29 20:38:04 -------- d-----w- C:\ProgramData\Malwarebytes

2013-01-29 20:38:04 . 2012-12-15 00:49:28 24176 ----a-w- C:\Windows\system32\drivers\mbam.sys

2013-01-29 01:49:42 . 2012-10-30 23:50:30 285328 ----a-w- C:\Windows\system32\aswBoot.exe

2013-01-29 01:49:06 . 2013-02-04 14:38:01 -------- d-----w- C:\ProgramData\AVAST Software

2013-01-29 01:49:06 . 2013-02-03 22:35:42 -------- d-----w- C:\Program Files\AVAST Software

2013-01-28 04:33:52 . 2013-01-28 04:33:52 0 ----a-w- C:\Windows\SysWow64\sho50B7.tmp

2013-01-27 23:39:34 . 2013-01-27 23:53:43 -------- d-----w- C:\Program Files (x86)\Narbacular Drop

2013-01-25 18:18:12 . 2013-01-25 18:18:12 -------- d-----w- C:\Users\Michael\AppData\Roaming\Sony Corporation

2013-01-18 14:25:58 . 2013-01-12 11:30:18 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-01-17 16:00:44 . 2013-01-17 16:00:44 -------- d-----w- C:\Users\Lisa\AppData\Roaming\Motorola Mobility

2013-01-15 14:29:46 . 2013-01-28 22:42:56 -------- d-----w- C:\Include

2013-01-15 14:24:52 . 2013-01-29 15:13:09 -------- d-----w- C:\Users\Shawn.Michael-HP\Tutorial Projects

2013-01-15 14:21:36 . 2013-02-02 01:44:43 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-01-15 14:20:57 . 2013-01-15 14:21:33 -------- d-----w- C:\Program Files (x86)\CodeBlocks

2013-01-09 23:39:00 . 2013-01-10 00:05:29 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-09 15:07:52 . 2012-11-23 03:26:31 3149824 ----a-w- C:\Windows\system32\win32k.sys

2013-01-09 15:07:52 . 2012-11-23 03:13:57 68608 ----a-w- C:\Windows\system32\taskhost.exe

2013-01-06 03:09:36 . 2013-01-09 00:14:23 -------- d-----w- C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2013-01-17 09:28 . 2011-08-13 21:46 273840 ------w- c:\windows\system32\MpSigStub.exe

2013-01-12 15:34 . 2012-04-01 03:11 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-01-12 15:34 . 2011-08-23 18:06 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-10 04:37 . 2011-08-14 14:52 67599240 ----a-w- c:\windows\system32\MRT.exe

2012-12-19 21:33 . 2012-07-14 00:14 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-12-19 21:33 . 2012-01-16 20:19 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-12-16 17:11 . 2012-12-21 16:12 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-16 14:45 . 2012-12-21 16:12 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-11-30 04:45 . 2013-01-09 15:08 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-11-14 07:06 . 2012-12-13 23:18 17811968 ----a-w- c:\windows\system32\mshtml.dll

2012-11-14 06:32 . 2012-12-13 23:18 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-11-14 06:11 . 2012-12-13 23:18 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-11-14 06:04 . 2012-12-13 23:18 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-11-14 06:04 . 2012-12-13 23:18 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-11-14 06:02 . 2012-12-13 23:18 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 06:02 . 2012-12-13 23:18 237056 ----a-w- c:\windows\system32\url.dll

2012-11-14 05:59 . 2012-12-13 23:18 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-11-14 05:58 . 2012-12-13 23:18 816640 ----a-w- c:\windows\system32\jscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 05:55 . 2012-12-13 23:18 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-11-14 05:55 . 2012-12-13 23:18 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-11-14 05:53 . 2012-12-13 23:18 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-11-14 05:52 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-11-14 05:46 . 2012-12-13 23:18 248320 ----a-w- c:\windows\system32\ieui.dll

2012-11-14 02:09 . 2012-12-13 23:18 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-11-14 01:58 . 2012-12-13 23:18 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-11-14 01:57 . 2012-12-13 23:18 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-11-14 01:49 . 2012-12-13 23:18 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-11-14 01:48 . 2012-12-13 23:18 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-11-14 01:44 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-11-09 05:45 . 2012-12-13 23:22 2048 ----a-w- c:\windows\system32\tzres.dll

2012-11-09 04:42 . 2012-12-13 23:22 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-11-08 19:29 . 2012-11-08 19:29 1402312 ----a-w- c:\windows\SysWow64\msxml4.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-12-03 1354736]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2010-09-28 664600]

"CloudCare"="c:\program files (x86)\Bsecure\BsecTray.exe" [2011-06-25 96040]

"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-05-20 136544]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-11-13 421736]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]

.

c:\users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Egg Timer.exe - Shortcut.lnk - c:\program files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe [2012-7-31 56832]

note.txt [2013-1-3 1759]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"mixer2"=wdmaud.drv

# AdwCleaner v2.110 - Logfile created 02/04/2013 at 07:41:30

# Updated 03/02/2013 by Xplode

# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)

# User : Shawn - MICHAEL-HP

# Boot Mode : Normal

# Running from : C:\Users\Shawn.Michael-HP\Downloads\adwcleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk

Folder Found : C:\ProgramData\Ask

Folder Found : C:\ProgramData\Trymedia

***** [Registry] *****

Key Found : HKCU\Software\BrowserCompanion

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}

Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\clbfjfbnelcflpgpklppgplejolacbej

Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Found : HKLM\SOFTWARE\Classes\Interface\{1C888195-0160-4883-91B7-294C0CE2F277}

Key Found : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}

Key Found : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}

Key Found : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}

Key Found : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}

Key Found : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}

Key Found : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}

Key Found : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}

Key Found : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}

Key Found : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}

Key Found : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}

Key Found : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}

Key Found : HKLM\SOFTWARE\Classes\Interface\{99ACA0F7-D864-45CB-8C40-FD42A077E7CA}

Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}

Key Found : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}

Key Found : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}

Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}

Key Found : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}

Key Found : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}

Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}

Key Found : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Found : HKU\S-1-5-21-853655980-1941484234-785684605-1005\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

***** [internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=fmtgl&s={searchTerms}&f=4

-\\ Mozilla Firefox v17.0.1 (en-US)

*************************

AdwCleaner[R1].txt - [3935 octets] - [04/02/2013 07:41:30]

########## EOF - C:\AdwCleaner[R1].txt - [3995 octets] ##########

Link to post
Share on other sites

Found a fix named "ComboFix2.txt" in C:\Qoobox that was created this morning at 7:41 A.M. (When I ran the 1st scan), although the date in the file seems off by one day. Think this might be the 1st log, so here it is, just in case:

ComboFix 13-02-03.03 - Shawn 02/04/2013 7:14.1.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8175.5876 [GMT -8:00]

Running from: c:\users\Shawn.Michael-HP\Desktop\ComboFix.exe

AV: CloudCare *Disabled/Updated* {BABEE769-087B-572E-AD62-21FF46C86F61}

SP: CloudCare AntiSpyware *Disabled/Updated* {01DF068D-2E41-58A0-97D2-1A8D3D4F25DC}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\Install.exe

c:\users\Michael\mp560swin102ea24.exe

c:\users\Michael\mp560swin105ea24.exe

c:\users\Patrick\AppData\Roaming\0ad

c:\users\Patrick\AppData\Roaming\0ad\config\user.cfg

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\config\user.cfg

.

.

((((((((((((((((((((((((( Files Created from 2013-01-04 to 2013-02-04 )))))))))))))))))))))))))))))))

.

.

2074-05-19 00:44 . 2008-03-21 21:46 607296 ----a-w- c:\program files (x86)\Microsoft Games\Age of Empires III Ancient\deformerdllyD.dll

2040-08-24 20:34 . 2040-08-24 20:34 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-04 15:25 . 2013-02-04 15:25 -------- d-----w- c:\users\SHAWN~1~MIC\AppData\Local\temp

2013-02-04 15:25 . 2013-02-04 15:25 -------- d-----w- c:\users\Shawn\AppData\Local\temp

2013-02-04 15:25 . 2013-02-04 15:25 -------- d-----w- c:\users\Patrick\AppData\Local\temp

2013-02-04 15:25 . 2013-02-04 15:25 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-02-04 15:25 . 2013-02-04 15:25 -------- d-----w- c:\users\Michael\AppData\Local\temp

2013-02-04 15:25 . 2013-02-04 15:25 -------- d-----w- c:\users\Lisa\AppData\Local\temp

2013-02-04 15:25 . 2013-02-04 15:25 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-02-02 19:10 . 2009-01-25 20:14 17272 ----a-w- c:\windows\system32\sdnclean64.exe

2013-02-02 19:10 . 2013-02-04 15:03 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2

2013-02-02 01:53 . 2013-02-03 22:35 -------- d-----w- c:\programdata\Spybot - Search & Destroy

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Roaming\digipen

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Local\digipen

2013-02-02 00:06 . 2013-02-02 00:06 -------- d-----w- c:\users\Lisa\AppData\Local\MagicSoftware

2013-02-02 00:01 . 2013-02-02 00:01 -------- d-----w- c:\users\Lisa\AppData\Roaming\Sony Corporation

2013-02-01 20:05 . 2013-02-01 20:05 -------- d-----w- c:\program files (x86)\Common Files\Windows Microsoft Shared

2013-02-01 20:05 . 2010-04-26 19:23 49088 ----a-w- c:\windows\SysWow64\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-04-26 19:23 58432 ----a-w- c:\windows\system32\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-02-05 17:40 21624 ----a-w- c:\windows\SysWow64\drivers\BSecACFltr.sys

2013-02-01 20:05 . 2010-02-03 17:57 22832 ----a-w- c:\windows\system32\drivers\BSecACFltr.sys

2013-02-01 19:56 . 2013-02-01 19:56 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-02-01 14:15 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4C93BF7D-D194-42F6-B0EE-52A28CE1CAAF}\mpengine.dll

2013-01-31 04:28 . 2013-01-31 04:37 -------- d-----w- c:\users\Shawn.Michael-HP\HG

2013-01-31 04:21 . 2013-01-31 04:21 -------- d-----w- c:\program files (x86)\Mercurial

2013-01-29 23:38 . 2013-01-29 23:38 -------- d-----w- c:\users\Patrick\AppData\Roaming\Game

2013-01-29 23:36 . 2013-01-29 23:36 -------- d-----w- c:\program files (x86)\Royal Defense

2013-01-29 20:43 . 2013-01-29 20:43 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Local\Programs

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 20:38 . 2013-01-29 21:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\programdata\Malwarebytes

2013-01-29 20:38 . 2012-12-15 00:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-01-29 01:49 . 2012-10-30 23:50 285328 ----a-w- c:\windows\system32\aswBoot.exe

2013-01-29 01:49 . 2013-02-04 14:38 -------- d-----w- c:\programdata\AVAST Software

2013-01-29 01:49 . 2013-02-03 22:35 -------- d-----w- c:\program files\AVAST Software

2013-01-28 04:33 . 2013-01-28 04:33 0 ----a-w- c:\windows\SysWow64\sho50B7.tmp

2013-01-27 23:39 . 2013-01-27 23:53 -------- d-----w- c:\program files (x86)\Narbacular Drop

2013-01-25 18:18 . 2013-01-25 18:18 -------- d-----w- c:\users\Michael\AppData\Roaming\Sony Corporation

2013-01-18 14:25 . 2013-01-12 11:30 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-01-17 16:00 . 2013-01-17 16:00 -------- d-----w- c:\users\Lisa\AppData\Roaming\Motorola Mobility

2013-01-15 14:29 . 2013-01-28 22:42 -------- d-----w- C:\Include

2013-01-15 14:24 . 2013-01-29 15:13 -------- d-----w- c:\users\Shawn.Michael-HP\Tutorial Projects

2013-01-15 14:21 . 2013-02-02 01:44 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-01-15 14:20 . 2013-01-15 14:21 -------- d-----w- c:\program files (x86)\CodeBlocks

2013-01-09 23:39 . 2013-01-10 00:05 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-09 15:07 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys

2013-01-09 15:07 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe

2013-01-06 03:09 . 2013-01-09 00:14 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-01-17 09:28 . 2011-08-13 21:46 273840 ------w- c:\windows\system32\MpSigStub.exe

2013-01-12 15:34 . 2012-04-01 03:11 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-01-12 15:34 . 2011-08-23 18:06 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-10 04:37 . 2011-08-14 14:52 67599240 ----a-w- c:\windows\system32\MRT.exe

2012-12-19 21:33 . 2012-07-14 00:14 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-12-19 21:33 . 2012-01-16 20:19 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-12-16 17:11 . 2012-12-21 16:12 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-16 14:45 . 2012-12-21 16:12 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-11-30 04:45 . 2013-01-09 15:08 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-11-14 07:06 . 2012-12-13 23:18 17811968 ----a-w- c:\windows\system32\mshtml.dll

2012-11-14 06:32 . 2012-12-13 23:18 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-11-14 06:11 . 2012-12-13 23:18 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-11-14 06:04 . 2012-12-13 23:18 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-11-14 06:04 . 2012-12-13 23:18 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-11-14 06:02 . 2012-12-13 23:18 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 06:02 . 2012-12-13 23:18 237056 ----a-w- c:\windows\system32\url.dll

2012-11-14 05:59 . 2012-12-13 23:18 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-11-14 05:58 . 2012-12-13 23:18 816640 ----a-w- c:\windows\system32\jscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 05:55 . 2012-12-13 23:18 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-11-14 05:55 . 2012-12-13 23:18 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-11-14 05:53 . 2012-12-13 23:18 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-11-14 05:52 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-11-14 05:46 . 2012-12-13 23:18 248320 ----a-w- c:\windows\system32\ieui.dll

2012-11-14 02:09 . 2012-12-13 23:18 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-11-14 01:58 . 2012-12-13 23:18 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-11-14 01:57 . 2012-12-13 23:18 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-11-14 01:49 . 2012-12-13 23:18 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-11-14 01:48 . 2012-12-13 23:18 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-11-14 01:44 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-11-09 05:45 . 2012-12-13 23:22 2048 ----a-w- c:\windows\system32\tzres.dll

2012-11-09 04:42 . 2012-12-13 23:22 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-11-08 19:29 . 2012-11-08 19:29 1402312 ----a-w- c:\windows\SysWow64\msxml4.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-12-03 1354736]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2010-09-28 664600]

"CloudCare"="c:\program files (x86)\Bsecure\BsecTray.exe" [2011-06-25 96040]

"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-05-20 136544]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-11-13 421736]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]

.

c:\users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Egg Timer.exe - Shortcut.lnk - c:\program files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe [2012-7-31 56832]

note.txt [2013-1-3 1759]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"mixer2"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]

@=""

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

.

R2 CLKMSVC10_C6F09094;CyberLink Product - 2011/01/05 19:22;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [2010-11-26 245232]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]

R2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-07-17 116632]

R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]

R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]

R2 vmware-converter-agent;VMware vCenter Converter Standalone Agent;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe [2011-08-20 423536]

R2 vmware-converter-server;VMware vCenter Converter Standalone Server;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]

R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]

R3 bmdrvr;Modified Clusters Tracking Driver;SysWOW64\drivers\bmdrvr.sys [x]

R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]

R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2012-06-11 22016]

R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2012-01-25 9728]

R3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2012-06-08 31232]

R3 prwntdrv;prwntdrv;c:\windows\system32\prwntdrv.sys [2010-08-26 16776]

R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-09-03 19936]

R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-09-03 13280]

R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]

R3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]

R3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\Drivers\SIVX64.sys [2008-06-14 57312]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 USBTINSP;TI-Nspire Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [2010-03-30 142848]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-08-14 1255736]

R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]

R4 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]

S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-23 203264]

S2 Bsecure;CloudCare;c:\program files (x86)\Bsecure\InetCtrl.exe [2011-06-25 66344]

S2 BsecureAV;CloudCare AntiVirus;c:\program files (x86)\Bsecure\BsecAV.exe [2011-06-25 161776]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-11 2465712]

S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072]

S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]

S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-15 398184]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-15 682344]

S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2010-09-28 1119768]

S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]

S2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2011-11-09 301720]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]

S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-30 846448]

S2 vmware-converter-worker;VMware vCenter Converter Standalone Worker;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]

S3 BSecACFltr;BSecACFltr;c:\windows\system32\DRIVERS\BSecACFltr.sys [2010-02-03 22832]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-15 24176]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - BsecureFilter

*Deregistered* - CLKMDRV10_C6F09094

.

Contents of the 'Scheduled Tasks' folder

.

2013-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003Core.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-02-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003UA.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-01-11 c:\windows\Tasks\HPCeeScheduleForMICHAEL-HP$.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-01-25 c:\windows\Tasks\HPCeeScheduleForMichael.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-02-01 c:\windows\Tasks\HPCeeScheduleForPatrick.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-02-04 c:\windows\Tasks\HPCeeScheduleForShawn.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]

"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-26 2184520]

"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-06-24 1128448]

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local;192.168.*.*

mSearchAssistant = hxxp://start.facemoods.com/?a=fmtgl&s={searchTerms}&f=4

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

LSP: %SystemRoot%\system32\vsocklib.dll

TCP: DhcpNameServer = 192.168.0.1 205.171.3.25

FF - ProfilePath - c:\users\Shawn.Michael-HP\AppData\Roaming\Mozilla\Firefox\Profiles\dbh3faig.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - ExtSQL: 2013-01-29 06:12; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF

.

- - - - ORPHANS REMOVED - - - -

.

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]

"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-853655980-1941484234-785684605-1005\Software\SecuROM\License information*]

"datasecu"=hex:a9,1f,74,79,ab,40,60,ea,06,fd,68,99,75,08,36,4f,5f,b8,9a,73,62,

da,5c,9a,f4,0d,34,f1,29,03,75,72,56,46,8e,b5,07,33,00,d3,5b,06,55,e0,ac,99,\

"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*]

"v5Licence0"="15-3BWD-J5JA-Q87W-PSPD-EG7V-PAWT3ZW"

"Activated"="Y"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe

c:\program files (x86)\Photodex\ProShow\ScsiAccess.exe

c:\windows\SysWOW64\vmnat.exe

c:\windows\SysWOW64\vmnetdhcp.exe

c:\program files (x86)\Bsecure\BSecAMX.exe

c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

.

**************************************************************************

.

Completion time: 2013-02-04 07:41:11 - machine was rebooted

ComboFix-quarantined-files.txt 2013-02-04 15:41

ComboFix2.txt 2013-02-03 22:11

.

Pre-Run: 1,370,644,914,176 bytes free

Post-Run: 1,371,029,786,624 bytes free

.

- - End Of File - - D751C3B262EDF41A94C5C38AD38BA3EB

Link to post
Share on other sites

Hello QubicComputers,

OK please avoid ComboFix for now.

Please do the following to re-run AdwCleaner:

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[s1].txt as well.
    Note: If you get a message that you must reboot the computer before starting deletion, please do. At reboot, only AdwCleaner will run and you can only click on the Delete button.
    When the deletion is done, AdwCleaner will reboot the computer again and open the logfile.

=====

For x32 (x86) bit systems please download the Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.

For x64 bit systems please download the Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

To enter System Recovery Options by using the Windows installation disc:

  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:


    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt

[*]Select Command Prompt.

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select Computer, find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter.

Note: Replace letter e with the drive letter of your flash drive.

[*]The tool will start to run.

[*]When the tool opens click Yes to the disclaimer.

[*]Press the Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it in your reply.

=====

In your reply please provide the following:

  • AdwCleaner[s1].txt.
  • FRST.txt.

Link to post
Share on other sites

Here are the logs:

# AdwCleaner v2.111 - Logfile created 02/05/2013 at 06:33:48

# Updated 05/02/2013 by Xplode

# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)

# User : Shawn - MICHAEL-HP

# Boot Mode : Normal

# Running from : C:\Users\Shawn.Michael-HP\Downloads\adwcleaner.exe

# Option [Delete]

***** [services] *****

***** [Files / Folders] *****

File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk

Folder Deleted : C:\ProgramData\Ask

Folder Deleted : C:\ProgramData\Trymedia

***** [Registry] *****

Key Deleted : HKCU\Software\BrowserCompanion

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}

Key Deleted : HKCU\Software\Zugo

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}

Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS

Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}

Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}

Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\clbfjfbnelcflpgpklppgplejolacbej

Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1C888195-0160-4883-91B7-294C0CE2F277}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{99ACA0F7-D864-45CB-8C40-FD42A077E7CA}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://start.facemoods.com/?a=fmtgl&s={searchTerms}&f=4 --> hxxp://www.google.com

-\\ Mozilla Firefox v17.0.1 (en-US)

*************************

AdwCleaner[R3].txt - [4167 octets] - [05/02/2013 06:33:37]

AdwCleaner[s1].txt - [4108 octets] - [05/02/2013 06:33:48]

########## EOF - C:\AdwCleaner[s1].txt - [4168 octets] ##########

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-02-2013 02

Ran by SYSTEM at 05-02-2013 06:41:45

Running from G:\

Windows 7 Home Premium (X64) OS Language: English(US)

The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)

HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [2184520 2009-07-26] (CANON INC.)

HKLM\...\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon [767312 2009-03-17] (CANON INC.)

HKLM\...\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-24] (IDT, Inc.)

HKLM-x32\...\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)

HKLM-x32\...\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe [664600 2010-09-28] (PDF Complete Inc)

HKLM-x32\...\Run: [CloudCare] C:\Program Files (x86)\Bsecure\BsecTray.exe [96040 2011-06-25] (Bsecure Technologies, Inc.)

HKLM-x32\...\Run: [iJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [136544 2009-05-19] (CANON INC.)

HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-10-11] (Apple Inc.)

HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-11-13] (Apple Inc.)

HKLM-x32\...\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)

HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated)

HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.)

HKLM-x32\...\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)

HKLM-x32\...\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)

HKLM-x32\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4297136 2012-10-30] (AVAST Software)

HKU\Lisa\...\Run: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1354736 2012-12-03] (Valve Corporation)

HKU\Lisa\...\Run: [sansaDispatch] C:\Users\Lisa\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [x]

HKU\Michael\...\Run: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1354736 2012-12-03] (Valve Corporation)

HKU\Michael\...\Run: [sansaDispatch] C:\Users\Michael\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [x]

HKU\Patrick\...\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1354736 2012-12-03] (Valve Corporation)

HKU\Patrick\...\Run: [sansaDispatch] C:\Users\Patrick\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [79872 2012-02-22] (SanDisk Corporation)

HKU\Patrick\...\Run: [Google Update] "C:\Users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-07-14] (Google Inc.)

HKU\Patrick\...\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart [16328976 2012-12-17] (Google)

HKU\Shawn.Michael-HP\...\Run: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1354736 2012-12-03] (Valve Corporation)

HKU\UpdatusUser\...\Run: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1354736 2012-12-03] (Valve Corporation)

HKU\UpdatusUser\...\Run: [sansaDispatch] C:\Users\UpdatusUser\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [x]

Startup: C:\Users\Shawn.Michael-HP\Start Menu\Programs\Startup\Egg Timer.exe - Shortcut.lnk

ShortcutTarget: Egg Timer.exe - Shortcut.lnk -> C:\Program Files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe (Qube Software)

Startup: C:\Users\Shawn.Michael-HP\Start Menu\Programs\Startup\note.txt ()

==================== Services (Whitelisted) ===================

2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44808 2012-10-30] (AVAST Software)

2 Bsecure; C:\Program Files (x86)\Bsecure\InetCtrl.exe [66344 2011-06-25] (Bsecure Technologies, Inc.)

2 BsecureAV; C:\Program Files (x86)\Bsecure\BsecAV.exe [161776 2011-06-25] (Bsecure Technologies, Inc.)

2 CLKMSVC10_C6F09094; "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe" /svc [245232 2010-11-25] (CyberLink)

3 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-09] ()

2 MBAMScheduler; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe" [398184 2012-12-14] (Malwarebytes Corporation)

2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [682344 2012-12-14] (Malwarebytes Corporation)

2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [116632 2012-07-17] ()

4 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola)

2 ReflectService.exe; "C:\Program Files\Macrium\Reflect\ReflectService.exe" [301720 2011-11-09] ()

2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow\ScsiAccess.exe [181312 2011-12-23] ()

2 vmware-converter-agent; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-agent.xml" [6269 2012-04-11] ()

2 vmware-converter-server; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-server.xml" [4280 2012-04-11] ()

2 vmware-converter-worker; "C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe" -s "C:\ProgramData\VMware\VMware vCenter Converter Standalone\converter-worker.xml" [6882 2012-04-11] ()

2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-04-11] ()

==================== Drivers (Whitelisted) =====================

2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [25232 2012-10-30] (AVAST Software)

2 aswMonFlt; C:\Windows\System32\Drivers\aswMonFlt.sys [71600 2012-10-30] (AVAST Software)

1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [54072 2012-10-15] (AVAST Software)

1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [984144 2012-10-30] (AVAST Software)

1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [370288 2012-10-30] (AVAST Software)

1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59728 2012-10-30] (AVAST Software)

3 bmdrvr; C:\Windows\SysWow64\Drivers\bmdrvr.sys [74352 2011-03-15] (VMware, Inc.)

3 BSecACFltr; C:\Windows\System32\Drivers\BSecACFltr.sys [22832 2010-02-03] ()

3 BSecACFltr; C:\Windows\SysWow64\Drivers\BSecACFltr.sys [21624 2010-02-05] ()

0 BsecureFilter; C:\Windows\System32\drivers\BsecFltr.sys [58432 2010-04-26] (BSafe Online)

3 CpqDfw; C:\Windows\System32\Drivers\CpqDfw.sys [24376 2010-03-01] ()

3 cqcpu; C:\Windows\System32\Drivers\cqcpu.sys [24376 2010-03-01] ()

3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation)

3 motport; C:\Windows\System32\Drivers\motport.sys [31232 2012-06-08] (Motorola Mobility Inc)

3 prwntdrv; \??\C:\Windows\system32\prwntdrv.sys [16776 2010-08-25] ()

3 pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [19936 2011-09-02] ()

3 pwdspio; \??\C:\Windows\system32\pwdspio.sys [13280 2011-09-02] ()

3 SIVDRIVER; \??\C:\Windows\system32\Drivers\SIVX64.sys [57312 2008-06-14] (Ray Hinchliffe)

3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments)

==================== NetSvcs (Whitelisted) ====================

==================== One Month Created Files and Folders ========

2040-09-25 14:37 - 2040-09-25 14:37 - 00000000 ____D C:\Program Files (x86)\WinRAR

2040-08-24 12:34 - 2040-08-24 12:34 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-05 06:41 - 2013-02-05 06:41 - 00000000 ____D C:\FRST

2013-02-05 06:33 - 2013-02-05 06:33 - 00004191 ____A C:\AdwCleaner[s1].txt

2013-02-05 06:33 - 2013-02-05 06:33 - 00004167 ____A C:\AdwCleaner[R3].txt

2013-02-05 06:32 - 2013-02-05 06:32 - 00582119 ____A C:\Users\Shawn.Michael-HP\Downloads\adwcleaner.exe

2013-02-04 17:12 - 2013-02-04 17:12 - 00000159 ____A C:\Users\Patrick\Documents\RONTAP.txt

2013-02-04 16:19 - 2013-02-04 16:19 - 00000000 ____A C:\vcredist.bmp

2013-02-04 16:04 - 2013-02-05 06:35 - 00001018 ____A C:\Windows\setupact.log

2013-02-04 15:38 - 2013-02-04 15:38 - 00023019 ____A C:\ComboFix.txt

2013-02-04 15:21 - 2013-02-04 15:47 - 00010796 ____A C:\Users\Shawn.Michael-HP\Desktop\ComboFix.txt

2013-02-03 15:53 - 2013-02-03 15:54 - 23034922 ____A C:\Users\Shawn.Michael-HP\Downloads\planet_arnessk.zip

2013-02-03 13:44 - 2013-02-04 15:38 - 00000000 ____D C:\Qoobox

2013-02-03 13:43 - 2013-02-04 16:01 - 00000000 ____D C:\Windows\erdnt

2013-02-02 11:54 - 2013-02-02 11:54 - 00000000 ____D C:\Users\Shawn.Michael-HP\Documents\ProcAlyzer Dumps

2013-02-02 11:10 - 2013-02-05 06:26 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2

2013-02-02 11:10 - 2009-01-25 12:14 - 00017272 ____A (Safer Networking Limited) C:\Windows\System32\sdnclean64.exe

2013-02-02 11:01 - 2013-02-02 11:09 - 55454464 ____A (Safer-Networking Ltd. ) C:\Users\Shawn.Michael-HP\Downloads\SpybotSD2.exe

2013-02-01 17:57 - 2009-06-10 13:00 - 00000824 ____A C:\Windows\System32\Drivers\etc\hosts.20130201-175706.backup

2013-02-01 17:53 - 2013-02-04 16:02 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy

2013-02-01 17:49 - 2013-02-01 17:49 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\digipen

2013-02-01 17:49 - 2013-02-01 17:49 - 00000000 ____D C:\Users\Lisa\AppData\Local\digipen

2013-02-01 16:06 - 2013-02-01 16:06 - 00000000 ____D C:\Users\Lisa\AppData\Local\MagicSoftware

2013-02-01 16:01 - 2013-02-01 16:01 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Sony Corporation

2013-02-01 12:05 - 2010-04-26 11:23 - 00058432 ____A (BSafe Online) C:\Windows\System32\Drivers\BsecFltr.sys

2013-02-01 12:05 - 2010-04-26 11:23 - 00049088 ____A (BSafe Online) C:\Windows\SysWOW64\Drivers\BsecFltr.sys

2013-02-01 12:05 - 2010-02-05 09:40 - 00021624 ____A C:\Windows\SysWOW64\Drivers\BSecACFltr.sys

2013-02-01 12:05 - 2010-02-03 09:57 - 00022832 ____A C:\Windows\System32\Drivers\BSecACFltr.sys

2013-02-01 11:56 - 2013-02-01 11:56 - 00000000 ____D C:\Users\Shawn.Michael-HP\Documents\Quicken

2013-02-01 11:56 - 2013-02-01 11:56 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-01-31 15:53 - 2013-01-31 15:53 - 03763526 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL-1.2.9.zip

2013-01-31 15:53 - 2013-01-31 15:53 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\SDL-1.2.9

2013-01-31 06:39 - 2013-01-31 06:40 - 29449790 ____A C:\Users\Shawn.Michael-HP\Downloads\rootfs.tar.bz2

2013-01-31 06:39 - 2013-01-31 06:39 - 01393192 ____A C:\Users\Shawn.Michael-HP\Downloads\zImage.tns

2013-01-30 20:28 - 2013-01-30 20:37 - 00000000 ____D C:\Users\Shawn.Michael-HP\HG

2013-01-30 20:21 - 2013-01-30 20:21 - 00000000 ____D C:\Program Files (x86)\Mercurial

2013-01-30 16:41 - 2013-01-30 16:53 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\snapshot (1)

2013-01-30 16:37 - 2013-01-30 16:39 - 15732283 ____A C:\Users\Shawn.Michael-HP\Downloads\snapshot (1).zip

2013-01-30 08:37 - 2013-01-30 08:37 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\snapshot

2013-01-30 07:53 - 2013-01-30 07:53 - 01837897 ____A C:\Users\Shawn.Michael-HP\Downloads\snapshot.zip

2013-01-29 20:50 - 2013-01-29 20:50 - 00002070 ____A C:\Users\Shawn.Michael-HP\Desktop\Assembly - Shortcut.lnk

2013-01-29 15:38 - 2013-01-29 15:38 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\Game

2013-01-29 15:36 - 2013-01-29 15:36 - 00000000 ____D C:\Program Files (x86)\Royal Defense

2013-01-29 12:45 - 2013-01-29 12:45 - 00000000 ____D C:\Users\Michael\Documents\2013_01_29

2013-01-29 12:38 - 2013-01-29 13:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-01-29 12:38 - 2013-01-29 12:38 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 12:38 - 2013-01-29 12:38 - 00000000 ____D C:\Users\All Users\Malwarebytes

2013-01-29 12:38 - 2012-12-14 16:49 - 00024176 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys

2013-01-28 17:49 - 2013-02-04 16:06 - 00000000 ____A C:\Windows\SysWOW64\config.nt

2013-01-28 17:49 - 2013-02-04 16:02 - 00000000 ____D C:\Users\All Users\AVAST Software

2013-01-28 17:49 - 2013-02-04 16:02 - 00000000 ____D C:\Program Files\AVAST Software

2013-01-28 17:49 - 2012-10-30 15:51 - 00984144 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys

2013-01-28 17:49 - 2012-10-30 15:51 - 00370288 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys

2013-01-28 17:49 - 2012-10-30 15:51 - 00071600 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys

2013-01-28 17:49 - 2012-10-30 15:51 - 00059728 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys

2013-01-28 17:49 - 2012-10-30 15:51 - 00041224 ____A (AVAST Software) C:\Windows\avastSS.scr

2013-01-28 17:49 - 2012-10-30 15:51 - 00025232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys

2013-01-28 17:49 - 2012-10-30 15:50 - 00285328 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe

2013-01-28 17:49 - 2012-10-30 15:50 - 00227648 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe

2013-01-28 17:49 - 2012-10-15 08:59 - 00054072 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr2.sys

2013-01-28 17:03 - 2013-01-28 17:07 - 00000000 ____D C:\Users\Michael\Documents\2013_01_28

2013-01-28 14:41 - 2013-01-28 14:41 - 00392961 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-1.2.7.zip

2013-01-28 14:41 - 2013-01-28 14:41 - 00024143 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-devel-1.2.7-VC8.zip

2013-01-28 12:46 - 2013-01-28 12:46 - 00032317 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-devel-1.2.8-VC.zip

2013-01-28 12:43 - 2013-01-28 12:43 - 00388380 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-1.2.8.zip

2013-01-28 12:42 - 2013-01-28 12:42 - 00010752 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-1.2.8-win32-x64.zip

2013-01-27 20:33 - 2013-01-27 20:33 - 00000000 ____A C:\Windows\SysWOW64\sho50B7.tmp

2013-01-27 15:39 - 2013-01-27 15:53 - 00000000 ____D C:\Program Files (x86)\Narbacular Drop

2013-01-27 15:39 - 2013-01-27 15:39 - 26853453 ____A ( ) C:\Users\Shawn.Michael-HP\Downloads\NarbacularDrop.exe

2013-01-27 15:39 - 2013-01-27 15:39 - 00000071 ____A C:\Windows\NARBACULARDROP.INI

2013-01-27 14:35 - 2013-01-27 14:35 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\GLSLDemo_v1.0

2013-01-27 14:28 - 2013-01-27 14:30 - 24079572 ____A C:\Users\Shawn.Michael-HP\Downloads\GLSLDemo_win32_v1.0.zip

2013-01-25 10:18 - 2013-01-25 10:18 - 00000000 ____D C:\Users\Michael\Documents\Sony PMB

2013-01-25 10:18 - 2013-01-25 10:18 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Sony Corporation

2013-01-25 07:48 - 2013-01-27 12:28 - 00000078 ____A C:\Users\Shawn.Michael-HP\Desktop\jeremiah.txt

2013-01-25 06:23 - 2013-01-25 06:23 - 00011154 ____A C:\Users\Shawn.Michael-HP\Documents\County Answers.xlsx

2013-01-25 06:09 - 2013-01-25 06:09 - 00016570 ____A C:\Users\Shawn.Michael-HP\.recently-used.xbel

2013-01-25 06:01 - 2013-01-25 06:01 - 00416611 ____A C:\Users\Shawn.Michael-HP\Downloads\Counties.xcf

2013-01-24 12:59 - 2013-01-24 13:11 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\bullet-2.67-win32-binaries

2013-01-24 12:08 - 2013-01-24 12:09 - 09180715 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.78.zip

2013-01-24 12:06 - 2013-01-24 12:07 - 09610255 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.79-rev2440.zip

2013-01-23 20:08 - 2013-01-23 20:10 - 08924563 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.81-rev2613 (2).zip

2013-01-23 20:07 - 2013-01-23 20:08 - 04445430 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.81-rev2613 (1).zip

2013-01-23 20:07 - 2013-01-23 20:07 - 03757854 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.81-rev2613.zip

2013-01-23 18:55 - 2013-01-23 18:56 - 00012288 __ASH C:\Users\Michael\Documents\Thumbs.db

2013-01-23 18:54 - 2013-01-23 18:54 - 00000000 ____D C:\Users\Michael\Desktop\2013_01_23

2013-01-21 11:35 - 2013-01-21 12:03 - 249690928 ____A (Microsoft Corporation) C:\Users\Patrick\Downloads\RiseOfNationsXTrial.exe

2013-01-20 19:37 - 2013-01-25 07:18 - 00000000 ____D C:\Users\Shawn.Michael-HP\Desktop\Island

2013-01-20 19:35 - 2013-01-20 19:35 - 00398890 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_mixer-devel-1.2.11-VC.zip

2013-01-20 17:26 - 2013-01-20 17:26 - 06620601 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_mixer-1.2.12.zip

2013-01-20 17:18 - 2013-01-20 17:18 - 00582383 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_mixer-1.2.12-win32-x64.zip

2013-01-20 16:44 - 2013-02-05 06:17 - 00000332 ____A C:\Windows\Tasks\HPCeeScheduleForShawn.job

2013-01-18 06:25 - 2013-01-12 03:30 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2013-01-18 06:25 - 2013-01-12 03:26 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2013-01-18 06:25 - 2013-01-12 03:24 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2013-01-18 06:24 - 2013-01-18 06:25 - 00003989 ____A C:\Windows\SysWOW64\jupdate-1.7.0_11-b21.log

2013-01-17 08:00 - 2013-01-17 08:00 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Motorola Mobility

2013-01-16 17:06 - 2013-01-16 17:08 - 53896621 ____A C:\Users\Shawn.Michael-HP\Downloads\Portal_Taste_The_Cake_Part_1.zip

2013-01-15 16:30 - 2013-01-15 16:41 - 235602472 ____A C:\Users\Patrick\Downloads\rexaura_1.2.zip

2013-01-15 12:04 - 2013-01-15 12:04 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\VirtualDub-1.9.11

2013-01-15 12:03 - 2013-01-15 12:03 - 01707366 ____A C:\Users\Shawn.Michael-HP\Downloads\VirtualDub-1.9.11.zip

2013-01-15 08:17 - 2013-01-15 13:23 - 00000087 ____A C:\Users\Shawn.Michael-HP\Downloads\PhotoLapse.ini

2013-01-15 08:14 - 2013-01-15 08:14 - 00155648 ____A (http://home.hccnet.nl/s.vd.palen) C:\Users\Shawn.Michael-HP\Downloads\PhotoLapse.exe

2013-01-15 08:06 - 2013-01-16 15:50 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\JPGs to AVI 2.1

2013-01-15 08:06 - 2013-01-15 08:06 - 00052798 ____A C:\Users\Shawn.Michael-HP\Downloads\JPGs to AVI 2.1.zip

2013-01-15 07:24 - 2013-01-15 07:24 - 00000000 ____D C:\Users\Patrick\AppData\Local\{A3125CF7-8E28-4C6E-B652-E639DA7B05AB}

2013-01-15 06:29 - 2013-01-28 14:42 - 00000000 ____D C:\Include

2013-01-15 06:24 - 2013-01-29 07:13 - 00000000 ____D C:\Users\Shawn.Michael-HP\Tutorial Projects

2013-01-15 06:21 - 2013-02-01 17:44 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-01-15 06:20 - 2013-01-15 06:21 - 00000000 ____D C:\Program Files (x86)\CodeBlocks

2013-01-15 06:17 - 2013-01-15 06:17 - 00800817 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL-devel-1.2.15-mingw32.tar.tar

2013-01-15 06:15 - 2013-01-15 06:19 - 100600973 ____A (The Code::Blocks Team) C:\Users\Shawn.Michael-HP\Downloads\codeblocks-12.11mingw-setup.exe

2013-01-14 20:29 - 2013-01-29 14:35 - 00000000 ____D C:\Users\Shawn.Michael-HP\Desktop\Pics

2013-01-12 12:44 - 2013-01-12 12:44 - 00000000 ____D C:\Users\Patrick\AppData\Local\{16C60D4A-13B9-4EE0-9BAC-356D8E6F48F3}

2013-01-11 07:55 - 2013-01-25 10:24 - 00000000 ____D C:\Users\Michael\Documents\2013_01_11

2013-01-09 20:32 - 2013-01-09 20:33 - 00262806 ____A C:\Windows\msxml4-KB2758694-enu.LOG

2013-01-09 15:39 - 2013-01-09 16:05 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-09 07:08 - 2012-12-07 05:20 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll

2013-01-09 07:08 - 2012-12-07 05:15 - 02746368 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll

2013-01-09 07:08 - 2012-12-07 04:26 - 00308736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll

2013-01-09 07:08 - 2012-12-07 04:20 - 02576384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll

2013-01-09 07:08 - 2012-12-07 03:20 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs

2013-01-09 07:08 - 2012-12-07 03:20 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs

2013-01-09 07:08 - 2012-12-07 03:20 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs

2013-01-09 07:08 - 2012-12-07 03:20 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs

2013-01-09 07:08 - 2012-12-07 03:20 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs

2013-01-09 07:08 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs

2013-01-09 07:08 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs

2013-01-09 07:08 - 2012-12-07 03:19 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs

2013-01-09 07:08 - 2012-12-07 03:19 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs

2013-01-09 07:08 - 2012-12-07 03:19 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs

2013-01-09 07:08 - 2012-12-07 03:19 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs

2013-01-09 07:08 - 2012-12-07 03:19 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs

2013-01-09 07:08 - 2012-12-07 03:19 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs

2013-01-09 07:08 - 2012-12-07 03:19 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00055296 ____A (Microsoft) C:\Windows\SysWOW64\cero.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00051712 ____A (Microsoft) C:\Windows\SysWOW64\esrb.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00046592 ____A (Microsoft) C:\Windows\SysWOW64\fpb.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00045568 ____A (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00044544 ____A (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00043520 ____A (Microsoft) C:\Windows\SysWOW64\csrr.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00040960 ____A (Microsoft) C:\Windows\SysWOW64\cob-au.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00030720 ____A (Microsoft) C:\Windows\SysWOW64\usk.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00023552 ____A (Microsoft) C:\Windows\SysWOW64\oflc.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00021504 ____A (Microsoft) C:\Windows\SysWOW64\grb.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi.rs

2013-01-09 07:08 - 2012-12-07 02:46 - 00015360 ____A (Microsoft) C:\Windows\SysWOW64\djctq.rs

2013-01-09 07:08 - 2012-11-29 21:45 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll

2013-01-09 07:08 - 2012-11-29 21:45 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll

2013-01-09 07:08 - 2012-11-29 21:45 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll

2013-01-09 07:08 - 2012-11-29 21:45 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll

2013-01-09 07:08 - 2012-11-29 21:43 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll

2013-01-09 07:08 - 2012-11-29 21:41 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll

2013-01-09 07:08 - 2012-11-29 21:41 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:54 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll

2013-01-09 07:08 - 2012-11-29 20:53 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll

2013-01-09 07:08 - 2012-11-29 20:53 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 19:23 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe

2013-01-09 07:08 - 2012-11-29 18:44 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe

2013-01-09 07:08 - 2012-11-29 18:44 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll

2013-01-09 07:08 - 2012-11-29 18:44 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe

2013-01-09 07:08 - 2012-11-29 18:44 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe

2013-01-09 07:08 - 2012-11-29 18:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 18:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 18:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 18:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll

2013-01-09 07:08 - 2012-11-29 15:17 - 00420064 ____A C:\Windows\SysWOW64\locale.nls

2013-01-09 07:08 - 2012-11-29 15:15 - 00420064 ____A C:\Windows\System32\locale.nls

2013-01-09 07:08 - 2012-11-21 21:44 - 00800768 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll

2013-01-09 07:08 - 2012-11-21 20:45 - 00626688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll

2013-01-09 07:08 - 2012-11-19 21:48 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll

2013-01-09 07:08 - 2012-11-19 20:51 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll

2013-01-09 07:08 - 2012-11-08 21:45 - 00750592 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll

2013-01-09 07:08 - 2012-11-08 20:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll

2013-01-09 07:08 - 2012-10-31 21:43 - 02002432 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll

2013-01-09 07:08 - 2012-10-31 21:43 - 01882624 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll

2013-01-09 07:08 - 2012-10-31 20:47 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll

2013-01-09 07:08 - 2012-10-31 20:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll

2013-01-09 07:07 - 2012-11-22 19:26 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

2013-01-09 07:07 - 2012-11-22 19:13 - 00068608 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe

==================== One Month Modified Files and Folders =======

2040-09-25 14:37 - 2040-09-25 14:37 - 00000000 ____D C:\Program Files (x86)\WinRAR

2040-08-24 12:34 - 2040-08-24 12:34 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-05 06:41 - 2013-02-05 06:41 - 00000000 ____D C:\FRST

2013-02-05 06:36 - 2012-04-08 18:42 - 00000000 ____D C:\Users\All Users\VMware

2013-02-05 06:36 - 2011-09-06 19:52 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-02-05 06:36 - 2011-08-13 17:10 - 00000000 ____D C:\Program Files (x86)\Steam

2013-02-05 06:36 - 2011-08-13 13:49 - 00000000 ____D C:\Program Files (x86)\Bsecure

2013-02-05 06:35 - 2013-02-04 16:04 - 00001018 ____A C:\Windows\setupact.log

2013-02-05 06:35 - 2011-10-25 11:44 - 00000000 ____D C:\Users\All Users\NVIDIA

2013-02-05 06:35 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT

2013-02-05 06:34 - 2011-01-05 19:16 - 01358980 ____A C:\Windows\WindowsUpdate.log

2013-02-05 06:34 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-02-05 06:34 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-02-05 06:33 - 2013-02-05 06:33 - 00004191 ____A C:\AdwCleaner[s1].txt

2013-02-05 06:33 - 2013-02-05 06:33 - 00004167 ____A C:\AdwCleaner[R3].txt

2013-02-05 06:33 - 2009-07-13 21:13 - 00788388 ____A C:\Windows\System32\PerfStringBackup.INI

2013-02-05 06:32 - 2013-02-05 06:32 - 00582119 ____A C:\Users\Shawn.Michael-HP\Downloads\adwcleaner.exe

2013-02-05 06:32 - 2011-09-06 19:52 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-02-05 06:26 - 2013-02-02 11:10 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2

2013-02-05 06:17 - 2013-01-20 16:44 - 00000332 ____A C:\Windows\Tasks\HPCeeScheduleForShawn.job

2013-02-04 19:42 - 2012-07-14 09:18 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003UA.job

2013-02-04 17:12 - 2013-02-04 17:12 - 00000159 ____A C:\Users\Patrick\Documents\RONTAP.txt

2013-02-04 17:06 - 2011-01-05 19:25 - 00000000 ____D C:\Users\All Users\PDFC

2013-02-04 16:59 - 2012-09-15 21:08 - 00000000 ___SD C:\Users\Patrick\Google Drive

2013-02-04 16:19 - 2013-02-04 16:19 - 00000000 ____A C:\vcredist.bmp

2013-02-04 16:17 - 2011-08-14 12:51 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log

2013-02-04 16:16 - 2012-06-03 15:21 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\HpUpdate

2013-02-04 16:16 - 2012-06-03 15:21 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\HP Support Assistant

2013-02-04 16:06 - 2013-01-28 17:49 - 00000000 ____A C:\Windows\SysWOW64\config.nt

2013-02-04 16:05 - 2012-07-15 11:19 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Local\LogMeIn Hamachi

2013-02-04 16:05 - 2011-08-14 16:19 - 00000000 ____D C:\users\Shawn.Michael-HP

2013-02-04 16:03 - 2012-06-20 16:53 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\Computer Repair

2013-02-04 16:03 - 2012-05-03 18:03 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\0ad

2013-02-04 16:03 - 2012-04-27 14:05 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\0ad

2013-02-04 16:03 - 2012-04-08 18:46 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\VMware

2013-02-04 16:03 - 2011-08-15 15:33 - 00000000 ____D C:\users\Lisa

2013-02-04 16:03 - 2011-08-13 13:58 - 00000000 ____D C:\users\Patrick

2013-02-04 16:03 - 2011-08-13 01:31 - 00000000 ____D C:\users\Michael

2013-02-04 16:03 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF

2013-02-04 16:03 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\AppCompat

2013-02-04 16:02 - 2013-02-01 17:53 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy

2013-02-04 16:02 - 2013-01-28 17:49 - 00000000 ____D C:\Users\All Users\AVAST Software

2013-02-04 16:02 - 2013-01-28 17:49 - 00000000 ____D C:\Program Files\AVAST Software

2013-02-04 16:02 - 2012-01-04 18:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2013-02-04 16:02 - 2011-08-30 16:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Games

2013-02-04 16:01 - 2013-02-03 13:43 - 00000000 ____D C:\Windows\erdnt

2013-02-04 16:01 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration

2013-02-04 15:47 - 2013-02-04 15:21 - 00010796 ____A C:\Users\Shawn.Michael-HP\Desktop\ComboFix.txt

2013-02-04 15:38 - 2013-02-04 15:38 - 00023019 ____A C:\ComboFix.txt

2013-02-04 15:38 - 2013-02-03 13:44 - 00000000 ____D C:\Qoobox

2013-02-04 15:07 - 2011-08-15 17:26 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Local\CrashDumps

2013-02-03 20:54 - 2011-08-14 07:35 - 00000000 ____D C:\Users\All Users\CanonIJPLM

2013-02-03 15:54 - 2013-02-03 15:53 - 23034922 ____A C:\Users\Shawn.Michael-HP\Downloads\planet_arnessk.zip

2013-02-02 15:10 - 2012-04-08 18:46 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Local\VMware

2013-02-02 14:05 - 2012-04-22 13:20 - 00000000 ____D C:\Users\Shawn.Michael-HP\.gimp-2.6

2013-02-02 11:54 - 2013-02-02 11:54 - 00000000 ____D C:\Users\Shawn.Michael-HP\Documents\ProcAlyzer Dumps

2013-02-02 11:09 - 2013-02-02 11:01 - 55454464 ____A (Safer-Networking Ltd. ) C:\Users\Shawn.Michael-HP\Downloads\SpybotSD2.exe

2013-02-02 10:23 - 2012-07-25 11:25 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\.techniclauncher

2013-02-01 21:17 - 2011-01-05 22:11 - 00600518 ____A C:\Windows\PFRO.log

2013-02-01 18:04 - 2009-07-13 18:34 - 00000938 ___RA C:\Windows\System32\Drivers\etc\hosts.20130202-115226.backup

2013-02-01 17:57 - 2009-07-13 18:34 - 00249971 ___RA C:\Windows\System32\Drivers\etc\hosts.20130201-180455.backup

2013-02-01 17:49 - 2013-02-01 17:49 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\digipen

2013-02-01 17:49 - 2013-02-01 17:49 - 00000000 ____D C:\Users\Lisa\AppData\Local\digipen

2013-02-01 17:44 - 2013-01-15 06:21 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-02-01 16:07 - 2011-08-15 15:38 - 00117576 ____A C:\Users\Lisa\AppData\Local\GDIPFONTCACHEV1.DAT

2013-02-01 16:06 - 2013-02-01 16:06 - 00000000 ____D C:\Users\Lisa\AppData\Local\MagicSoftware

2013-02-01 16:01 - 2013-02-01 16:01 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Sony Corporation

2013-02-01 16:00 - 2012-08-08 14:26 - 00000000 ____D C:\Users\Lisa\AppData\Local\LogMeIn Hamachi

2013-02-01 15:37 - 2012-07-16 14:51 - 00000000 ____D C:\Users\Patrick\AppData\Local\LogMeIn Hamachi

2013-02-01 13:02 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache

2013-02-01 12:25 - 2009-07-13 21:08 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT

2013-02-01 11:56 - 2013-02-01 11:56 - 00000000 ____D C:\Users\Shawn.Michael-HP\Documents\Quicken

2013-02-01 11:56 - 2013-02-01 11:56 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-02-01 06:42 - 2012-07-14 09:18 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003Core.job

2013-01-31 17:24 - 2011-12-22 16:45 - 00000000 ____D C:\Program Files (x86)\Life Quest

2013-01-31 16:57 - 2012-05-14 10:36 - 00000340 ____A C:\Windows\Tasks\HPCeeScheduleForPatrick.job

2013-01-31 15:53 - 2013-01-31 15:53 - 03763526 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL-1.2.9.zip

2013-01-31 15:53 - 2013-01-31 15:53 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\SDL-1.2.9

2013-01-31 07:14 - 2012-10-09 14:47 - 00000000 ____D C:\Users\Shawn.Michael-HP\Desktop\Ndless

2013-01-31 06:40 - 2013-01-31 06:39 - 29449790 ____A C:\Users\Shawn.Michael-HP\Downloads\rootfs.tar.bz2

2013-01-31 06:39 - 2013-01-31 06:39 - 01393192 ____A C:\Users\Shawn.Michael-HP\Downloads\zImage.tns

2013-01-30 20:37 - 2013-01-30 20:28 - 00000000 ____D C:\Users\Shawn.Michael-HP\HG

2013-01-30 20:21 - 2013-01-30 20:21 - 00000000 ____D C:\Program Files (x86)\Mercurial

2013-01-30 16:53 - 2013-01-30 16:41 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\snapshot (1)

2013-01-30 16:39 - 2013-01-30 16:37 - 15732283 ____A C:\Users\Shawn.Michael-HP\Downloads\snapshot (1).zip

2013-01-30 08:37 - 2013-01-30 08:37 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\snapshot

2013-01-30 08:34 - 2012-04-22 13:12 - 00000000 ____D C:\Program Files (x86)\SeaMonkey

2013-01-30 07:53 - 2013-01-30 07:53 - 01837897 ____A C:\Users\Shawn.Michael-HP\Downloads\snapshot.zip

2013-01-29 20:50 - 2013-01-29 20:50 - 00002070 ____A C:\Users\Shawn.Michael-HP\Desktop\Assembly - Shortcut.lnk

2013-01-29 20:05 - 2012-12-15 07:13 - 00255338 ____A C:\Users\Michael\Documents\Budget.xlsx

2013-01-29 16:15 - 2011-12-12 18:08 - 00000000 ____D C:\BigFishGamesCache

2013-01-29 15:38 - 2013-01-29 15:38 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\Game

2013-01-29 15:36 - 2013-01-29 15:36 - 00000000 ____D C:\Program Files (x86)\Royal Defense

2013-01-29 14:35 - 2013-01-14 20:29 - 00000000 ____D C:\Users\Shawn.Michael-HP\Desktop\Pics

2013-01-29 13:13 - 2013-01-29 12:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-01-29 12:45 - 2013-01-29 12:45 - 00000000 ____D C:\Users\Michael\Documents\2013_01_29

2013-01-29 12:38 - 2013-01-29 12:38 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 12:38 - 2013-01-29 12:38 - 00000000 ____D C:\Users\All Users\Malwarebytes

2013-01-29 07:21 - 2011-11-09 18:24 - 00000000 ____D C:\Windows\Minidump

2013-01-29 07:21 - 2011-01-05 22:11 - 00303757 ____N C:\Windows\Minidump\012913-21044-01.dmp

2013-01-29 07:13 - 2013-01-15 06:24 - 00000000 ____D C:\Users\Shawn.Michael-HP\Tutorial Projects

2013-01-28 17:07 - 2013-01-28 17:03 - 00000000 ____D C:\Users\Michael\Documents\2013_01_28

2013-01-28 14:42 - 2013-01-15 06:29 - 00000000 ____D C:\Include

2013-01-28 14:41 - 2013-01-28 14:41 - 00392961 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-1.2.7.zip

2013-01-28 14:41 - 2013-01-28 14:41 - 00024143 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-devel-1.2.7-VC8.zip

2013-01-28 12:46 - 2013-01-28 12:46 - 00032317 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-devel-1.2.8-VC.zip

2013-01-28 12:43 - 2013-01-28 12:43 - 00388380 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-1.2.8.zip

2013-01-28 12:42 - 2013-01-28 12:42 - 00010752 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_net-1.2.8-win32-x64.zip

2013-01-27 20:33 - 2013-01-27 20:33 - 00000000 ____A C:\Windows\SysWOW64\sho50B7.tmp

2013-01-27 15:53 - 2013-01-27 15:39 - 00000000 ____D C:\Program Files (x86)\Narbacular Drop

2013-01-27 15:39 - 2013-01-27 15:39 - 26853453 ____A ( ) C:\Users\Shawn.Michael-HP\Downloads\NarbacularDrop.exe

2013-01-27 15:39 - 2013-01-27 15:39 - 00000071 ____A C:\Windows\NARBACULARDROP.INI

2013-01-27 15:00 - 2011-12-01 17:05 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\digipen

2013-01-27 15:00 - 2011-11-30 14:44 - 00000000 ____D C:\Program Files (x86)\DigiPen

2013-01-27 14:35 - 2013-01-27 14:35 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\GLSLDemo_v1.0

2013-01-27 14:30 - 2013-01-27 14:28 - 24079572 ____A C:\Users\Shawn.Michael-HP\Downloads\GLSLDemo_win32_v1.0.zip

2013-01-27 12:28 - 2013-01-25 07:48 - 00000078 ____A C:\Users\Shawn.Michael-HP\Desktop\jeremiah.txt

2013-01-25 10:33 - 2012-12-23 16:33 - 00000340 ____A C:\Windows\Tasks\HPCeeScheduleForMichael.job

2013-01-25 10:24 - 2013-01-11 07:55 - 00000000 ____D C:\Users\Michael\Documents\2013_01_11

2013-01-25 10:18 - 2013-01-25 10:18 - 00000000 ____D C:\Users\Michael\Documents\Sony PMB

2013-01-25 10:18 - 2013-01-25 10:18 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Sony Corporation

2013-01-25 10:17 - 2012-08-01 16:58 - 00000000 ____D C:\Users\Michael\AppData\Roaming\NVIDIA

2013-01-25 10:16 - 2012-01-19 18:34 - 00000000 ____D C:\Users\Michael\Documents\Pict

2013-01-25 10:14 - 2012-07-25 15:07 - 00000000 ____D C:\Users\Michael\AppData\Local\LogMeIn Hamachi

2013-01-25 07:18 - 2013-01-20 19:37 - 00000000 ____D C:\Users\Shawn.Michael-HP\Desktop\Island

2013-01-25 07:14 - 2013-01-04 17:06 - 00000000 ____D C:\Users\Shawn.Michael-HP\Desktop\Mine - 1.4.6 V4

2013-01-25 06:23 - 2013-01-25 06:23 - 00011154 ____A C:\Users\Shawn.Michael-HP\Documents\County Answers.xlsx

2013-01-25 06:09 - 2013-01-25 06:09 - 00016570 ____A C:\Users\Shawn.Michael-HP\.recently-used.xbel

2013-01-25 06:05 - 2012-04-22 13:30 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\gtk-2.0

2013-01-25 06:01 - 2013-01-25 06:01 - 00416611 ____A C:\Users\Shawn.Michael-HP\Downloads\Counties.xcf

2013-01-24 13:11 - 2013-01-24 12:59 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\bullet-2.67-win32-binaries

2013-01-24 12:09 - 2013-01-24 12:08 - 09180715 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.78.zip

2013-01-24 12:07 - 2013-01-24 12:06 - 09610255 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.79-rev2440.zip

2013-01-23 20:10 - 2013-01-23 20:08 - 08924563 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.81-rev2613 (2).zip

2013-01-23 20:08 - 2013-01-23 20:07 - 04445430 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.81-rev2613 (1).zip

2013-01-23 20:07 - 2013-01-23 20:07 - 03757854 ____A C:\Users\Shawn.Michael-HP\Downloads\bullet-2.81-rev2613.zip

2013-01-23 18:56 - 2013-01-23 18:55 - 00012288 __ASH C:\Users\Michael\Documents\Thumbs.db

2013-01-23 18:54 - 2013-01-23 18:54 - 00000000 ____D C:\Users\Michael\Desktop\2013_01_23

2013-01-22 18:03 - 2012-08-08 11:38 - 00013603 ____A C:\Users\Shawn.Michael-HP\Documents\Scout Time Log.xlsx

2013-01-22 17:45 - 2011-08-17 14:20 - 00000000 ____D C:\Users\All Users\CanonIJ

2013-01-21 13:56 - 2012-09-07 18:29 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\.techniclauncher

2013-01-21 12:06 - 2011-08-15 15:20 - 00000000 ____D C:\Users\Patrick\Documents\My Games

2013-01-21 12:05 - 2012-03-20 14:41 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\Microsoft Games

2013-01-21 12:03 - 2013-01-21 11:35 - 249690928 ____A (Microsoft Corporation) C:\Users\Patrick\Downloads\RiseOfNationsXTrial.exe

2013-01-20 20:47 - 2011-11-03 13:16 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\Audacity

2013-01-20 19:35 - 2013-01-20 19:35 - 00398890 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_mixer-devel-1.2.11-VC.zip

2013-01-20 17:26 - 2013-01-20 17:26 - 06620601 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_mixer-1.2.12.zip

2013-01-20 17:18 - 2013-01-20 17:18 - 00582383 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL_mixer-1.2.12-win32-x64.zip

2013-01-20 14:21 - 2012-08-15 19:43 - 00000193 ____A C:\Windows\WORDPAD.INI

2013-01-18 06:25 - 2013-01-18 06:24 - 00003989 ____A C:\Windows\SysWOW64\jupdate-1.7.0_11-b21.log

2013-01-18 06:25 - 2012-02-20 13:19 - 00000000 ____D C:\Program Files (x86)\Java

2013-01-17 08:00 - 2013-01-17 08:00 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Motorola Mobility

2013-01-17 01:28 - 2011-08-13 13:46 - 00273840 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe

2013-01-16 17:08 - 2013-01-16 17:06 - 53896621 ____A C:\Users\Shawn.Michael-HP\Downloads\Portal_Taste_The_Cake_Part_1.zip

2013-01-16 15:50 - 2013-01-15 08:06 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\JPGs to AVI 2.1

2013-01-16 13:22 - 2011-09-10 17:58 - 00000000 ____D C:\tmp

2013-01-15 16:41 - 2013-01-15 16:30 - 235602472 ____A C:\Users\Patrick\Downloads\rexaura_1.2.zip

2013-01-15 13:23 - 2013-01-15 08:17 - 00000087 ____A C:\Users\Shawn.Michael-HP\Downloads\PhotoLapse.ini

2013-01-15 12:04 - 2013-01-15 12:04 - 00000000 ____D C:\Users\Shawn.Michael-HP\Downloads\VirtualDub-1.9.11

2013-01-15 12:03 - 2013-01-15 12:03 - 01707366 ____A C:\Users\Shawn.Michael-HP\Downloads\VirtualDub-1.9.11.zip

2013-01-15 08:14 - 2013-01-15 08:14 - 00155648 ____A (http://home.hccnet.nl/s.vd.palen) C:\Users\Shawn.Michael-HP\Downloads\PhotoLapse.exe

2013-01-15 08:06 - 2013-01-15 08:06 - 00052798 ____A C:\Users\Shawn.Michael-HP\Downloads\JPGs to AVI 2.1.zip

2013-01-15 07:24 - 2013-01-15 07:24 - 00000000 ____D C:\Users\Patrick\AppData\Local\{A3125CF7-8E28-4C6E-B652-E639DA7B05AB}

2013-01-15 06:21 - 2013-01-15 06:20 - 00000000 ____D C:\Program Files (x86)\CodeBlocks

2013-01-15 06:19 - 2013-01-15 06:15 - 100600973 ____A (The Code::Blocks Team) C:\Users\Shawn.Michael-HP\Downloads\codeblocks-12.11mingw-setup.exe

2013-01-15 06:17 - 2013-01-15 06:17 - 00800817 ____A C:\Users\Shawn.Michael-HP\Downloads\SDL-devel-1.2.15-mingw32.tar.tar

2013-01-12 12:44 - 2013-01-12 12:44 - 00000000 ____D C:\Users\Patrick\AppData\Local\{16C60D4A-13B9-4EE0-9BAC-356D8E6F48F3}

2013-01-12 12:21 - 2012-06-13 12:24 - 00000000 ____D C:\Program Files (x86)\MuLab

2013-01-12 07:34 - 2012-03-31 19:11 - 00697864 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2013-01-12 07:34 - 2011-08-23 10:06 - 00074248 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2013-01-12 03:30 - 2013-01-18 06:25 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2013-01-12 03:26 - 2013-01-18 06:25 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe

2013-01-12 03:24 - 2013-01-18 06:25 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe

2013-01-10 16:02 - 2011-09-14 09:02 - 00000346 ____A C:\Windows\Tasks\HPCeeScheduleForMICHAEL-HP$.job

2013-01-10 06:26 - 2009-07-13 20:45 - 00471848 ____A C:\Windows\System32\FNTCACHE.DAT

2013-01-09 20:42 - 2011-08-15 13:24 - 00784608 ____A C:\Windows\SysWOW64\PerfStringBackup.INI

2013-01-09 20:37 - 2011-08-14 06:52 - 67599240 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

2013-01-09 20:34 - 2011-08-22 14:19 - 00000000 ____D C:\Users\All Users\Microsoft Help

2013-01-09 20:33 - 2013-01-09 20:32 - 00262806 ____A C:\Windows\msxml4-KB2758694-enu.LOG

2013-01-09 16:05 - 2013-01-09 15:39 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-08 16:14 - 2013-01-05 19:09 - 00000000 ____D C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans

2013-01-08 14:35 - 2012-04-29 14:27 - 00000000 ____D C:\Users\Shawn.Michael-HP\Desktop\Unification Project

==================== Known DLLs (Whitelisted) =================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK

HKLM\...\exefile\DefaultIcon: %1 => OK

HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-02-02 14:50:56

Restore point made on: 2013-02-03 13:33:23

Restore point made on: 2013-02-03 14:26:04

Restore point made on: 2013-02-04 06:36:16

Restore point made on: 2013-02-04 15:50:00

==================== Memory info ===========================

Percentage of memory in use: 12%

Total physical RAM: 8174.54 MB

Available physical RAM: 7147.84 MB

Total Pagefile: 8172.69 MB

Available Pagefile: 7128.67 MB

Total Virtual: 8192 MB

Available Virtual: 8191.9 MB

==================== Partitions =============================

1 Drive c: (OS) (Fixed) (Total:1849.96 GB) (Free:1275.05 GB) NTFS

2 Drive e: (HP_RECOVERY) (Fixed) (Total:12.96 GB) (Free:1.59 GB) NTFS ==>[system with boot components (obtained from reading drive)]

4 Drive g: () (Removable) (Total:0.98 GB) (Free:0.97 GB) FAT

9 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

10 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt

-------- ------------- ------- ------- --- ---

Disk 0 Online 1863 GB 0 B

Disk 1 Online 999 MB 0 B

Disk 2 No Media 0 B 0 B

Disk 3 No Media 0 B 0 B

Disk 4 No Media 0 B 0 B

Disk 5 No Media 0 B 0 B

Partitions of Disk 0:

===============

Disk ID: 40B3A861

Partition ### Type Size Offset

------------- ---------------- ------- -------

Partition 1 Primary 100 MB 1024 KB

Partition 2 Primary 1849 GB 101 MB

Partition 3 Primary 12 GB 1850 GB

==================================================================================

Disk: 0

Partition 1

Type : 07

Hidden: No

Active: Yes

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy

=========================================================

Disk: 0

Partition 2

Type : 07

Hidden: No

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 2 C OS NTFS Partition 1849 GB Healthy

=========================================================

Disk: 0

Partition 3

Type : 07

Hidden: No

Active: No

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 3 E HP_RECOVERY NTFS Partition 12 GB Healthy

=========================================================

Partitions of Disk 1:

===============

Disk ID: 002112FA

Partition ### Type Size Offset

------------- ---------------- ------- -------

Partition 1 Primary 998 MB 16 KB

==================================================================================

Disk: 1

Partition 1

Type : 06

Hidden: No

Active: Yes

Volume ### Ltr Label Fs Type Size Status Info

---------- --- ----------- ----- ---------- ------- --------- --------

* Volume 4 G FAT Removable 998 MB Healthy

=========================================================

Last Boot: 2013-02-03 12:46

==================== End Of Log =============================

Link to post
Share on other sites

Good morning QubicComputers. :)

Please run this tool.

Please download OTL.exe by OldTimer to your Desktop.

  • Close all windows and double click OTL.exe.
  • In the "Custom Scans/Fixes" window (under the light green bar) paste the following in bold:

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click Run Scan and let the program run uninterrupted.
  • When the scan completes, it will open two Notepad windows. OTL.txt and Extras.txt. These are saved in the same location as OTL. Post both logs in this thread.
  • You may need to use two posts to get it all.

Link to post
Share on other sites

Here are the two logs:

OTL logfile created on: 2/5/2013 2:27:16 PM - Run 1

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Shawn.Michael-HP\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.98 Gb Total Physical Memory | 5.57 Gb Available Physical Memory | 69.82% Memory free

15.96 Gb Paging File | 13.40 Gb Available in Paging File | 83.96% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 1849.96 Gb Total Space | 1274.39 Gb Free Space | 68.89% Space Free | Partition Type: NTFS

Drive D: | 12.96 Gb Total Space | 1.59 Gb Free Space | 12.29% Space Free | Partition Type: NTFS

Computer Name: MICHAEL-HP | User Name: Shawn | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/02/05 14:24:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Shawn.Michael-HP\Desktop\OTL.exe

PRC - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

PRC - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

PRC - [2012/12/14 16:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

PRC - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

PRC - [2012/12/03 14:46:59 | 001,354,736 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe

PRC - [2012/10/30 15:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe

PRC - [2012/10/30 15:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe

PRC - [2012/10/02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

PRC - [2012/07/17 12:31:18 | 000,776,088 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe

PRC - [2012/07/17 12:31:18 | 000,116,632 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe

PRC - [2012/01/18 14:47:28 | 000,433,264 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe

PRC - [2012/01/18 14:47:20 | 000,354,416 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe

PRC - [2012/01/18 12:27:20 | 000,079,872 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe

PRC - [2011/12/23 09:35:08 | 000,181,312 | ---- | M] () -- C:\Program Files (x86)\Photodex\ProShow\scsiaccess.exe

PRC - [2011/10/01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

PRC - [2011/10/01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

PRC - [2011/08/19 19:51:48 | 000,423,536 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe

PRC - [2011/08/19 19:32:40 | 000,423,536 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe

PRC - [2011/06/25 08:59:55 | 000,161,776 | ---- | M] (Bsecure Technologies, Inc.) -- C:\Program Files (x86)\Bsecure\BsecAV.exe

PRC - [2011/06/25 08:59:34 | 000,096,040 | ---- | M] (Bsecure Technologies, Inc.) -- C:\Program Files (x86)\Bsecure\BsecTray.exe

PRC - [2011/06/25 08:59:34 | 000,066,344 | ---- | M] (Bsecure Technologies, Inc.) -- C:\Program Files (x86)\Bsecure\InetCtrl.exe

PRC - [2011/06/25 08:59:34 | 000,022,824 | ---- | M] () -- C:\Program Files (x86)\Bsecure\BsecAMX.exe

PRC - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

PRC - [2010/11/27 00:55:42 | 000,648,032 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

PRC - [2010/11/27 00:55:42 | 000,398,176 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

PRC - [2010/10/05 06:08:46 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

PRC - [2010/10/05 06:08:42 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

PRC - [2010/09/28 08:09:28 | 001,119,768 | ---- | M] (PDF Complete Inc) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe

PRC - [2009/05/19 16:11:52 | 000,136,544 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe

PRC - [2008/11/20 10:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe

========== Modules (No Company Name) ==========

MOD - [2013/01/17 17:48:02 | 000,647,168 | ---- | M] () -- C:\Program Files (x86)\Steam\sdl.dll

MOD - [2013/01/17 17:47:52 | 020,320,240 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll

MOD - [2013/01/17 17:47:52 | 001,100,800 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll

MOD - [2013/01/17 17:47:52 | 000,969,640 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll

MOD - [2013/01/17 17:47:52 | 000,192,000 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll

MOD - [2013/01/17 17:47:52 | 000,124,416 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll

MOD - [2012/07/17 12:31:18 | 000,776,088 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe

MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

MOD - [2011/06/25 08:59:34 | 000,022,824 | ---- | M] () -- C:\Program Files (x86)\Bsecure\BsecAMX.exe

========== Services (SafeList) ==========

SRV:64bit: - [2012/10/30 15:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)

SRV:64bit: - [2011/11/09 01:22:22 | 000,301,720 | ---- | M] () [Auto | Running] -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService.exe)

SRV:64bit: - [2011/06/24 01:23:14 | 000,302,592 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)

SRV:64bit: - [2010/11/23 09:21:52 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:64bit: - [2010/08/05 19:51:08 | 000,291,896 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)

SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/03/02 17:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)

SRV - [2012/12/18 06:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)

SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)

SRV - [2012/12/10 17:29:46 | 002,465,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)

SRV - [2012/10/24 07:49:46 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)

SRV - [2012/10/10 21:23:42 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)

SRV - [2012/10/02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2012/07/17 12:31:18 | 000,116,632 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager)

SRV - [2012/01/18 14:47:28 | 000,433,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)

SRV - [2012/01/18 14:47:20 | 000,354,416 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)

SRV - [2012/01/18 14:04:52 | 011,839,488 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe -- (VMwareHostd)

SRV - [2012/01/18 12:27:20 | 000,079,872 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)

SRV - [2011/12/23 09:35:08 | 000,181,312 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Photodex\ProShow\scsiaccess.exe -- (ScsiAccess)

SRV - [2011/10/01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)

SRV - [2011/10/01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)

SRV - [2011/09/09 16:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)

SRV - [2011/09/02 15:06:38 | 000,065,657 | ---- | M] (Motorola) [Disabled | Stopped] -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service)

SRV - [2011/08/29 21:11:04 | 000,846,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)

SRV - [2011/08/19 19:51:48 | 000,423,536 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe -- (vmware-converter-worker)

SRV - [2011/08/19 19:51:48 | 000,423,536 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe -- (vmware-converter-server)

SRV - [2011/08/19 19:32:40 | 000,423,536 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe -- (vmware-converter-agent)

SRV - [2011/06/25 08:59:55 | 000,161,776 | ---- | M] (Bsecure Technologies, Inc.) [Auto | Running] -- C:\Program Files (x86)\Bsecure\BsecAV.exe -- (BsecureAV)

SRV - [2011/06/25 08:59:34 | 000,066,344 | ---- | M] (Bsecure Technologies, Inc.) [Auto | Running] -- C:\Program Files (x86)\Bsecure\InetCtrl.exe -- (Bsecure)

SRV - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)

SRV - [2010/11/27 00:55:42 | 000,398,176 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)

SRV - [2010/11/25 20:20:28 | 000,245,232 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe -- (CLKMSVC10_C6F09094)

SRV - [2010/10/12 09:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)

SRV - [2010/10/05 06:08:46 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)

SRV - [2010/10/05 06:08:42 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)

SRV - [2010/09/28 08:09:28 | 001,119,768 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)

SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2009/06/10 13:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2009/02/09 23:01:49 | 000,116,104 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)

SRV - [2007/05/31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)

SRV - [2007/05/31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)

========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)

DRV:64bit: - [2012/10/30 15:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)

DRV:64bit: - [2012/10/30 15:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)

DRV:64bit: - [2012/10/30 15:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)

DRV:64bit: - [2012/10/30 15:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)

DRV:64bit: - [2012/10/30 15:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV:64bit: - [2012/10/15 08:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)

DRV:64bit: - [2012/06/11 10:56:34 | 000,022,016 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\motccgp.sys -- (motccgp)

DRV:64bit: - [2012/06/08 15:08:28 | 000,031,232 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\motport.sys -- (motport)

DRV:64bit: - [2012/06/08 15:08:28 | 000,031,232 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\motmodem.sys -- (motmodem)

DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2012/01/25 13:57:46 | 000,009,728 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\motccgpfl.sys -- (motccgpfl)

DRV:64bit: - [2012/01/18 14:47:44 | 000,063,088 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)

DRV:64bit: - [2012/01/18 14:46:18 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)

DRV:64bit: - [2012/01/18 12:06:00 | 000,045,680 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)

DRV:64bit: - [2012/01/18 12:06:00 | 000,020,080 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)

DRV:64bit: - [2011/10/01 08:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)

DRV:64bit: - [2011/10/01 08:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)

DRV:64bit: - [2011/10/01 08:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)

DRV:64bit: - [2011/10/01 08:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)

DRV:64bit: - [2011/09/02 21:29:54 | 000,019,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)

DRV:64bit: - [2011/09/02 21:29:52 | 000,013,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)

DRV:64bit: - [2011/08/29 21:11:04 | 000,039,024 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)

DRV:64bit: - [2011/08/29 21:01:10 | 000,037,680 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb)

DRV:64bit: - [2011/08/08 13:59:12 | 000,116,336 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)

DRV:64bit: - [2011/06/09 17:35:04 | 000,528,384 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)

DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2010/11/29 05:31:18 | 001,579,520 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)

DRV:64bit: - [2010/11/23 09:53:44 | 007,886,848 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)

DRV:64bit: - [2010/11/23 08:46:42 | 000,285,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2010/11/20 03:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)

DRV:64bit: - [2010/11/20 02:49:51 | 000,146,432 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rmcast.sys -- (RMCAST)

DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010/09/24 07:46:32 | 000,116,752 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)

DRV:64bit: - [2010/09/13 05:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)

DRV:64bit: - [2010/09/02 22:59:26 | 000,349,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2010/08/25 18:39:00 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\prwntdrv.sys -- (prwntdrv)

DRV:64bit: - [2010/04/26 11:23:30 | 000,058,432 | ---- | M] (BSafe Online) [File_System | Boot | Unknown] -- C:\Windows\SysNative\drivers\BsecFltr.sys -- (BsecureFilter)

DRV:64bit: - [2010/03/29 16:31:18 | 000,142,848 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tinspusb.sys -- (USBTINSP)

DRV:64bit: - [2010/03/01 12:59:50 | 000,024,376 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cqcpu.sys -- (cqcpu)

DRV:64bit: - [2010/03/01 12:59:50 | 000,024,376 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cpqdfw.sys -- (CpqDfw)

DRV:64bit: - [2010/02/03 09:57:21 | 000,022,832 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\BSecACFltr.sys -- (BSecACFltr)

DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/13 16:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)

DRV:64bit: - [2009/07/13 16:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)

DRV:64bit: - [2009/07/13 16:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)

DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)

DRV:64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)

DRV:64bit: - [2008/06/14 10:26:50 | 000,057,312 | ---- | M] (Ray Hinchliffe) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SIVX64.sys -- (SIVDRIVER)

DRV:64bit: - [2007/02/17 23:22:48 | 000,296,816 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\VMM.sys -- (vmm)

DRV:64bit: - [2007/01/29 05:20:34 | 000,079,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMNetSrv.sys -- (VPCNetS2)

DRV - [2010/08/25 18:39:00 | 000,013,704 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\prwntdrv.sys -- (prwntdrv)

DRV - [2010/04/26 11:23:50 | 000,049,088 | ---- | M] (BSafe Online) [File_System | Boot | Unknown] -- C:\Windows\SysWOW64\drivers\BsecFltr.sys -- (BsecureFilter)

DRV - [2010/02/05 09:40:12 | 000,021,624 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\BSecACFltr.sys -- (BSecACFltr)

DRV - [2009/07/13 17:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =

IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF

IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}

IE:64bit: - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2357-0/4?satitle={searchTerms}&mfe=Desktops

IE:64bit: - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com

IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF

IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}

IE - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2357-0/4?satitle={searchTerms}&mfe=Desktops

IE - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKCU\..\SearchScopes,DefaultScope = {ec29edf6-ad3c-4e1c-a087-d6cb81400c43}

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/02/04 16:05:11 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/16 09:03:42 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 1.1.11\Extensions\\Components: C:\Program Files (x86)\mozilla.org\SeaMonkey\Components [2012/12/16 09:03:43 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 1.1.11\Extensions\\Plugins: C:\Program Files (x86)\mozilla.org\SeaMonkey\Plugins [2013/01/15 06:11:38 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.9.1\extensions\\Components: C:\Program Files (x86)\SeaMonkey\components [2012/12/16 09:03:43 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.9.1\extensions\\Plugins: C:\Program Files (x86)\SeaMonkey\plugins

FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey 1.1.11\Extensions\\Components: C:\Program Files (x86)\mozilla.org\SeaMonkey\Components [2012/12/16 09:03:43 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey 1.1.11\Extensions\\Plugins: C:\Program Files (x86)\mozilla.org\SeaMonkey\Plugins [2013/01/15 06:11:38 | 000,000,000 | ---D | M]

[2012/04/22 13:12:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Shawn.Michael-HP\AppData\Roaming\mozilla\Extensions

[2012/10/10 08:03:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Shawn.Michael-HP\AppData\Roaming\mozilla\SeaMonkey\Profiles\zgzv74xf.default\extensions

[2012/10/10 08:03:34 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Shawn.Michael-HP\AppData\Roaming\mozilla\SeaMonkey\Profiles\zgzv74xf.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}

[2012/09/09 16:43:55 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Users\Shawn.Michael-HP\AppData\Roaming\mozilla\SeaMonkey\Profiles\zgzv74xf.default\extensions\inspector@mozilla.org

[2012/12/02 14:11:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2012/11/29 00:27:51 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2012/11/29 00:27:12 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

[2012/11/29 00:27:12 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2013/02/02 11:52:26 | 000,444,830 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 www.007guard.com

O1 - Hosts: 127.0.0.1 007guard.com

O1 - Hosts: 127.0.0.1 008i.com

O1 - Hosts: 127.0.0.1 www.008k.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 www.00hq.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 010402.com

O1 - Hosts: 127.0.0.1 www.032439.com

O1 - Hosts: 127.0.0.1 032439.com

O1 - Hosts: 127.0.0.1 www.0scan.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 www.1000gratisproben.com

O1 - Hosts: 127.0.0.1 1000gratisproben.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 www.1001namen.com

O1 - Hosts: 127.0.0.1 100888290cs.com

O1 - Hosts: 127.0.0.1 www.100888290cs.com

O1 - Hosts: 127.0.0.1 www.100sexlinks.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 www.10sek.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 www.1-2005-search.com

O1 - Hosts: 127.0.0.1 1-2005-search.com

O1 - Hosts: 127.0.0.1 www.123fporn.info

O1 - Hosts: 15276 more lines...

O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)

O2:64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)

O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)

O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)

O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)

O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.

O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)

O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)

O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)

O4:64bit: - HKLM..\Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)

O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)

O4 - HKLM..\Run: [CloudCare] C:\Program Files (x86)\Bsecure\BsecTray.exe (Bsecure Technologies, Inc.)

O4 - HKLM..\Run: [iJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)

O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)

O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)

O4 - HKCU..\Run: [steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)

O4 - Startup: C:\Users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Egg Timer.exe - Shortcut.lnk = C:\Program Files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe (Qube Software)

O4 - Startup: C:\Users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\note.txt ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)

O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000027 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000028 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)

O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000029 - C:\Program Files\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files (x86)\Bsecure\InetCtrl57.dll (Bsecure Technologies, Inc.)

O1364bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.5.0)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Reg Error: Value error.)

O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.13.2)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A35758A6-7465-4C0F-997C-3651CED8C8D2}: DhcpNameServer = 192.168.0.1 205.171.3.25

O18:64bit: - Protocol\Handler\livecall - No CLSID value found

O18:64bit: - Protocol\Handler\ms-help - No CLSID value found

O18:64bit: - Protocol\Handler\msnim - No CLSID value found

O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found

O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

Drivers32: VIDC.VMnc - C:\Windows\SysWow64\vmnc.dll (VMware, Inc.)

CREATERESTOREPOINT

Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2040/09/25 14:37:10 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

[2040/09/25 14:37:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR

[2040/09/25 14:37:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR

[2040/08/24 12:34:18 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Roaming\WinBatch

[2013/02/05 14:24:41 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Shawn.Michael-HP\Desktop\OTL.exe

[2013/02/05 07:16:10 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

[2013/02/05 07:15:16 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe

[2013/02/05 06:41:41 | 000,000,000 | ---D | C] -- C:\FRST

[2013/02/03 13:44:08 | 000,000,000 | ---D | C] -- C:\Qoobox

[2013/02/03 13:43:28 | 000,000,000 | ---D | C] -- C:\Windows\erdnt

[2013/02/02 11:54:49 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\Documents\ProcAlyzer Dumps

[2013/02/02 11:10:25 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe

[2013/02/02 11:10:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2

[2013/02/01 17:53:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy

[2013/02/01 12:05:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Microsoft Shared

[2013/02/01 12:05:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bsecure Endpoint Security

[2013/02/01 12:05:26 | 000,058,432 | ---- | C] (BSafe Online) -- C:\Windows\SysNative\drivers\BsecFltr.sys

[2013/02/01 12:05:26 | 000,049,088 | ---- | C] (BSafe Online) -- C:\Windows\SysWow64\drivers\BsecFltr.sys

[2013/02/01 11:56:36 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\Documents\Quicken

[2013/02/01 11:56:34 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Roaming\Intuit

[2013/01/30 20:28:57 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\HG

[2013/01/30 20:21:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mercurial 2.5.0

[2013/01/30 20:21:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mercurial

[2013/01/29 15:36:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Royal Defense

[2013/01/29 15:36:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Royal Defense

[2013/01/29 12:43:58 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Local\Programs

[2013/01/29 12:38:09 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

[2013/01/29 12:38:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2013/01/29 12:38:04 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2013/01/29 12:38:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2013/01/29 12:38:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2013/01/28 17:49:44 | 000,370,288 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys

[2013/01/28 17:49:44 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys

[2013/01/28 17:49:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus

[2013/01/28 17:49:43 | 000,984,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys

[2013/01/28 17:49:43 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys

[2013/01/28 17:49:43 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys

[2013/01/28 17:49:42 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe

[2013/01/28 17:49:42 | 000,071,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys

[2013/01/28 17:49:13 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe

[2013/01/28 17:49:13 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr

[2013/01/28 17:49:06 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software

[2013/01/28 17:49:06 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software

[2013/01/27 15:39:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Narbacular Drop

[2013/01/27 15:39:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Narbacular Drop

[2013/01/20 19:37:38 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\Desktop\Island

[2013/01/18 06:25:58 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe

[2013/01/18 06:25:58 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe

[2013/01/15 06:29:46 | 000,000,000 | ---D | C] -- C:\Include

[2013/01/15 06:24:52 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\Tutorial Projects

[2013/01/15 06:21:36 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

[2013/01/15 06:20:58 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks

[2013/01/15 06:20:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks

[2013/01/15 06:20:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CodeBlocks

[2013/01/14 20:29:23 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\Desktop\Pics

[2013/01/09 15:39:00 | 000,000,000 | ---D | C] -- C:\Users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

[2013/01/09 07:08:42 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll

[2013/01/09 07:08:42 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll

[2013/01/09 07:08:42 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll

[2013/01/09 07:08:42 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe

[2013/01/09 07:08:42 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll

[2013/01/09 07:08:42 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll

[2013/01/09 07:08:42 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll

[2013/01/09 07:08:42 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll

[2013/01/09 07:08:42 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll

[2013/01/09 07:08:42 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll

[2013/01/09 07:08:42 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll

[2013/01/09 07:08:42 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll

[2013/01/09 07:08:42 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll

[2013/01/09 07:08:42 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll

[2013/01/09 07:08:42 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll

[2013/01/09 07:08:42 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll

[2013/01/09 07:08:41 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe

[2013/01/09 07:08:41 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe

[2013/01/09 07:08:41 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

[2013/01/09 07:08:41 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

[2013/01/09 07:08:41 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll

[2013/01/09 07:08:41 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll

[2013/01/09 07:08:41 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll

[2013/01/09 07:08:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe

[2013/01/09 07:08:35 | 000,750,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll

[2013/01/09 07:08:35 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll

[2013/01/09 07:08:25 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll

[2013/01/09 07:08:25 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll

[2013/01/09 07:08:24 | 002,746,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gameux.dll

[2013/01/09 07:08:24 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gameux.dll

[2013/01/09 07:08:24 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wpc.dll

[2013/01/09 07:08:24 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wpc.dll

[2013/01/09 07:08:24 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cero.rs

[2013/01/09 07:08:24 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cero.rs

[2013/01/09 07:08:24 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\esrb.rs

[2013/01/09 07:08:24 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysNative\esrb.rs

[2013/01/09 07:08:24 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\fpb.rs

[2013/01/09 07:08:24 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysNative\fpb.rs

[2013/01/09 07:08:24 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc-nz.rs

[2013/01/09 07:08:24 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc-nz.rs

[2013/01/09 07:08:24 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegibbfc.rs

[2013/01/09 07:08:24 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegibbfc.rs

[2013/01/09 07:08:24 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\csrr.rs

[2013/01/09 07:08:24 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysNative\csrr.rs

[2013/01/09 07:08:24 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cob-au.rs

[2013/01/09 07:08:24 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cob-au.rs

[2013/01/09 07:08:24 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\usk.rs

[2013/01/09 07:08:24 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysNative\usk.rs

[2013/01/09 07:08:24 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc.rs

[2013/01/09 07:08:24 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc.rs

[2013/01/09 07:08:24 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\grb.rs

[2013/01/09 07:08:24 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysNative\grb.rs

[2013/01/09 07:08:24 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-pt.rs

[2013/01/09 07:08:24 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-pt.rs

[2013/01/09 07:08:24 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-fi.rs

[2013/01/09 07:08:24 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-fi.rs

[2013/01/09 07:08:24 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi.rs

[2013/01/09 07:08:24 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi.rs

[2013/01/09 07:08:24 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\djctq.rs

[2013/01/09 07:08:24 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysNative\djctq.rs

[2013/01/09 07:07:52 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskhost.exe

[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/05 14:25:47 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2013/02/05 14:25:47 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2013/02/05 14:24:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Shawn.Michael-HP\Desktop\OTL.exe

[2013/02/05 14:20:40 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2013/02/05 14:17:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2013/02/05 14:17:50 | 2133,753,855 | -HS- | M] () -- C:\hiberfil.sys

[2013/02/05 07:42:00 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003UA.job

[2013/02/05 07:32:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2013/02/05 07:16:07 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

[2013/02/05 07:16:06 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll

[2013/02/05 07:16:06 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll

[2013/02/05 07:16:06 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe

[2013/02/05 07:16:06 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe

[2013/02/05 07:16:06 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe

[2013/02/05 06:33:32 | 000,788,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2013/02/05 06:33:32 | 000,668,030 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2013/02/05 06:33:32 | 000,124,206 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2013/02/05 06:17:18 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForShawn.job

[2013/02/04 16:19:27 | 000,000,000 | ---- | M] () -- C:\vcredist.bmp

[2013/02/04 16:06:13 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt

[2013/02/02 11:52:26 | 000,444,830 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts

[2013/02/01 18:04:55 | 000,000,938 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20130202-115226.backup

[2013/02/01 17:57:06 | 000,249,971 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20130201-180455.backup

[2013/02/01 06:42:00 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003Core.job

[2013/01/31 16:57:03 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForPatrick.job

[2013/01/29 20:50:29 | 000,002,070 | ---- | M] () -- C:\Users\Shawn.Michael-HP\Desktop\Assembly - Shortcut.lnk

[2013/01/29 14:34:59 | 001,956,895 | ---- | M] () -- C:\Users\Shawn.Michael-HP\Documents\512-927_fillable.pdf

[2013/01/29 13:44:41 | 001,924,456 | ---- | M] () -- C:\Users\Shawn.Michael-HP\Documents\S-Eagle Scout.pdf

[2013/01/27 15:39:37 | 000,000,071 | ---- | M] () -- C:\Windows\NARBACULARDROP.INI

[2013/01/25 10:33:22 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForMichael.job

[2013/01/25 06:09:35 | 000,016,570 | ---- | M] () -- C:\Users\Shawn.Michael-HP\.recently-used.xbel

[2013/01/22 18:03:04 | 001,955,512 | ---- | M] () -- C:\Users\Shawn.Michael-HP\Documents\ShawnFinalPlanEagle.pdf

[2013/01/20 14:21:35 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI

[2013/01/15 06:20:58 | 000,001,077 | ---- | M] () -- C:\Users\Shawn.Michael-HP\Application Data\Microsoft\Internet Explorer\Quick Launch\CodeBlocks.lnk

[2013/01/12 07:34:18 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe

[2013/01/12 07:34:18 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

[2013/01/10 16:02:03 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForMICHAEL-HP$.job

[2013/01/10 06:26:42 | 000,471,848 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2013/01/09 20:42:55 | 000,784,608 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/02/04 16:19:27 | 000,000,000 | ---- | C] () -- C:\vcredist.bmp

[2013/02/01 12:05:26 | 000,022,832 | ---- | C] () -- C:\Windows\SysNative\drivers\BSecACFltr.sys

[2013/02/01 12:05:26 | 000,021,624 | ---- | C] () -- C:\Windows\SysWow64\drivers\BSecACFltr.sys

[2013/01/29 20:50:29 | 000,002,070 | ---- | C] () -- C:\Users\Shawn.Michael-HP\Desktop\Assembly - Shortcut.lnk

[2013/01/29 13:24:05 | 001,924,456 | ---- | C] () -- C:\Users\Shawn.Michael-HP\Documents\S-Eagle Scout.pdf

[2013/01/28 17:49:42 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt

[2013/01/27 15:39:37 | 000,000,071 | ---- | C] () -- C:\Windows\NARBACULARDROP.INI

[2013/01/25 06:09:35 | 000,016,570 | ---- | C] () -- C:\Users\Shawn.Michael-HP\.recently-used.xbel

[2013/01/22 18:03:04 | 001,955,512 | ---- | C] () -- C:\Users\Shawn.Michael-HP\Documents\ShawnFinalPlanEagle.pdf

[2013/01/20 16:44:13 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\HPCeeScheduleForShawn.job

[2013/01/15 06:20:58 | 000,001,077 | ---- | C] () -- C:\Users\Shawn.Michael-HP\Application Data\Microsoft\Internet Explorer\Quick Launch\CodeBlocks.lnk

[2012/12/29 08:40:24 | 168,279,073 | ---- | C] () -- C:\Users\Shawn.Michael-HP\AppData\Roaming\3.MineCraft - 1.4.6.zip

[2012/12/03 14:55:40 | 061,375,949 | ---- | C] () -- C:\Users\Shawn.Michael-HP\AppData\Roaming\.minecraft.zip

[2012/12/02 17:35:50 | 000,000,127 | ---- | C] () -- C:\Users\Shawn.Michael-HP\.MinecraftRemoteConsole.store

[2012/10/14 16:54:05 | 000,098,696 | ---- | C] () -- C:\Windows\SysWow64\setupprwdrv03.exe

[2012/10/14 16:54:05 | 000,013,704 | ---- | C] () -- C:\Windows\SysWow64\prwntdrv.sys

[2012/10/10 06:33:43 | 000,000,529 | ---- | C] () -- C:\Users\Shawn.Michael-HP\SciTE.session

[2012/09/13 13:35:25 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat

[2012/08/15 19:43:20 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI

[2012/07/28 13:59:15 | 000,000,712 | ---- | C] () -- C:\Users\Shawn.Michael-HP\Shawn - Shortcut.lnk

[2012/04/22 12:54:12 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat

[2012/04/22 12:54:02 | 000,118,784 | ---- | C] () -- C:\Windows\SeaMonkeyUninstall.exe

[2012/04/22 12:53:58 | 000,118,784 | ---- | C] () -- C:\Windows\GREUninstall.exe

[2012/04/22 12:53:58 | 000,008,839 | ---- | C] () -- C:\Windows\mozver.dat

[2012/03/01 16:51:00 | 000,000,044 | ---- | C] () -- C:\Windows\MSYS.INI

[2012/01/17 10:17:25 | 000,000,145 | ---- | C] () -- C:\Users\Shawn.Michael-HP\.appletviewer

[2012/01/13 09:03:34 | 000,000,058 | ---- | C] () -- C:\Windows\myst4-screen.ini

[2011/12/30 14:30:20 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat

[2011/11/05 07:58:19 | 000,000,126 | ---- | C] () -- C:\Windows\QUICKEN.INI

[2011/08/25 14:08:06 | 000,000,492 | ---- | C] () -- C:\Windows\{3D00025F-C839-4312-A402-5C86723B8AC8}_WiseFW.ini

[2011/08/25 13:57:52 | 000,000,292 | ---- | C] () -- C:\Windows\{AC59B86B-4E39-47C8-B79A-3EC33B86FB47}_WiseFW.ini

[2011/08/18 10:17:15 | 000,000,000 | ---- | C] () -- C:\Windows\VirtualPhone.INI

[2011/08/17 10:17:26 | 000,002,624 | ---- | C] () -- C:\Windows\Palm OS Emulator.ini

[2011/08/16 18:24:32 | 000,000,225 | ---- | C] () -- C:\Windows\PowerReg.dat

[2011/08/15 13:24:58 | 000,784,608 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

========== ZeroAccess Check ==========

[2012/07/26 16:36:50 | 000,000,000 | ---D | M] -- C:\Users\Shawn.Michael-HP\Desktop\McCormic\Mike\Local Settings\Application Data\{fbe85e6f-9791-cc8e-9b92-421bf3956b14}\U

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 21:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 04:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2012/04/11 06:41:03 | 000,001,024 | ---- | M] () -- C:\.rnd

[2013/02/05 06:33:41 | 000,004,167 | ---- | M] () -- C:\AdwCleaner[R3].txt

[2013/02/05 06:33:59 | 000,004,191 | ---- | M] () -- C:\AdwCleaner[s1].txt

[2012/02/01 15:36:32 | 012,827,730 | ---- | M] () -- C:\Angry.apk

[2012/02/01 15:19:18 | 010,043,192 | ---- | M] () -- C:\app1.apk

[2009/07/24 11:22:29 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK

[2013/02/04 15:38:17 | 000,023,019 | ---- | M] () -- C:\ComboFix.txt

[2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini

[2013/02/05 14:17:50 | 2133,753,855 | -HS- | M] () -- C:\hiberfil.sys

[2011/04/01 12:03:50 | 000,000,014 | ---- | M] () -- C:\hp_devel_cpc

[2007/11/07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe

[2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini

[2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll

[2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll

[2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll

[2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll

[2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll

[2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll

[2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll

[2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll

[2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll

[2011/01/05 19:39:17 | 000,000,000 | RHS- | M] () -- C:\OS

[2013/02/05 14:17:49 | 4276,662,271 | -HS- | M] () -- C:\pagefile.sys

[2013/02/04 16:19:27 | 000,000,000 | ---- | M] () -- C:\vcredist.bmp

[2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab

[2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI

< %systemroot%\*. /mp /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 233 bytes -> C:\ProgramData\Temp:E5F8E280

@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:9D6EAEC3

@Alternate Data Stream - 226 bytes -> C:\ProgramData\Temp:D055FC10

@Alternate Data Stream - 196 bytes -> C:\ProgramData\Temp:E84CA8F2

@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:A039EDF9

@Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:7D288858

@Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:25F31665

@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:07BB519E

@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:CC45913B

@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A4BF246C

@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:4B244549

@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:F84B8DB5

@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:D0AB0B4A

@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:E6EC5C2A

@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:9547F1DB

@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:57EE48CA

@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:C0913157

@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:A41FEAA2

@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:BE64143E

@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:0D786AE3

@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:ED9B661E

< End of report >

Link to post
Share on other sites

OTL Extras logfile created on: 2/5/2013 2:27:16 PM - Run 1

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Shawn.Michael-HP\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.98 Gb Total Physical Memory | 5.57 Gb Available Physical Memory | 69.82% Memory free

15.96 Gb Paging File | 13.40 Gb Available in Paging File | 83.96% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 1849.96 Gb Total Space | 1274.39 Gb Free Space | 68.89% Space Free | Partition Type: NTFS

Drive D: | 12.96 Gb Total Space | 1.59 Gb Free Space | 12.29% Space Free | Partition Type: NTFS

Computer Name: MICHAEL-HP | User Name: Shawn | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = SeaMonkeyHTML] -- C:\Program Files (x86)\SeaMonkey\seamonkey.exe (mozilla.org)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{064CD5CA-2351-4C24-B75C-F90238E0CC99}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{0AD399A3-A545-426C-8327-985F10885D20}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

"{0D12349F-2BA3-4A49-8E0C-F881AC81E028}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{134B139B-1D79-4479-9132-5C0D4D57A113}" = rport=139 | protocol=6 | dir=out | app=system |

"{269C2F43-0AA5-4405-8422-5ED8495788D1}" = rport=138 | protocol=17 | dir=out | app=system |

"{26DBB158-16CE-48D5-A5A2-13125ECECBA9}" = rport=137 | protocol=17 | dir=out | app=system |

"{3400FAA9-8C84-4361-8D27-DB7B1B2494A2}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |

"{387B3DE3-1C01-4A44-B911-E476ECB332BD}" = lport=445 | protocol=6 | dir=in | app=system |

"{44763118-F863-4132-A1A0-75AC7AE8AC8D}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

"{48C5EFF3-0803-4BFC-A487-8B2AA618FFA3}" = lport=137 | protocol=17 | dir=in | app=system |

"{496C9100-3385-4008-B9B4-8EA6D3D32568}" = lport=2869 | protocol=6 | dir=in | app=system |

"{53F9693E-4C67-4311-A242-6A72C7A7A0C4}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{5BE19FDD-18F9-475C-9C51-C869254230A9}" = lport=139 | protocol=6 | dir=in | app=system |

"{63584DB9-A275-428D-AE6A-B9119E7FD765}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |

"{6D31AD1B-B97F-4CD5-B1CD-2C68BCF9A695}" = lport=10243 | protocol=6 | dir=in | app=system |

"{6E9470B8-CE04-4826-9F6C-49260BA55702}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

"{7032F20B-67C2-4BB3-9C24-507098884FEB}" = lport=56789 | protocol=6 | dir=in | name=vmware vcenter converter standalone - server |

"{7185DD37-FD5A-4B3C-99A4-2EDF4A5B4D34}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{852F3609-74E4-4996-840E-DC8A97A3A427}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{8934A89C-841D-4AB3-B513-541EAECB50C5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{9A252F9B-235F-4F5D-8E4D-166F6189C1EA}" = rport=445 | protocol=6 | dir=out | app=system |

"{9C14F5A3-6C8F-4627-BA54-DC4C6BDB6F77}" = lport=138 | protocol=17 | dir=in | app=system |

"{B5156EEB-5EF2-43EA-95FC-DC8A024F6052}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{B888DA16-805D-442C-8F81-F8AF05C0C4A4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{BA679D76-1D43-4E0D-8ED5-7B41843B3823}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{C7944DF8-53B0-420E-9C21-1368502166CE}" = lport=9089 | protocol=6 | dir=in | name=vmware vcenter converter standalone - agent |

"{C976D17E-E5AA-479F-8AAF-EA2C08FCC12B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

"{CDE912B9-7B51-40B2-9CBB-F650A878F375}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{D604980F-BE04-4F01-9338-DD19F6906DA8}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

"{DF124FBD-AF4E-42B6-83CB-6FA4528C1B32}" = rport=10243 | protocol=6 | dir=out | app=system |

"{E810BD41-B14C-4DE3-AF98-A76FEF3A9CDB}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |

"{EB6374AC-A14B-428B-90B9-B1CBE6E6E248}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{00EF42E1-6862-4620-BC6A-3A88F244AC1E}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\ti shared\commlib\1\jre\bin\java.exe |

"{015623F0-AD2B-4006-9B00-388D17581A7B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

"{04C67C59-7726-4DE8-B888-86753AE68C1A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rayman origins demo\rayman origins.exe |

"{051897D6-0C15-4A4A-AD37-D73194D2606D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3x.exe |

"{08D49DF3-E985-41EA-8BD7-85184737ACD7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{095E35FE-5AB9-4C7F-8A34-528B27FBA0F1}" = protocol=6 | dir=in | app=c:\program files (x86)\robotics academy\robotc virtual worlds nxt\robotc.exe |

"{09F313DF-BB95-45FF-B923-C0428FEEE5CD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\mmccuistion\source sdk base 2007\hl2.exe |

"{0AFE82C1-2050-476D-98D1-6840E885132C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |

"{0E93A22C-1A86-4960-B886-33342BA4806D}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |

"{0F47BC73-3B80-4E8B-B32C-BE669CC159D4}" = protocol=17 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war\gamedata\sweaw.exe |

"{11CF5154-8BFD-460F-A28C-AFA8C0FBCBE0}" = protocol=17 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe |

"{136C2EA0-A724-4550-ABF9-A74052A29596}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |

"{14086138-2060-4A58-820F-0F3F31F8E277}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |

"{1419053A-9277-45EE-9183-7C2174FF72A8}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |

"{14AC082B-84B7-4446-A496-940544220165}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{16611A60-C61F-4E44-AA03-0CD0240EF70A}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |

"{1B448DE1-8374-4422-A40C-81C86DAF2042}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |

"{1DE45E46-FBF7-4564-AB3F-3AA9329C8350}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\demolitioninc\finaldgamegl.exe |

"{20E19893-913E-468E-A821-88F7F8B9959E}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |

"{221EC582-3FDA-4219-84E6-6C7981686BE0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\bin\sdklauncher.exe |

"{22C56046-4159-4398-867A-5937F8C3F94E}" = protocol=17 | dir=in | app=c:\program files (x86)\bsecure\inetctrl.exe |

"{238A306E-CF6C-4BA5-9D34-0FAD082C2BB2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |

"{25821E7A-CD19-4284-A473-31379AF0A613}" = protocol=6 | dir=in | app=c:\program files (x86)\bsecure\inetctrl.exe |

"{2C9F245B-D688-4315-AF03-BA88A14D2262}" = protocol=17 | dir=in | app=c:\program files (x86)\bsecure\inetctrl.exe |

"{2CFB99BB-6FCB-48AF-AA9E-189A315B6A95}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |

"{2E0A16C5-0234-43D2-A997-189B941CC241}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\mmccuistion\source sdk base 2007\hl2.exe |

"{2F2C7CD0-BA87-4464-A49F-47BD0285B7C3}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{2F2F4ECA-3821-47CD-8B91-803CFE551360}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |

"{2F83B44F-BD48-4C6A-A70A-4A796C4385FF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{31207273-C697-40FF-B324-6414E273DC29}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |

"{314D0606-BDFE-4E66-A4A4-6212FD925677}" = protocol=6 | dir=in | app=c:\program files (x86)\ti education\ti-nspire computer link\jre\bin\java.exe |

"{32792E21-3A58-4350-8DAA-8D2E5543BE04}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{346A3703-7A77-4FFC-A37E-DDD20A3ACADF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lord of the rings online us\smp.exe |

"{34E0A5B4-1A08-4352-A805-1AB424C29EC7}" = protocol=6 | dir=out | app=system |

"{3711FC19-1E3A-41AD-B685-8A5877F7ACB6}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |

"{3D34209E-D65E-435D-BFA6-0612E846E8A7}" = protocol=17 | dir=in | app=c:\program files\java\jdk1.7.0_02\jre\bin\javaw.exe |

"{3FC393AD-EC26-4D8D-9D9E-3708F673A35E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe |

"{40BACC54-DA2E-4001-B0A0-2DF1534002C0}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{42D54D91-FED7-44B9-9656-79D261FB17C1}" = protocol=6 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war\gamedata\sweaw.exe |

"{47126C12-8A58-4495-87A9-3FBD11E2D659}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{4F25D0AC-465A-42F5-B24E-27ED47705100}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |

"{4F95F5D8-582F-4C06-9375-2E5568D7C58E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{513119C4-3A5C-411D-B43D-D8607FEF06C4}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |

"{51F214EA-5C17-444D-A4A5-26FBBEA2B4A6}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |

"{541C3AFB-2997-4CAA-8525-1472222EBDA1}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{5604E1AE-04F9-4188-8BB6-5E592E42ABCA}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\music\hptouchsmartmusic.exe |

"{56D9EBBA-A0B3-42D2-A672-26BB8B767A91}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |

"{595C6A9F-5334-45A5-B425-4056965CEB6A}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |

"{5A56F1FA-8B0B-41CC-A1F0-149882E9CF70}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"{5BB919F3-AB53-4197-BB40-33A508881751}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{6160A435-4C5B-48B3-A08B-5BC16B6003B7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rayman origins demo\rayman origins.exe |

"{66FD8A7C-BC82-4428-B476-BE050388E259}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |

"{68FF96BB-AF21-4B52-A4E3-E86D6342D0D5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\bin\sdklauncher.exe |

"{69184D61-99EE-4E41-8973-F65599B9CD61}" = protocol=17 | dir=in | app=c:\program files (x86)\ti education\ti-nspire computer link\ti-nspirelink.exe |

"{6AA10A31-68D0-402D-AB01-156F0357C761}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3x.exe |

"{703071D9-E52B-4DE1-89D9-ADCC17B2DCC3}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |

"{71AC4FAC-913E-45F0-952D-34DDA321E2B3}" = protocol=6 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe |

"{73647068-C4C5-405A-BDA2-7B5AE114D46B}" = protocol=6 | dir=in | app=c:\program files (x86)\ti education\ti-nspire computer link\ti-nspirelink.exe |

"{773EE6BA-D0F3-4ECB-A148-8E9B02E979E4}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe |

"{77E9361C-4461-44E5-80D8-7AA545CD030C}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\video\hpmediasmartvideo.exe |

"{78BF4C12-7741-422B-901E-1E4460423022}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{7AD0A5AD-4D67-42E7-88E5-CACE09FBB5A5}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |

"{7C3A14C5-2AF2-4CF9-B2FA-B9973B6FAD4D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lord of the rings online us\smp.exe |

"{7F919330-EB52-47C5-9230-2F85E246403C}" = protocol=17 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war forces of corruption\swfoc.exe |

"{8220DC04-37B7-495F-80B3-EB093B31A0ED}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |

"{83EFE139-2B34-423D-BC56-89DF4F7BCE2F}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |

"{8570A46C-834D-4EEF-9900-2FC4D5FC27A9}" = protocol=17 | dir=in | app=c:\program files (x86)\ti education\ti-nspire computer link\jre\bin\java.exe |

"{8710F30C-4FEF-421B-8746-80F0EE9B8BA7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{881B037F-955A-47A0-95D8-F5E8EE811DB5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{886E7738-E71F-40F8-9300-3AD71F2DA795}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\mmccuistion\source sdk base 2007\hl2.exe |

"{8941010E-3C94-4900-A686-BDFDD7136B39}" = protocol=6 | dir=in | app=c:\program files\java\jdk1.7.0_02\jre\bin\javaw.exe |

"{90B312A5-B979-4EB4-B1F2-2D316FD513B4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\bin\sdklauncher.exe |

"{932CB8D8-517E-4420-B449-600CF0C16492}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |

"{94D04DE5-B693-4769-A608-26B95660AEB6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{96BE93C5-53F8-4420-AB17-29721AD4C263}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{97652AC6-EA3A-4D5C-B3B7-94F6A8862FD2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{98D0D94A-3DB1-4AE3-86D9-1C19BC380119}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

"{9A50579D-038B-4568-B098-CD96CAF25FCC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |

"{9E0CB1E0-ECC7-4D43-89A6-BC2F8C31EF81}" = protocol=17 | dir=in | app=c:\program files (x86)\0 a.d. alpha\binaries\system\pyrogenesis.exe |

"{A14BB324-F684-40DD-9506-1428E112C478}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |

"{A2AE1ABA-4908-4CEB-A91A-E993EDE567E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |

"{ABBCBF79-0350-40A3-9E02-F5A9A109FBA2}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |

"{AD985255-F235-484C-9D04-5F93252A1A26}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3y.exe |

"{AFD06F88-B627-4677-BCAF-275C87FFF9DE}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |

"{B2DC477B-0239-4C9D-809E-E862BC047CB9}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |

"{B61CFA90-5731-4D3F-8A14-41C48370B108}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{BA82AF74-BC34-4228-9A6E-667049484EA2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{BBCFC735-E19B-4683-9EE5-7E207B0460CB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\mmccuistion\source sdk base 2007\hl2.exe |

"{BCE3772D-AFF7-4947-8966-3409ACC2A089}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\bin\sdklauncher.exe |

"{BD783A92-C642-4E15-B027-0572515731A3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{C044CB9B-9693-4E8C-95BB-B94ACD7CCA04}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

"{C1A77B9C-6196-4D1B-9CCD-43022DB52D90}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3y.exe |

"{C289142F-BAF3-4EAE-B1B8-E3023D5F5FB4}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |

"{C509E06D-2224-4764-BAD6-2CCF62918B10}" = protocol=6 | dir=in | app=c:\program files (x86)\0 a.d. alpha\binaries\system\pyrogenesis.exe |

"{C846C6DE-B80B-4E64-9D0A-7BBE80A45AC6}" = protocol=17 | dir=in | app=c:\program files (x86)\robotics academy\robotc virtual worlds nxt\robotc.exe |

"{CC8B9BA9-40CF-493B-95CC-B137B93845DE}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\ti shared\commlib\1\jre\bin\java.exe |

"{CCEB1F20-C972-411B-8195-FAB36D5D418D}" = protocol=6 | dir=in | app=c:\program files (x86)\lucasarts\star wars empire at war forces of corruption\swfoc.exe |

"{CD0AE78F-4C16-4246-8E3B-857E88A1351D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{D01D9545-25CB-4DF8-93FB-2F576B1842E2}" = protocol=6 | dir=in | app=c:\program files (x86)\bsecure\inetctrl.exe |

"{D3875B10-6A21-43DC-A5F1-EDE73AE71ED5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |

"{D548C418-C0B1-4EE5-BBD3-A55E555D7C47}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |

"{E3C1EF63-A23E-4DA3-8433-53A7B6B68BC5}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

"{E3F76168-18FB-4777-BB19-B34B102EA7C4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{EB807F92-04FB-42D5-A8C0-F69D96DEDD82}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |

"{EBDEBB88-E7FD-4F27-90B0-7C48EC6BD913}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |

"{F66309F7-522B-46AE-9603-96906CC04D7B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\demolitioninc\finaldgamegl.exe |

"{F991A85F-7AF4-4C26-B194-ED4396285AD6}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |

"{FA830E62-9CA8-4BBB-AC3F-01337E1A43AE}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |

"{FCF81793-7F44-4F6D-AD2E-0F23783B4BEF}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\photo\hpmediasmartphoto.exe |

"{FE66085E-5BB1-4FF0-91FC-1AFEAD3E2AD9}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |

"TCP Query User{0019A636-C4CB-405A-8653-51E919E231D0}C:\old terrabyte drive\users\shawn\appdata\local\temp\temp1_emulator-win.zip\emulator.exe" = protocol=6 | dir=in | app=c:\old terrabyte drive\users\shawn\appdata\local\temp\temp1_emulator-win.zip\emulator.exe |

"TCP Query User{06211665-C219-44FD-9528-3FE92FD1AE99}C:\users\shawn.michael-hp\appdata\local\temp\rarsfx0\omni.exe" = protocol=6 | dir=in | app=c:\users\shawn.michael-hp\appdata\local\temp\rarsfx0\omni.exe |

"TCP Query User{1107F40B-BE00-4464-8D29-890C4022C218}C:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\debug\palmsim_54_dbg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\debug\palmsim_54_dbg.exe |

"TCP Query User{153A16D9-0BBC-418B-8825-D96924D695B6}C:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\release\palmsim_54_rel.exe" = protocol=6 | dir=in | app=c:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\release\palmsim_54_rel.exe |

"TCP Query User{1C14F602-CE9B-4CF6-8FB3-340EE7673AC8}C:\users\shawn.michael-hp\desktop\emulator_bound.exe" = protocol=6 | dir=in | app=c:\users\shawn.michael-hp\desktop\emulator_bound.exe |

"TCP Query User{2F228A4D-3596-4145-833B-B5B42BD033C8}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |

"TCP Query User{48CFBF8A-8F6D-4AD2-A8CF-935C5EF794CD}C:\program files (x86)\digipen\nitronic rush\nitronicrush.exe" = protocol=6 | dir=in | app=c:\program files (x86)\digipen\nitronic rush\nitronicrush.exe |

"TCP Query User{4A0319C4-9A83-4080-A273-0AA21E790EBE}F:\program files (x86)\sean o'connor's windows games\ufos\ufos.exe" = protocol=6 | dir=in | app=f:\program files (x86)\sean o'connor's windows games\ufos\ufos.exe |

"TCP Query User{4DB2F48F-892B-4C69-BEAF-F613ADDAE051}C:\program files\java\jdk1.7.0_02\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jdk1.7.0_02\bin\java.exe |

"TCP Query User{4E4F6820-8158-44CE-BDD4-E2A0C87799A4}C:\old terrabyte drive\program files (x86)\sean o'connor's windows games\ufos\ufos.exe" = protocol=6 | dir=in | app=c:\old terrabyte drive\program files (x86)\sean o'connor's windows games\ufos\ufos.exe |

"TCP Query User{55F530E2-3470-43F2-A9BA-F4A5DABF7540}C:\program files\java\jdk1.7.0_02\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jdk1.7.0_02\jre\bin\javaw.exe |

"TCP Query User{5DD1FC38-5832-4DA3-BE29-3C64C6DEB18A}C:\program files (x86)\orblitz\orblitz.exe" = protocol=6 | dir=in | app=c:\program files (x86)\orblitz\orblitz.exe |

"TCP Query User{8186B966-CC1C-4788-A700-E08CD370BFB7}C:\users\shawn.michael-hp\tutorial projects\net1 server\bin\debug\net1 server.exe" = protocol=6 | dir=in | app=c:\users\shawn.michael-hp\tutorial projects\net1 server\bin\debug\net1 server.exe |

"TCP Query User{8622A2EC-09F0-4A13-8073-D21D1CB60ABE}C:\program files\java\jdk1.7.0_02\bin\jconsole.exe" = protocol=6 | dir=in | app=c:\program files\java\jdk1.7.0_02\bin\jconsole.exe |

"TCP Query User{8623E80B-44F9-43BC-A1D6-C4D5E7D602E6}C:\program files (x86)\toxic games\qube demo\binaries\win32\qube_demo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\toxic games\qube demo\binaries\win32\qube_demo.exe |

"TCP Query User{870DB6C6-F128-4137-BFD8-29550CBF2BB0}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |

"TCP Query User{9B1DBB2D-8DC7-4E1A-B0C0-F0DBBD0D41C6}C:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe" = protocol=6 | dir=in | app=c:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe |

"TCP Query User{9DC67B92-8E01-4CBE-B1FF-1A4553578D75}C:\program files (x86)\digipen\myr\working\myr.exe" = protocol=6 | dir=in | app=c:\program files (x86)\digipen\myr\working\myr.exe |

"TCP Query User{B41B4907-BEF2-41D5-AE45-CE8AB3182EC9}C:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\virtual phone\virtualphone.exe" = protocol=6 | dir=in | app=c:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\virtual phone\virtualphone.exe |

"TCP Query User{C0BE1973-7C80-406C-87F0-B207400B63A6}C:\program files (x86)\ti education\ti-nspire student software\ti-nspire student software.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ti education\ti-nspire student software\ti-nspire student software.exe |

"TCP Query User{C1B823D7-F675-4FC7-9C48-983B82BE5B7E}C:\program files (x86)\orblitz\orblitz.exe" = protocol=6 | dir=in | app=c:\program files (x86)\orblitz\orblitz.exe |

"TCP Query User{C792A6BC-023C-4292-82D0-37FABBC1EDE1}C:\program files (x86)\0 a.d. alpha\binaries\system\pyrogenesis.exe" = protocol=6 | dir=in | app=c:\program files (x86)\0 a.d. alpha\binaries\system\pyrogenesis.exe |

"TCP Query User{DB85BE87-972A-474F-96DB-223D9FE6DD3D}C:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe" = protocol=6 | dir=in | app=c:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe |

"TCP Query User{E746ABE9-089F-408C-AF13-904EBAF8FA1B}C:\program files (x86)\access\garnet os development suite\palmostools\palm os emulator\emulator.exe" = protocol=6 | dir=in | app=c:\program files (x86)\access\garnet os development suite\palmostools\palm os emulator\emulator.exe |

"TCP Query User{F1CB2E3A-4FBA-4235-9C05-3E0175C101BA}C:\program files (x86)\windows mobile developer power toys\activesync_remote_display\asrdisp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\windows mobile developer power toys\activesync_remote_display\asrdisp.exe |

"TCP Query User{FAEB84FC-EC6A-40B9-9408-FB99EB406ABB}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |

"UDP Query User{00E105EF-DB48-4B03-9147-535E1D05B95C}C:\program files\java\jdk1.7.0_02\bin\jconsole.exe" = protocol=17 | dir=in | app=c:\program files\java\jdk1.7.0_02\bin\jconsole.exe |

"UDP Query User{017C0084-BDDB-4A63-B649-ACB39FE4274B}F:\program files (x86)\sean o'connor's windows games\ufos\ufos.exe" = protocol=17 | dir=in | app=f:\program files (x86)\sean o'connor's windows games\ufos\ufos.exe |

"UDP Query User{077113B8-85B1-4DE6-91A6-087F6E592F8C}C:\program files\java\jdk1.7.0_02\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jdk1.7.0_02\bin\java.exe |

"UDP Query User{083B2821-3CF9-4364-95DD-D60C5FECDE3D}C:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe" = protocol=17 | dir=in | app=c:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe |

"UDP Query User{0CDA5C19-8D45-4E01-9A6A-0238260FE7E9}C:\program files\java\jdk1.7.0_02\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jdk1.7.0_02\jre\bin\javaw.exe |

"UDP Query User{0EAD7A97-0418-4F92-8502-7FEAACCF5855}C:\old terrabyte drive\program files (x86)\sean o'connor's windows games\ufos\ufos.exe" = protocol=17 | dir=in | app=c:\old terrabyte drive\program files (x86)\sean o'connor's windows games\ufos\ufos.exe |

"UDP Query User{1636A225-C58B-48D1-A0A6-B9E26D446C8D}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |

"UDP Query User{1719768D-9B02-4741-8E38-9E480C9ADA5E}C:\program files (x86)\0 a.d. alpha\binaries\system\pyrogenesis.exe" = protocol=17 | dir=in | app=c:\program files (x86)\0 a.d. alpha\binaries\system\pyrogenesis.exe |

"UDP Query User{1CA7E9BD-C3D0-4336-9541-314BE1B1B9CC}C:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe" = protocol=17 | dir=in | app=c:\users\shawn.michael-hp\downloads\palmsim61_rel_softonic\palmsim.exe |

"UDP Query User{3366FBED-DB03-4706-BEA3-4AC469205E13}C:\program files (x86)\orblitz\orblitz.exe" = protocol=17 | dir=in | app=c:\program files (x86)\orblitz\orblitz.exe |

"UDP Query User{4831FFB0-E0C9-4176-9330-853B2AED0DAC}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |

"UDP Query User{59F631DC-F5EE-4417-99BE-AE453266D3C6}C:\users\shawn.michael-hp\tutorial projects\net1 server\bin\debug\net1 server.exe" = protocol=17 | dir=in | app=c:\users\shawn.michael-hp\tutorial projects\net1 server\bin\debug\net1 server.exe |

"UDP Query User{5C7ED440-D3F0-4DFA-8B7C-8B6104EB0830}C:\old terrabyte drive\users\shawn\appdata\local\temp\temp1_emulator-win.zip\emulator.exe" = protocol=17 | dir=in | app=c:\old terrabyte drive\users\shawn\appdata\local\temp\temp1_emulator-win.zip\emulator.exe |

"UDP Query User{8309CB1D-5A71-4F5B-AC35-781597FA369D}C:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\debug\palmsim_54_dbg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\debug\palmsim_54_dbg.exe |

"UDP Query User{92C47507-283A-4199-B7EA-198C47413A93}C:\program files (x86)\toxic games\qube demo\binaries\win32\qube_demo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\toxic games\qube demo\binaries\win32\qube_demo.exe |

"UDP Query User{A575353F-936B-4725-B8D3-2AB65FBF63F4}C:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\virtual phone\virtualphone.exe" = protocol=17 | dir=in | app=c:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\virtual phone\virtualphone.exe |

"UDP Query User{A94ED4BA-F3F9-4481-B4BB-675745D7724E}C:\program files (x86)\access\garnet os development suite\palmostools\palm os emulator\emulator.exe" = protocol=17 | dir=in | app=c:\program files (x86)\access\garnet os development suite\palmostools\palm os emulator\emulator.exe |

"UDP Query User{B8403766-E0B1-4C6B-82D1-E737F525CA8F}C:\program files (x86)\ti education\ti-nspire student software\ti-nspire student software.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ti education\ti-nspire student software\ti-nspire student software.exe |

"UDP Query User{C5116909-CCE0-4EE4-83B3-ED33E0621898}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |

"UDP Query User{C91911CA-62AF-4E81-A751-549311D97502}C:\program files (x86)\orblitz\orblitz.exe" = protocol=17 | dir=in | app=c:\program files (x86)\orblitz\orblitz.exe |

"UDP Query User{C99BD6B9-039E-4578-8C4A-299035448A1C}C:\program files (x86)\digipen\myr\working\myr.exe" = protocol=17 | dir=in | app=c:\program files (x86)\digipen\myr\working\myr.exe |

"UDP Query User{DA41BB0F-3245-4B2D-A5FD-70C4A8B16CB9}C:\program files (x86)\windows mobile developer power toys\activesync_remote_display\asrdisp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\windows mobile developer power toys\activesync_remote_display\asrdisp.exe |

"UDP Query User{DEB7C249-E575-4214-B44C-C08662FD092C}C:\program files (x86)\digipen\nitronic rush\nitronicrush.exe" = protocol=17 | dir=in | app=c:\program files (x86)\digipen\nitronic rush\nitronicrush.exe |

"UDP Query User{E1D3CC92-ECB1-40AE-A2A0-93EB1C30031D}C:\users\shawn.michael-hp\appdata\local\temp\rarsfx0\omni.exe" = protocol=17 | dir=in | app=c:\users\shawn.michael-hp\appdata\local\temp\rarsfx0\omni.exe |

"UDP Query User{EB97557A-B43F-4776-8A79-50A1B823A6DA}C:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\release\palmsim_54_rel.exe" = protocol=17 | dir=in | app=c:\program files (x86)\access\garnet os development suite\sdk-5r4\tools\palm_os_54_simulator\release\palmsim_54_rel.exe |

"UDP Query User{FE36296E-A292-4FB7-A2E8-CFB44FD15972}C:\users\shawn.michael-hp\desktop\emulator_bound.exe" = protocol=17 | dir=in | app=c:\users\shawn.michael-hp\desktop\emulator_bound.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector

"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)

"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers

"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant

"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java 7 Update 5 (64-bit)

"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services

"{290329c4-a276-3aec-b633-9f5a39d8dd96}" = Python 3.3.0 (64-bit)

"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022

"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

"{4E7CCB76-687B-4C53-9A5E-08780AF3A551}" = Motorola Mobile Drivers Installation 5.9.0

"{4FF5C7C9-86CC-41ED-B93B-0B51AB4FED24}" = VmciSockets

"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile Device Center

"{64A3A4F4-B792-11D6-A78A-00B0D0170020}" = Java SE Development Kit 7 Update 2 (64-bit)

"{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes

"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour

"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support

"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007

"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended

"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010

"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010

"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010

"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010

"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting

"{A40F60B1-F1E1-452E-96A5-FF97F9A2D102}" = HP MediaSmart SmartMenu

"{AD42B520-F567-413A-A46D-C5F7FBB93C17}" = Macrium Reflect Free Edition

"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 301.42

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components

"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053

"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64

"{C0C31BCC-56FB-42a7-8766-D29E1BD74C7d}" = Python 2.7.3 (64-bit)

"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto

"{D5D8CB90-785A-458E-A5D1-3D084A1B4EE9}" = Microsoft Camera Codec Pack

"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics

"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter

"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319

"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile

"Blender" = Blender

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

"Recuva" = Recuva

"UDK-8e1ce88c-9ed6-4772-a41b-e7e6aece6ade" = My Game Long Name

"wxPython2.8-unicode-py27_is1" = wxPython 2.8.12.1 (unicode) for Python 2.7

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd

"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser

"{043557F2-58BE-4C6D-90D5-896C8F5D2C0C}_is1" = Egg Timer version 1.0

"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam

"{058B96F8-EA38-11D5-A801-0050FC209733}" = Capitalism II Demo

"{07D418A4-4A9C-43E5-AB83-2C68683782DA}_is1" = Labyrinth version 0.9

"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements

"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

"{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}" = VMware Workstation

"{106B4413-ACBB-4CDE-8707-587DB9BD77EC}" = LogMeIn Hamachi

"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1

"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser

"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware

"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker

"{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update

"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe

"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

"{238DCFCD-70B3-46B2-B90B-2CDCC69A3D03}" = Zoo Tycoon 2 - Zookeeper Collection

"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java 6 Update 31

"{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13

"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program

"{28DB8373-C1BB-444F-A427-A55585A12ED7}" = Motorola Device Manager

"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in

"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger

"{2AADC4EE-94C8-422B-977B-547774C4A463}" = Motorola Device Software Update

"{2E7E6323-863A-4A62-878C-CA1085AE793B}" = Windows Mobile Developer Power Toys

"{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}" = HP MediaSmart/TouchSmart Netflix

"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App

"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery

"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery

"{35388A22-8E5B-46B2-865F-B73A59651F3D}_is1" = Coreship v1.0

"{3D00025F-C839-4312-A402-5C86723B8AC8}" = TI-Nspire™ Computer Link Software

"{3D9B7276-7AFA-4CF9-B984-5E8DD5D5C7F3}" = Mercurial 2.5.0 (x86)

"{3DE19DBA-6F79-4E14-AE0B-1833B26DD184}_is1" = Solace - February 2011

"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology

"{406656D9-548A-4451-8FDD-69A8A60B3DBC}" = Abyss

"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go

"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager

"{465210C4-595A-BD80-44E8-E0457D9D8432}" = Zinio Reader 4

"{466CEBFB-6F03-4412-BFE7-C131BF8A96CC}_is1" = Crystalline 1.0

"{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}" = LightScribe System Software

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4C2ED74A-3AF6-4D98-A0E7-969D2B6A0467}_is1" = Leshy Version 1.21

"{506570F6-D18A-4771-B695-F90E3187F59C}_is1" = Continuum Passage

"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup

"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack

"{5AD025E6-6D9E-43F3-AE58-C6D1B05D4D79}_is1" = Duality 1.0

"{5FDA4F65-604A-4A68-9149-DBFF5A6E03C1}_is1" = Blank

"{603E9B5A-C0AF-44AD-B4F4-08C30BC46886}_is1" = Hack Attack 1.0

"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM

"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components

"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo

"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0

"{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant

"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)

"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{72C0156F-ABB0-443D-8662-7DF9025342FB}_is1" = Grid Version 1.01g

"{76BC14E7-113E-4570-91A6-E2EA03EEC7C0}_is1" = Dreamside Maroon 1.0282.333

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

"{7A21C722-F259-4976-B7AA-6658E5FDEDAF}" = Google Drive

"{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}" = HP Support Information

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010

"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010

"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010

"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010

"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010

"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010

"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010

"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010

"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010

"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010

"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010

"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010

"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010

"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010

"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010

"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In

"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English

"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010

"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{912CED74-88D3-4C5B-ACB0-13231864975E}" = PressReader

"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music

"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker

"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010

"{95140000-007D-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit

"{95140000-0081-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector

"{99612BF2-3DA1-45E8-9086-75D4E4760CBF}_is1" = Attack of the 50ft Robot!

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9A96022A-B5D0-4314-AA09-459907AF6F3D}_is1" = Nous Ver: 1.04

"{9B55759D-424F-4CB1-B84E-AAE83CC1D20A}_is1" = Nitronic Rush (2012-06-19) version 20120619.0

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{9D1CFAC3-24CB-4345-A1D9-7A13479E3690}_is1" = 0xCELERATOR version 1.0

"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail

"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™

"{A1CDC328-790D-4566-8DBD-67603D9F8129}_is1" = Myr Gold Build

"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR

"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer

"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer

"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris

"{AC2C1BDB-1E91-4F94-B99C-E716FE2E9C75}_is1" = MinGW-Get version 0.4-alpha-1

"{AC59B86B-4E39-47C8-B79A-3EC33B86FB47}" = Connectivity Library and TI-Nspire™ handheld drivers

"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.5)

"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k

"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager

"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime

"{B593FA46-32FA-4464-A786-A853F979EE3A}_is1" = Gear Full Circle 10/31/2010 Build

"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB

"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer

"{BA9DA421-71C2-433B-ADF4-8DBD483F72C4}" = Egg Timer Setup

"{BC99E569-2C69-42EC-8422-77BAAF46F1B7}_is1" = Tag - v1.1

"{C259BBE2-2531-4387-B5E3-9E6845854272}" = OneClickdigital Media Manager

"{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties

"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint

"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail

"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86

"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010

"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64

"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux

"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video

"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!

"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common

"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

"{D49CC74A-41DF-4F29-A296-A835FD116C4B}" = Egg Timer

"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX

"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime

"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD

"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources

"{DE031509-F445-4261-A377-0ECF7414D992}" = Active@ Partition Recovery

"{DE4A7830-7480-425C-8330-699C30FD8C66}" = PHM Registry Editor

"{DE59B901-18EA-4CB9-ADE4-291BF5C1E12E}_is1" = MiniTool Partition Wizard Home Edition 7.0

"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update

"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio

"{E3D20974-80DA-4D38-BD33-4F344906630A}" = Audiokinetic Wwise v2011.2.2 build 4007

"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime

"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger

"{EDF0C1D5-D980-48F9-BA19-0ECEDEF8C5D4}" = VMware vCenter Converter Standalone

"{F032E764-78E7-4057-8FB2-B75E70AE364C}_is1" = Aphotic Ascent

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support

"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video

"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Adobe Shockwave Player" = Adobe Shockwave Player 11.6

"Alice Greenfingers 1.06" = Alice Greenfingers 1.06

"Android SDK Tools" = Android SDK Tools

"avast" = avast! Free Antivirus

"Base Invaders_is1" = Base Invaders Version 1.3

"BFGC" = Big Fish Games: Game Manager

"BFG-Chocolatier - Decadence by Design" = Chocolatier: Decadence by Design

"BFG-Escape the Museum" = Escape the Museum

"BFG-Life Quest" = Life Quest®

"BFG-Royal Defense" = Royal Defense

"BFG-Westward II - Heroes of the Frontier" = Westward II: Heroes of the Frontier

"Bontago" = Bontago

"Bossinabox_is1" = Bossinabox 1.0

"CameraWindowDC" = Canon Utilities CameraWindow DC

"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX

"CameraWindowLauncher" = Canon Utilities CameraWindow

"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder

"Canon MP560 series User Registration" = Canon MP560 series User Registration

"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility

"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool

"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program

"CanonMyPrinter" = Canon Utilities My Printer

"CanonSolutionMenu" = Canon Utilities Solution Menu

"CloudCare" = CloudCare

"Coffee Tycoon" = Coffee Tycoon (remove only)

"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows

"Crazy Machines Elements - DEMO_is1" = Crazy Machines Elements - DEMO

"Data Doctor Recovery Pen Drive (Demo)" = Data Doctor Recovery Pen Drive (Demo)

"DigiPen Project Albatross" = Project Albatross

"EASEUS Partition Recovery_is1" = EASEUS Partition Recovery 5.0.1

"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX

"Easy-WebPrint EX" = Canon Easy-WebPrint EX

"FileZilla Client" = FileZilla Client 3.5.3

"Glitch_is1" = Glitch 1.3

"Inno Setup 5_is1" = Inno Setup version 5.5.0

"InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs

"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe

"InstallShield_{238DCFCD-70B3-46B2-B90B-2CDCC69A3D03}" = Zoo Tycoon 2 - Zookeeper Collection

"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go

"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo

"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III

"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music

"InstallShield_{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties

"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint

"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video

"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!

"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD

"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video

"Kore Industries : Textures Pack" = Kore Industries : Textures Pack

"LAME for Audacity_is1" = LAME v3.98.3 for Audacity

"LogMeIn Hamachi" = LogMeIn Hamachi

"Magic DVD Ripper_is1" = Magic DVD Ripper V5.4.2

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100

"Marble Mayhem!_is1" = Marble Mayhem! 1.0

"Momenta_is1" = Momenta

"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX

"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)

"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0

"MSYS-1.0_is1" = "Minimal SYStem 1.0.11"

"MyCamera" = Canon Utilities MyCamera

"MyCameraDC" = Canon Utilities MyCamera DC

"Myszere_is1" = Myszere 1.0

"NarbacularDrop_is1" = Narbacular Drop version 1.4

"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver

"Office14.Click2Run" = Microsoft Office Click-to-Run 2010

"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010

"OpenAL" = OpenAL

"Orblitz" = Orblitz

"PDF Complete" = PDF Complete Special Edition

"Perspective" = Perspective 1.0

"Photodex Presenter" = Photodex Presenter

"PhotoStitch" = Canon Utilities PhotoStitch

"Pong" = Pong

"portal-theme-v10-by-vitor-santo_folder" = portal-theme-v10-by-vitor-santo.themepack

"ProShow" = ProShow

"PTGui" = PTGui Pro Trial 9.1.3b

"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX

"RemoteCaptureDC" = Canon Utilities RemoteCapture DC

"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX

"RiseOfNations 1.0" = Microsoft Rise Of Nations

"RiseofNationsExpansion 1.0" = Rise of Nations Thrones and Patriots

"RiseofNationsExpansionTrial 1.0" = Rise of Nations Thrones and Patriots Trial Version

"SeaMonkey (1.1.11)" = SeaMonkey (1.1.11)

"SeaMonkey (2.9.1)" = SeaMonkey (2.9.1)

"Steam App 211" = Source SDK

"Steam App 218" = Source SDK Base 2007

"Steam App 400" = Portal

"Steam App 620" = Portal 2

"Steam App 629" = Portal 2 Authoring Tools - Beta

"Steam App 98610" = Demolition, Inc. Demo

"Synaesthete_is1" = Synaesthete (v1.0)

"TI-Nspire Student Software" = TI-Nspire Student Software

"VeNix_is1" = VeNix 1.0

"VMware_Workstation" = VMware Workstation

"Void" = Void 1.0

"WildTangent hp Master Uninstall" = HP Games

"WinGimp-2.0_is1" = GIMP 2.6.11

"WinLiveSuite" = Windows Live Essentials

"WinRAR archiver" = WinRAR 4.01 (32-bit)

"WT087328" = Blackhawk Striker 2

"WT087330" = Bounce Symphony

"WT087335" = Build-a-lot 2

"WT087343" = Dora's World Adventure

"WT087360" = Escape Rosecliff Island

"WT087361" = FATE

"WT087362" = Final Drive Nitro

"WT087372" = Heroes of Hellas 2 - Olympia

"WT087379" = Jewel Quest Solitaire 2

"WT087394" = Penguins!

"WT087395" = Poker Superstars III

"WT087396" = Polar Bowler

"WT087397" = Polar Golfer

"WT087414" = Virtual Families

"WT087415" = Wheel of Fortune 2

"WT087428" = Bejeweled 2 Deluxe

"WT087453" = Chuzzle Deluxe

"WT087501" = Plants vs. Zombies

"WT087533" = Zuma Deluxe

"WT087536" = Diner Dash 2 Restaurant Rescue

"WT089299" = Mystery P.I. - The London Caper

"WT089307" = Virtual Villagers 4 - The Tree of Life

"WT089308" = Blasterball 3

"WT089328" = Farm Frenzy

"WT089359" = Cake Mania

"WT089362" = Agatha Christie - Peril at End House

"WTA-44dffd02-7c99-48b0-b418-91ac10429ad8" = Ancient Rome

"YAGARTO" = YAGARTO 4.6.2

"YTdetect" = Yahoo! Detect

"ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1" = Zinio Reader 4

"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{3730F349-7ACC-42BE-9C4E-A4507A47F4C1}" = Garnet OS Development Suite

"CodeBlocks" = CodeBlocks

"HuluDesktop" = Hulu Desktop

"Sansa Updater" = Sansa Updater

========== Last 20 Event Log Errors ==========

[ Application Events ]

Error - 2/4/2013 8:08:35 PM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. Too many failures while downloading ranges: 2

Error - 2/4/2013 8:09:11 PM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. (Stream product id=0x0066): Streaming Failed

Error - 2/5/2013 10:20:59 AM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. Too many failures while downloading ranges: 2

Error - 2/5/2013 10:21:33 AM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. (Stream product id=0x0066): Streaming Failed

Error - 2/5/2013 10:29:11 AM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. Too many failures while downloading ranges: 2

Error - 2/5/2013 10:29:45 AM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. (Stream product id=0x0066): Streaming Failed

Error - 2/5/2013 11:08:58 AM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. Too many failures while downloading ranges: 2

Error - 2/5/2013 11:09:40 AM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. (Stream product id=0x0066): Streaming Failed

Error - 2/5/2013 6:20:42 PM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. Too many failures while downloading ranges: 2

Error - 2/5/2013 6:21:16 PM | Computer Name = Michael-HP | Source = CVHSVC | ID = 100

Description = Information only. (Stream product id=0x0066): Streaming Failed

[ Hewlett-Packard Events ]

Error - 8/21/2011 5:37:15 PM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\081121023707.xml

File not created by asset agent

Error - 9/4/2011 6:26:47 PM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091104032639.xml

File not created by asset agent

Error - 10/2/2011 5:23:32 PM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\101102022330.xml

File not created by asset agent

Error - 10/9/2011 4:25:45 PM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\101109012536.xml

File not created by asset agent

Error - 10/16/2011 4:44:08 PM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\101116014406.xml

File not created by asset agent

Error - 11/4/2011 11:13:08 AM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\111104081305.xml

File not created by asset agent

Error - 1/29/2012 5:57:41 PM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\011229015739.xml

File not created by asset agent

Error - 1/29/2012 5:57:44 PM | Computer Name = Michael-HP | Source = Hewlett-Packard | ID = 0

Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\011229015741.xml

File not created by asset agent

Error - 5/14/2012 2:48:16 PM | Computer Name = Michael-HP | Source = HPSF.exe | ID = 2000

Description = HP Error ID: -2147467262 at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow

dr, Boolean bOnlyDetected, HPSASession SFSession) Message: Unable to cast object

of type 'System.DBNull' to type 'System.String'. StackTrace: at HP.SupportAssistant.Common.CustomerExperience.HPSFReporting.SaveSessionInfo(DataRow

dr, Boolean bOnlyDetected, HPSASession SFSession) Source: HP.SupportAssistant.Common

Name:

HPSF.exe Version: 06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support

Framework\HPSF.exe Format: en-US RAM: 8174 Ram Utilization: 30 TargetSite: Void SaveSessionInfo(System.Data.DataRow,

Boolean, HP.SupportAssistant.Common.CustomerExperience.HPSASession)

Error - 6/17/2012 7:49:34 PM | Computer Name = Michael-HP | Source = hpsa_service.exe | ID = 2000

Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String

category) at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore()

at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,

Boolean localScan) Message: Failed to perform update. StackTrace: at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String

category) at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore()

at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,

Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager InnerException.Message:

Object '/8a5c95b5_b804_4b8e_99bb_916057d24fef/aqsz1_0n+hjfgoyzqxyboaaw_5.rem' has

been disconnected or does not exist at the server. Name: hpsa_service.exe Version:

06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

Format:

en-US RAM: 8174 Ram Utilization: 20 TargetSite: Void UpdateDetail(System.String)

[ System Events ]

Error - 2/5/2013 11:06:39 AM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7009

Description = A timeout was reached (30000 milliseconds) while waiting for the VMware

Authorization Service service to connect.

Error - 2/5/2013 11:06:39 AM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7000

Description = The VMware Authorization Service service failed to start due to the

following error: %%1053

Error - 2/5/2013 11:06:42 AM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7001

Description = The VMware Workstation Server service depends on the VMware Authorization

Service service which failed to start because of the following error: %%1053

Error - 2/5/2013 11:06:46 AM | Computer Name = Michael-HP | Source = DCOM | ID = 10016

Description =

Error - 2/5/2013 11:08:54 AM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7038

Description = The nvUpdatusService service was unable to log on as .\UpdatusUser

with the currently configured password due to the following error: %%1330 To ensure

that the service is configured properly, use the Services snap-in in Microsoft

Management Console (MMC).

Error - 2/5/2013 11:08:54 AM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7000

Description = The NVIDIA Update Service Daemon service failed to start due to the

following error: %%1069

Error - 2/5/2013 6:18:34 PM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7024

Description = The VMware Workstation Server service terminated with service-specific

error %%-1.

Error - 2/5/2013 6:20:25 PM | Computer Name = Michael-HP | Source = DCOM | ID = 10016

Description =

Error - 2/5/2013 6:20:41 PM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7038

Description = The nvUpdatusService service was unable to log on as .\UpdatusUser

with the currently configured password due to the following error: %%1330 To ensure

that the service is configured properly, use the Services snap-in in Microsoft

Management Console (MMC).

Error - 2/5/2013 6:20:41 PM | Computer Name = Michael-HP | Source = Service Control Manager | ID = 7000

Description = The NVIDIA Update Service Daemon service failed to start due to the

following error: %%1069

< End of report >

Link to post
Share on other sites

Good afternoon QubicComputers,

You have the ZeroAccess infection. This is a rootkit that can offer backdoor access to a remote user.

If you do any banking or other financial transactions on the computer, or if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be removed, your computer is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the Operating System.

Please visit the following sites for more information on internet theft and when to reformat!

How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

I will of course do my best to help clean the computer of any infections that I can see if you would like to continue.

If you have any questions before making a final decision, please feel free to ask.

Instructions on how to format and reinstall Windows can be found here

=====

If you decide you wish to attempt to clean your computer in spite of this threat then please proceed with these instructions:

Please run OTL.exe.

  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
    [2012/07/26 16:36:50 | 000,000,000 | ---D | M] -- C:\Users\Shawn.Michael-HP\Desktop\McCormic\Mike\Local Settings\Application Data\{fbe85e6f-9791-cc8e-9b92-421bf3956b14}\U
    [2012/07/26 16:36:50 | 000,000,000 | ---D | M] -- C:\Users\Shawn.Michael-HP\Desktop\McCormic\Mike\Local Settings\Application Data\{fbe85e6f-9791-cc8e-9b92-421bf3956b14}
    @Alternate Data Stream - 233 bytes -> C:\ProgramData\Temp:E5F8E280
    @Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:9D6EAEC3
    @Alternate Data Stream - 226 bytes -> C:\ProgramData\Temp:D055FC10
    @Alternate Data Stream - 196 bytes -> C:\ProgramData\Temp:E84CA8F2
    @Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:A039EDF9
    @Alternate Data Stream - 148 bytes -> C:\ProgramData\Temp:7D288858
    @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:25F31665
    @Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:07BB519E
    @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:CC45913B
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A4BF246C
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:4B244549
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:F84B8DB5
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:D0AB0B4A
    @Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:E6EC5C2A
    @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:9547F1DB
    @Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:57EE48CA
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:C0913157
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:A41FEAA2
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:BE64143E
    @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:0D786AE3
    @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:ED9B661E
    :Commands
    [EmptyTemp]
  • Return to OTL.exe, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.
  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

=====

Then try running ComboFix and post its log in your reply.

=====

In your reply please post the contents of OTL and ComboFix if you decide to proceed.

Link to post
Share on other sites

ComboFix finally worked properly! Here are the logs:

All processes killed

========== OTL ==========

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!

C:\Users\Shawn.Michael-HP\Desktop\McCormic\Mike\Local Settings\Application Data\{fbe85e6f-9791-cc8e-9b92-421bf3956b14}\U folder moved successfully.

C:\Users\Shawn.Michael-HP\Desktop\McCormic\Mike\Local Settings\Application Data\{fbe85e6f-9791-cc8e-9b92-421bf3956b14} folder moved successfully.

ADS C:\ProgramData\Temp:E5F8E280 deleted successfully.

ADS C:\ProgramData\Temp:9D6EAEC3 deleted successfully.

ADS C:\ProgramData\Temp:D055FC10 deleted successfully.

ADS C:\ProgramData\Temp:E84CA8F2 deleted successfully.

ADS C:\ProgramData\Temp:A039EDF9 deleted successfully.

ADS C:\ProgramData\Temp:7D288858 deleted successfully.

ADS C:\ProgramData\Temp:25F31665 deleted successfully.

ADS C:\ProgramData\Temp:07BB519E deleted successfully.

ADS C:\ProgramData\Temp:CC45913B deleted successfully.

ADS C:\ProgramData\Temp:A4BF246C deleted successfully.

ADS C:\ProgramData\Temp:4B244549 deleted successfully.

ADS C:\ProgramData\Temp:F84B8DB5 deleted successfully.

ADS C:\ProgramData\Temp:D0AB0B4A deleted successfully.

ADS C:\ProgramData\Temp:E6EC5C2A deleted successfully.

ADS C:\ProgramData\Temp:9547F1DB deleted successfully.

ADS C:\ProgramData\Temp:57EE48CA deleted successfully.

ADS C:\ProgramData\Temp:C0913157 deleted successfully.

ADS C:\ProgramData\Temp:A41FEAA2 deleted successfully.

ADS C:\ProgramData\Temp:BE64143E deleted successfully.

ADS C:\ProgramData\Temp:0D786AE3 deleted successfully.

ADS C:\ProgramData\Temp:ED9B661E deleted successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 41620 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Lisa

->Temp folder emptied: 3360324 bytes

->Temporary Internet Files folder emptied: 3110980 bytes

->Java cache emptied: 195272 bytes

->Flash cache emptied: 43206 bytes

User: Michael

->Temp folder emptied: 66088702 bytes

->Temporary Internet Files folder emptied: 33905941 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 12867956 bytes

->Flash cache emptied: 45846 bytes

User: Patrick

->Temp folder emptied: 705281818 bytes

->Temporary Internet Files folder emptied: 56181995 bytes

->Java cache emptied: 13676487 bytes

->Google Chrome cache emptied: 24043213 bytes

->Flash cache emptied: 42689 bytes

User: Program Files

->Temp folder emptied: 0 bytes

User: Public

->Temp folder emptied: 0 bytes

User: Shawn

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Shawn.Michael-HP

->Temp folder emptied: 1034998 bytes

->Temporary Internet Files folder emptied: 105971637 bytes

->Java cache emptied: 6132149 bytes

->FireFox cache emptied: 13089843 bytes

->Flash cache emptied: 49288 bytes

User: SHAWN~1~MIC

->Temp folder emptied: 0 bytes

User: UpdatusUser

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 41620 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 200704 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 107552 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 431421 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes

%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 556 bytes

RecycleBin emptied: 5965 bytes

Total Files Cleaned = 998.00 mb

OTL by OldTimer - Version 3.2.69.0 log created on 02062013_070228

Files\Folders moved on Reboot...

C:\Users\Shawn.Michael-HP\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

C:\Windows\temp\vmware-SYSTEM\vmauthd.log moved successfully.

C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-3500.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

ComboFix 13-02-03.03 - Shawn 02/06/2013 7:15.1.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8175.5701 [GMT -8:00]

Running from: c:\users\Shawn.Michael-HP\Desktop\ComboFix.exe

AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

AV: CloudCare *Disabled/Updated* {BABEE769-087B-572E-AD62-21FF46C86F61}

SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: CloudCare AntiSpyware *Disabled/Updated* {01DF068D-2E41-58A0-97D2-1A8D3D4F25DC}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\Install.exe

c:\users\Michael\mp560swin102ea24.exe

c:\users\Michael\mp560swin105ea24.exe

c:\users\Patrick\AppData\Roaming\0ad

c:\users\Patrick\AppData\Roaming\0ad\config\user.cfg

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad

c:\users\Shawn.Michael-HP\AppData\Roaming\0ad\config\user.cfg

.

.

((((((((((((((((((((((((( Files Created from 2013-01-06 to 2013-02-06 )))))))))))))))))))))))))))))))

.

.

2074-05-19 00:44 . 2008-03-21 21:46 607296 ----a-w- c:\program files (x86)\Microsoft Games\Age of Empires III Ancient\deformerdllyD.dll

2040-08-24 20:34 . 2040-08-24 20:34 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-06 15:31 . 2013-02-06 15:31 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-02-06 15:31 . 2013-02-06 15:31 -------- d-----w- c:\users\SHAWN~1~MIC\AppData\Local\temp

2013-02-06 15:31 . 2013-02-06 15:31 -------- d-----w- c:\users\Shawn\AppData\Local\temp

2013-02-06 15:31 . 2013-02-06 15:31 -------- d-----w- c:\users\Patrick\AppData\Local\temp

2013-02-06 15:31 . 2013-02-06 15:31 -------- d-----w- c:\users\Michael\AppData\Local\temp

2013-02-06 15:31 . 2013-02-06 15:31 -------- d-----w- c:\users\Lisa\AppData\Local\temp

2013-02-06 15:31 . 2013-02-06 15:31 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-02-02 19:10 . 2009-01-25 20:14 17272 ----a-w- c:\windows\system32\sdnclean64.exe

2013-02-02 19:10 . 2013-02-05 14:26 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2

2013-02-02 01:53 . 2013-02-05 00:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Roaming\digipen

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Local\digipen

2013-02-02 00:06 . 2013-02-02 00:06 -------- d-----w- c:\users\Lisa\AppData\Local\MagicSoftware

2013-02-02 00:01 . 2013-02-02 00:01 -------- d-----w- c:\users\Lisa\AppData\Roaming\Sony Corporation

2013-02-01 20:05 . 2013-02-01 20:05 -------- d-----w- c:\program files (x86)\Common Files\Windows Microsoft Shared

2013-02-01 20:05 . 2010-04-26 19:23 49088 ----a-w- c:\windows\SysWow64\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-04-26 19:23 58432 ----a-w- c:\windows\system32\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-02-05 17:40 21624 ----a-w- c:\windows\SysWow64\drivers\BSecACFltr.sys

2013-02-01 20:05 . 2010-02-03 17:57 22832 ----a-w- c:\windows\system32\drivers\BSecACFltr.sys

2013-02-01 19:56 . 2013-02-01 19:56 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-01-31 04:28 . 2013-01-31 04:37 -------- d-----w- c:\users\Shawn.Michael-HP\HG

2013-01-31 04:21 . 2013-01-31 04:21 -------- d-----w- c:\program files (x86)\Mercurial

2013-01-29 23:38 . 2013-01-29 23:38 -------- d-----w- c:\users\Patrick\AppData\Roaming\Game

2013-01-29 23:36 . 2013-01-29 23:36 -------- d-----w- c:\program files (x86)\Royal Defense

2013-01-29 20:43 . 2013-01-29 20:43 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Local\Programs

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 20:38 . 2013-01-29 21:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\programdata\Malwarebytes

2013-01-29 20:38 . 2012-12-15 00:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-01-29 01:49 . 2012-10-30 23:50 285328 ----a-w- c:\windows\system32\aswBoot.exe

2013-01-29 01:49 . 2013-02-06 15:32 -------- d-----w- c:\programdata\AVAST Software

2013-01-29 01:49 . 2013-02-05 00:02 -------- d-----w- c:\program files\AVAST Software

2013-01-27 23:39 . 2013-01-27 23:53 -------- d-----w- c:\program files (x86)\Narbacular Drop

2013-01-25 18:18 . 2013-01-25 18:18 -------- d-----w- c:\users\Michael\AppData\Roaming\Sony Corporation

2013-01-17 16:00 . 2013-01-17 16:00 -------- d-----w- c:\users\Lisa\AppData\Roaming\Motorola Mobility

2013-01-15 14:29 . 2013-01-28 22:42 -------- d-----w- C:\Include

2013-01-15 14:24 . 2013-01-29 15:13 -------- d-----w- c:\users\Shawn.Michael-HP\Tutorial Projects

2013-01-15 14:21 . 2013-02-02 01:44 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-01-15 14:20 . 2013-01-15 14:21 -------- d-----w- c:\program files (x86)\CodeBlocks

2013-01-09 23:39 . 2013-01-10 00:05 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-09 15:07 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys

2013-01-09 15:07 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-02-05 15:16 . 2012-07-14 00:14 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2013-02-05 15:16 . 2012-01-16 20:19 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-01-17 09:28 . 2011-08-13 21:46 273840 ------w- c:\windows\system32\MpSigStub.exe

2013-01-12 15:34 . 2012-04-01 03:11 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-01-12 15:34 . 2011-08-23 18:06 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-10 04:37 . 2011-08-14 14:52 67599240 ----a-w- c:\windows\system32\MRT.exe

2012-12-16 17:11 . 2012-12-21 16:12 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-16 14:45 . 2012-12-21 16:12 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-11-30 04:45 . 2013-01-09 15:08 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-11-14 07:06 . 2012-12-13 23:18 17811968 ----a-w- c:\windows\system32\mshtml.dll

2012-11-14 06:32 . 2012-12-13 23:18 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-11-14 06:11 . 2012-12-13 23:18 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-11-14 06:04 . 2012-12-13 23:18 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-11-14 06:04 . 2012-12-13 23:18 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-11-14 06:02 . 2012-12-13 23:18 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 06:02 . 2012-12-13 23:18 237056 ----a-w- c:\windows\system32\url.dll

2012-11-14 05:59 . 2012-12-13 23:18 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-11-14 05:58 . 2012-12-13 23:18 816640 ----a-w- c:\windows\system32\jscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 05:55 . 2012-12-13 23:18 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-11-14 05:55 . 2012-12-13 23:18 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-11-14 05:53 . 2012-12-13 23:18 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-11-14 05:52 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-11-14 05:46 . 2012-12-13 23:18 248320 ----a-w- c:\windows\system32\ieui.dll

2012-11-14 02:09 . 2012-12-13 23:18 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-11-14 01:58 . 2012-12-13 23:18 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-11-14 01:57 . 2012-12-13 23:18 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-11-14 01:49 . 2012-12-13 23:18 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-11-14 01:48 . 2012-12-13 23:18 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-11-14 01:44 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-11-09 05:45 . 2012-12-13 23:22 2048 ----a-w- c:\windows\system32\tzres.dll

2012-11-09 04:42 . 2012-12-13 23:22 2048 ----a-w- c:\windows\SysWow64\tzres.dll

2012-11-08 19:29 . 2012-11-08 19:29 1402312 ----a-w- c:\windows\SysWow64\msxml4.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-12-03 1354736]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2010-09-28 664600]

"CloudCare"="c:\program files (x86)\Bsecure\BsecTray.exe" [2011-06-25 96040]

"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-05-20 136544]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-11-13 421736]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

c:\users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Egg Timer.exe - Shortcut.lnk - c:\program files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe [2012-7-31 56832]

note.txt [2013-1-3 1759]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"mixer2"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]

@=""

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

.

R2 CLKMSVC10_C6F09094;CyberLink Product - 2011/01/05 19:22;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [2010-11-26 245232]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072]

R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]

R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]

R3 bmdrvr;Modified Clusters Tracking Driver;SysWOW64\drivers\bmdrvr.sys [x]

R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]

R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2012-06-11 22016]

R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2012-01-25 9728]

R3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2012-06-08 31232]

R3 prwntdrv;prwntdrv;c:\windows\system32\prwntdrv.sys [2010-08-26 16776]

R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-09-03 19936]

R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-09-03 13280]

R3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\Drivers\SIVX64.sys [2008-06-14 57312]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 USBTINSP;TI-Nspire Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [2010-03-30 142848]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-08-14 1255736]

R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]

R4 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]

S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-23 203264]

S2 Bsecure;CloudCare;c:\program files (x86)\Bsecure\InetCtrl.exe [2011-06-25 66344]

S2 BsecureAV;CloudCare AntiVirus;c:\program files (x86)\Bsecure\BsecAV.exe [2011-06-25 161776]

S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-11 2465712]

S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]

S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-15 398184]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-15 682344]

S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-07-17 116632]

S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2010-09-28 1119768]

S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]

S2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2011-11-09 301720]

S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]

S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]

S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-30 846448]

S2 vmware-converter-agent;VMware vCenter Converter Standalone Agent;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe [2011-08-20 423536]

S2 vmware-converter-server;VMware vCenter Converter Standalone Server;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

S2 vmware-converter-worker;VMware vCenter Converter Standalone Worker;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]

S3 BSecACFltr;BSecACFltr;c:\windows\system32\DRIVERS\BSecACFltr.sys [2010-02-03 22832]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-15 24176]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]

S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]

S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - BsecureFilter

*Deregistered* - CLKMDRV10_C6F09094

.

Contents of the 'Scheduled Tasks' folder

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003Core.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003UA.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-01-11 c:\windows\Tasks\HPCeeScheduleForMICHAEL-HP$.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-01-25 c:\windows\Tasks\HPCeeScheduleForMichael.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-02-01 c:\windows\Tasks\HPCeeScheduleForPatrick.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-02-05 c:\windows\Tasks\HPCeeScheduleForShawn.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]

"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-26 2184520]

"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-06-24 1128448]

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = ;192.168.*.*

mSearchAssistant = hxxp://www.google.com

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

LSP: %SystemRoot%\system32\vsocklib.dll

LSP: %ProgramFiles%\Bsecure\InetCtrl57.dll

FF - ProfilePath - c:\users\Shawn.Michael-HP\AppData\Roaming\Mozilla\Firefox\Profiles\dbh3faig.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - ExtSQL: 2013-01-29 06:12; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF

.

- - - - ORPHANS REMOVED - - - -

.

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]

"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-853655980-1941484234-785684605-1005\Software\SecuROM\License information*]

"datasecu"=hex:a9,1f,74,79,ab,40,60,ea,06,fd,68,99,75,08,36,4f,5f,b8,9a,73,62,

da,5c,9a,f4,0d,34,f1,29,03,75,72,56,46,8e,b5,07,33,00,d3,5b,06,55,e0,ac,99,\

"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*]

"v5Licence0"="15-3BWD-J5JA-Q87W-PSPD-EG7V-PAWT3ZW"

"Activated"="Y"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe

c:\windows\SysWOW64\vmnat.exe

c:\program files (x86)\VMware\VMware Workstation\vmware-authd.exe

c:\windows\SysWOW64\vmnetdhcp.exe

c:\program files (x86)\Bsecure\BSecAMX.exe

c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe

c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

.

**************************************************************************

.

Completion time: 2013-02-06 07:56:56 - machine was rebooted

ComboFix-quarantined-files.txt 2013-02-06 15:56

ComboFix2.txt 2013-02-04 23:38

ComboFix3.txt 2013-02-04 15:41

ComboFix4.txt 2013-02-03 22:11

.

Pre-Run: 1,368,493,522,944 bytes free

Post-Run: 1,367,176,671,232 bytes free

.

- - End Of File - - 7BCE8FA421A6C7589AEF7674CF349A2E

Link to post
Share on other sites

Good morning QubicComputers,

You can now try removing the security programs you don't want to keep again.

Please follow these instructions to remove the remaining malicious entries:

  • Please close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open Notepad and copy/paste the text in the quotebox below into it:
    Please Note: Do NOT use any other text editor than Notepad or the CFScript will fail.

    killall::
    DDS::
    uInternet Settings,ProxyOverride = ;192.168.*.*
  • Save this as CFScript.txt, in the same location as ComboFix.exe.
    CFScriptB-4.gif
  • Referring to the picture above, drag CFScript into ComboFix.exe.
  • When finished, it shall produce a log for you at C:\ComboFix.txt.

Please post the ComboFix.txt in your next reply.

=====

Also, please download Malwarebytes Anti-Rootkit here.

  • Unzip the contents to a folder on the Desktop.
  • Open the folder where the contents were unzipped and run mbar.exe ( right-click and select Run as administrator for Vista and Windows 7).
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Please post the two logs produced.

Please note: This tool is still in BETA mode, so please ensure you have backed up any important files.

=====

In your reply I would like to see the following please:

  • ComboFix.txt.
  • Both MBAR logs.

How is the computer running?

Link to post
Share on other sites

The computer is running without problems, but I did disable all of Cloud Care for the moment. Here are the logs:

ComboFix 13-02-06.01 - Shawn 02/06/2013 13:35:40.2.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8175.5890 [GMT -8:00]

Running from: c:\users\Shawn.Michael-HP\Desktop\ComboFix.exe

Command switches used :: c:\users\Shawn.Michael-HP\Desktop\CFScript.txt

AV: CloudCare *Disabled/Updated* {BABEE769-087B-572E-AD62-21FF46C86F61}

SP: CloudCare AntiSpyware *Disabled/Updated* {01DF068D-2E41-58A0-97D2-1A8D3D4F25DC}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2013-01-06 to 2013-02-06 )))))))))))))))))))))))))))))))

.

.

2074-05-19 00:44 . 2008-03-21 21:46 607296 ----a-w- c:\program files (x86)\Microsoft Games\Age of Empires III Ancient\deformerdllyD.dll

2040-08-24 20:34 . 2040-08-24 20:34 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\WinBatch

2013-02-06 21:44 . 2013-02-06 21:44 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-02-06 21:44 . 2013-02-06 21:44 -------- d-----w- c:\users\SHAWN~1~MIC\AppData\Local\temp

2013-02-06 21:44 . 2013-02-06 21:44 -------- d-----w- c:\users\Shawn\AppData\Local\temp

2013-02-06 21:44 . 2013-02-06 21:44 -------- d-----w- c:\users\Patrick\AppData\Local\temp

2013-02-06 21:44 . 2013-02-06 21:44 -------- d-----w- c:\users\Michael\AppData\Local\temp

2013-02-06 21:44 . 2013-02-06 21:44 -------- d-----w- c:\users\Lisa\AppData\Local\temp

2013-02-06 21:44 . 2013-02-06 21:44 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-02-06 15:02 . 2013-02-06 15:02 -------- d-----w- C:\_OTL

2013-02-05 22:23 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F204D13-8E4E-4E7A-B0AC-F4817AA84E49}\mpengine.dll

2013-02-05 15:16 . 2013-02-05 15:16 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-02-05 14:41 . 2013-02-05 14:41 -------- d-----w- C:\FRST

2013-02-05 01:14 . 2005-02-11 15:55 102400 ----a-w- c:\program files (x86)\Microsoft Games\Rise of Nations\patcher.exe

2013-02-02 19:10 . 2009-01-25 20:14 17272 ----a-w- c:\windows\system32\sdnclean64.exe

2013-02-02 19:10 . 2013-02-05 14:26 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2

2013-02-02 01:53 . 2013-02-05 00:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Roaming\digipen

2013-02-02 01:49 . 2013-02-02 01:49 -------- d-----w- c:\users\Lisa\AppData\Local\digipen

2013-02-02 00:06 . 2013-02-02 00:06 -------- d-----w- c:\users\Lisa\AppData\Local\MagicSoftware

2013-02-02 00:01 . 2013-02-02 00:01 -------- d-----w- c:\users\Lisa\AppData\Roaming\Sony Corporation

2013-02-01 20:05 . 2013-02-01 20:05 -------- d-----w- c:\program files (x86)\Common Files\Windows Microsoft Shared

2013-02-01 20:05 . 2010-04-26 19:23 49088 ----a-w- c:\windows\SysWow64\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-04-26 19:23 58432 ----a-w- c:\windows\system32\drivers\BsecFltr.sys

2013-02-01 20:05 . 2010-02-05 17:40 21624 ----a-w- c:\windows\SysWow64\drivers\BSecACFltr.sys

2013-02-01 20:05 . 2010-02-03 17:57 22832 ----a-w- c:\windows\system32\drivers\BSecACFltr.sys

2013-02-01 19:56 . 2013-02-01 19:56 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Intuit

2013-01-31 04:28 . 2013-01-31 04:37 -------- d-----w- c:\users\Shawn.Michael-HP\HG

2013-01-31 04:21 . 2013-01-31 04:21 -------- d-----w- c:\program files (x86)\Mercurial

2013-01-29 23:38 . 2013-01-29 23:38 -------- d-----w- c:\users\Patrick\AppData\Roaming\Game

2013-01-29 23:36 . 2013-01-29 23:36 -------- d-----w- c:\program files (x86)\Royal Defense

2013-01-29 20:43 . 2013-01-29 20:43 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Local\Programs

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\Malwarebytes

2013-01-29 20:38 . 2013-01-29 21:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-01-29 20:38 . 2013-01-29 20:38 -------- d-----w- c:\programdata\Malwarebytes

2013-01-29 20:38 . 2012-12-15 00:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-01-29 01:49 . 2012-10-30 23:50 285328 ----a-w- c:\windows\system32\aswBoot.exe

2013-01-29 01:49 . 2013-02-06 15:32 -------- d-----w- c:\programdata\AVAST Software

2013-01-29 01:49 . 2013-02-05 00:02 -------- d-----w- c:\program files\AVAST Software

2013-01-27 23:39 . 2013-01-27 23:53 -------- d-----w- c:\program files (x86)\Narbacular Drop

2013-01-25 18:18 . 2013-01-25 18:18 -------- d-----w- c:\users\Michael\AppData\Roaming\Sony Corporation

2013-01-17 16:00 . 2013-01-17 16:00 -------- d-----w- c:\users\Lisa\AppData\Roaming\Motorola Mobility

2013-01-15 14:29 . 2013-01-28 22:42 -------- d-----w- C:\Include

2013-01-15 14:24 . 2013-01-29 15:13 -------- d-----w- c:\users\Shawn.Michael-HP\Tutorial Projects

2013-01-15 14:21 . 2013-02-06 17:55 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\CodeBlocks

2013-01-15 14:20 . 2013-01-15 14:21 -------- d-----w- c:\program files (x86)\CodeBlocks

2013-01-09 23:39 . 2013-01-10 00:05 -------- d-----w- c:\users\Shawn.Michael-HP\AppData\Roaming\5.MineCraft - Flans - 1.4.7

2013-01-09 15:07 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys

2013-01-09 15:07 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-02-05 15:16 . 2012-07-14 00:14 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2013-02-05 15:16 . 2012-01-16 20:19 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-01-17 09:28 . 2011-08-13 21:46 273840 ------w- c:\windows\system32\MpSigStub.exe

2013-01-12 15:34 . 2012-04-01 03:11 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-01-12 15:34 . 2011-08-23 18:06 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-01-10 04:37 . 2011-08-14 14:52 67599240 ----a-w- c:\windows\system32\MRT.exe

2012-12-16 17:11 . 2012-12-21 16:12 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-16 14:45 . 2012-12-21 16:12 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-12-16 14:13 . 2012-12-21 16:12 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-11-30 04:45 . 2013-01-09 15:08 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-11-14 07:06 . 2012-12-13 23:18 17811968 ----a-w- c:\windows\system32\mshtml.dll

2012-11-14 06:32 . 2012-12-13 23:18 10925568 ----a-w- c:\windows\system32\ieframe.dll

2012-11-14 06:11 . 2012-12-13 23:18 2312704 ----a-w- c:\windows\system32\jscript9.dll

2012-11-14 06:04 . 2012-12-13 23:18 1346048 ----a-w- c:\windows\system32\urlmon.dll

2012-11-14 06:04 . 2012-12-13 23:18 1392128 ----a-w- c:\windows\system32\wininet.dll

2012-11-14 06:02 . 2012-12-13 23:18 1494528 ----a-w- c:\windows\system32\inetcpl.cpl

2012-11-14 06:02 . 2012-12-13 23:18 237056 ----a-w- c:\windows\system32\url.dll

2012-11-14 05:59 . 2012-12-13 23:18 85504 ----a-w- c:\windows\system32\jsproxy.dll

2012-11-14 05:58 . 2012-12-13 23:18 816640 ----a-w- c:\windows\system32\jscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 599040 ----a-w- c:\windows\system32\vbscript.dll

2012-11-14 05:57 . 2012-12-13 23:18 173056 ----a-w- c:\windows\system32\ieUnatt.exe

2012-11-14 05:55 . 2012-12-13 23:18 2144768 ----a-w- c:\windows\system32\iertutil.dll

2012-11-14 05:55 . 2012-12-13 23:18 729088 ----a-w- c:\windows\system32\msfeeds.dll

2012-11-14 05:53 . 2012-12-13 23:18 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-11-14 05:52 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2012-11-14 05:46 . 2012-12-13 23:18 248320 ----a-w- c:\windows\system32\ieui.dll

2012-11-14 02:09 . 2012-12-13 23:18 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll

2012-11-14 01:58 . 2012-12-13 23:18 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2012-11-14 01:57 . 2012-12-13 23:18 1129472 ----a-w- c:\windows\SysWow64\wininet.dll

2012-11-14 01:49 . 2012-12-13 23:18 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2012-11-14 01:48 . 2012-12-13 23:18 420864 ----a-w- c:\windows\SysWow64\vbscript.dll

2012-11-14 01:44 . 2012-12-13 23:18 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2012-11-09 05:45 . 2012-12-13 23:22 2048 ----a-w- c:\windows\system32\tzres.dll

2012-11-09 04:42 . 2012-12-13 23:22 2048 ----a-w- c:\windows\SysWow64\tzres.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-12-03 1354736]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2010-09-28 664600]

"CloudCare"="c:\program files (x86)\Bsecure\BsecTray.exe" [2011-06-25 96040]

"IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-05-20 136544]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-11-13 421736]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

c:\users\Shawn.Michael-HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Egg Timer.exe - Shortcut.lnk - c:\program files (x86)\Qubic Programs\Egg Timer\Egg Timer.exe [2012-7-31 56832]

note.txt [2013-1-3 1759]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"mixer2"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]

@=""

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

.

R2 CLKMSVC10_C6F09094;CyberLink Product - 2011/01/05 19:22;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [2010-11-26 245232]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]

R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]

R3 bmdrvr;Modified Clusters Tracking Driver;SysWOW64\drivers\bmdrvr.sys [x]

R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]

R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2012-06-11 22016]

R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2012-01-25 9728]

R3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2012-06-08 31232]

R3 prwntdrv;prwntdrv;c:\windows\system32\prwntdrv.sys [2010-08-26 16776]

R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-09-03 19936]

R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-09-03 13280]

R3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\Drivers\SIVX64.sys [2008-06-14 57312]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 USBTINSP;TI-Nspire Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [2010-03-30 142848]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-08-14 1255736]

R4 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]

S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-23 203264]

S2 Bsecure;CloudCare;c:\program files (x86)\Bsecure\InetCtrl.exe [2011-06-25 66344]

S2 BsecureAV;CloudCare AntiVirus;c:\program files (x86)\Bsecure\BsecAV.exe [2011-06-25 161776]

S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-11 2465712]

S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072]

S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]

S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-15 398184]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-15 682344]

S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-07-17 116632]

S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2010-09-28 1119768]

S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176]

S2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2011-11-09 301720]

S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]

S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 2655768]

S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-30 846448]

S2 vmware-converter-agent;VMware vCenter Converter Standalone Agent;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe [2011-08-20 423536]

S2 vmware-converter-server;VMware vCenter Converter Standalone Server;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

S2 vmware-converter-worker;VMware vCenter Converter Standalone Worker;c:\program files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [2011-08-20 423536]

S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]

S3 BSecACFltr;BSecACFltr;c:\windows\system32\DRIVERS\BSecACFltr.sys [2010-02-03 22832]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-15 24176]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264]

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648]

S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960]

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376]

S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]

S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - BsecureFilter

*Deregistered* - CLKMDRV10_C6F09094

.

Contents of the 'Scheduled Tasks' folder

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-07 03:52]

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003Core.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-853655980-1941484234-785684605-1003UA.job

- c:\users\Patrick\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-14 17:18]

.

2013-01-11 c:\windows\Tasks\HPCeeScheduleForMICHAEL-HP$.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-01-25 c:\windows\Tasks\HPCeeScheduleForMichael.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-02-01 c:\windows\Tasks\HPCeeScheduleForPatrick.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

2013-02-05 c:\windows\Tasks\HPCeeScheduleForShawn.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]

@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"

[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]

2012-12-18 03:50 755816 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]

"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-26 2184520]

"CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-06-24 1128448]

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

mSearchAssistant = hxxp://www.google.com

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

LSP: %SystemRoot%\system32\vsocklib.dll

LSP: %ProgramFiles%\Bsecure\InetCtrl57.dll

FF - ProfilePath - c:\users\Shawn.Michael-HP\AppData\Roaming\Mozilla\Firefox\Profiles\dbh3faig.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - ExtSQL: 2013-01-29 06:12; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF

.

- - - - ORPHANS REMOVED - - - -

.

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]

"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-853655980-1941484234-785684605-1005\Software\SecuROM\License information*]

"datasecu"=hex:a9,1f,74,79,ab,40,60,ea,06,fd,68,99,75,08,36,4f,5f,b8,9a,73,62,

da,5c,9a,f4,0d,34,f1,29,03,75,72,56,46,8e,b5,07,33,00,d3,5b,06,55,e0,ac,99,\

"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*]

"v5Licence0"="15-3BWD-J5JA-Q87W-PSPD-EG7V-PAWT3ZW"

"Activated"="Y"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe

c:\program files (x86)\Photodex\ProShow\ScsiAccess.exe

c:\windows\SysWOW64\vmnat.exe

c:\program files (x86)\VMware\VMware Workstation\vmware-authd.exe

c:\windows\SysWOW64\vmnetdhcp.exe

c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

c:\program files (x86)\Bsecure\BSecAMX.exe

c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

.

**************************************************************************

.

Completion time: 2013-02-06 14:06:57 - machine was rebooted

ComboFix-quarantined-files.txt 2013-02-06 22:06

ComboFix2.txt 2013-02-06 15:57

ComboFix3.txt 2013-02-04 23:38

ComboFix4.txt 2013-02-04 15:41

ComboFix5.txt 2013-02-06 21:33

.

Pre-Run: 1,364,054,863,872 bytes free

Post-Run: 1,364,031,709,184 bytes free

.

- - End Of File - - DB9C70B6E4BB0A26D72BDB2C6CE583AB

---------------------------------------

Malwarebytes Anti-Rootkit BETA 1.01.0.1017

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

Java version: 1.6.0_31

File system is: NTFS

Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, Q:\ DRIVE_FIXED

CPU speed: 3.093000 GHz

Memory total: 8571629568, free: 6034702336

------------ Kernel report ------------

02/06/2013 14:10:15

------------ Loaded modules -----------

\SystemRoot\system32\ntoskrnl.exe

\SystemRoot\system32\hal.dll

\SystemRoot\system32\kdcom.dll

\SystemRoot\system32\mcupdate_GenuineIntel.dll

\SystemRoot\system32\PSHED.dll

\SystemRoot\system32\CLFS.SYS

\SystemRoot\system32\CI.dll

\SystemRoot\system32\drivers\Wdf01000.sys

\SystemRoot\system32\drivers\WDFLDR.SYS

\SystemRoot\system32\drivers\ACPI.sys

\SystemRoot\system32\drivers\WMILIB.SYS

\SystemRoot\system32\drivers\msisadrv.sys

\SystemRoot\system32\drivers\pci.sys

\SystemRoot\system32\drivers\vdrvroot.sys

\SystemRoot\System32\drivers\partmgr.sys

\SystemRoot\system32\drivers\volmgr.sys

\SystemRoot\System32\drivers\volmgrx.sys

\SystemRoot\system32\DRIVERS\vmci.sys

\SystemRoot\System32\drivers\mountmgr.sys

\SystemRoot\system32\DRIVERS\iaStor.sys

\SystemRoot\system32\drivers\amdxata.sys

\SystemRoot\system32\drivers\fltmgr.sys

\SystemRoot\system32\drivers\fileinfo.sys

\SystemRoot\system32\drivers\BsecFltr.sys

\SystemRoot\System32\Drivers\Ntfs.sys

\SystemRoot\System32\Drivers\msrpc.sys

\SystemRoot\System32\Drivers\ksecdd.sys

\SystemRoot\System32\Drivers\cng.sys

\SystemRoot\System32\drivers\pcw.sys

\SystemRoot\System32\Drivers\Fs_Rec.sys

\SystemRoot\system32\drivers\ndis.sys

\SystemRoot\system32\drivers\NETIO.SYS

\SystemRoot\System32\Drivers\ksecpkg.sys

\SystemRoot\System32\drivers\tcpip.sys

\SystemRoot\System32\drivers\fwpkclnt.sys

\SystemRoot\system32\drivers\volsnap.sys

\SystemRoot\System32\Drivers\spldr.sys

\SystemRoot\System32\drivers\rdyboost.sys

\SystemRoot\System32\Drivers\mup.sys

\SystemRoot\System32\drivers\hwpolicy.sys

\SystemRoot\System32\DRIVERS\fvevol.sys

\SystemRoot\system32\DRIVERS\disk.sys

\SystemRoot\system32\DRIVERS\CLASSPNP.SYS

\SystemRoot\system32\DRIVERS\cdrom.sys

\SystemRoot\System32\Drivers\Null.SYS

\SystemRoot\System32\Drivers\Beep.SYS

\SystemRoot\System32\drivers\vga.sys

\SystemRoot\System32\drivers\VIDEOPRT.SYS

\SystemRoot\System32\drivers\watchdog.sys

\SystemRoot\System32\DRIVERS\RDPCDD.sys

\SystemRoot\system32\drivers\rdpencdd.sys

\SystemRoot\system32\drivers\rdprefmp.sys

\SystemRoot\System32\Drivers\Msfs.SYS

\SystemRoot\System32\Drivers\Npfs.SYS

\SystemRoot\system32\DRIVERS\tdx.sys

\SystemRoot\system32\DRIVERS\TDI.SYS

\SystemRoot\system32\drivers\afd.sys

\SystemRoot\System32\DRIVERS\netbt.sys

\SystemRoot\system32\drivers\ws2ifsl.sys

\SystemRoot\system32\DRIVERS\wfplwf.sys

\SystemRoot\system32\DRIVERS\pacer.sys

\SystemRoot\system32\DRIVERS\vwififlt.sys

\SystemRoot\system32\DRIVERS\netbios.sys

\SystemRoot\system32\DRIVERS\wanarp.sys

\??\C:\Windows\system32\Drivers\vmm.sys

\SystemRoot\system32\drivers\termdd.sys

\SystemRoot\system32\DRIVERS\rdbss.sys

\SystemRoot\system32\drivers\nsiproxy.sys

\SystemRoot\system32\drivers\mssmbios.sys

\SystemRoot\System32\drivers\discache.sys

\SystemRoot\System32\Drivers\dfsc.sys

\SystemRoot\system32\DRIVERS\blbdrive.sys

\SystemRoot\system32\DRIVERS\tunnel.sys

\SystemRoot\system32\DRIVERS\nvlddmkm.sys

\SystemRoot\System32\Drivers\nvBridge.kmd

\SystemRoot\System32\drivers\dxgkrnl.sys

\SystemRoot\System32\drivers\dxgmms1.sys

\SystemRoot\system32\DRIVERS\HECIx64.sys

\SystemRoot\system32\drivers\usbehci.sys

\SystemRoot\system32\drivers\USBPORT.SYS

\SystemRoot\system32\drivers\HDAudBus.sys

\SystemRoot\system32\DRIVERS\athrx.sys

\SystemRoot\system32\DRIVERS\vwifibus.sys

\SystemRoot\system32\DRIVERS\Rt64win7.sys

\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys

\SystemRoot\system32\DRIVERS\intelppm.sys

\SystemRoot\system32\DRIVERS\VMNetSrv.sys

\SystemRoot\system32\drivers\CompositeBus.sys

\SystemRoot\system32\DRIVERS\AgileVpn.sys

\SystemRoot\system32\DRIVERS\rasl2tp.sys

\SystemRoot\system32\DRIVERS\ndistapi.sys

\SystemRoot\system32\DRIVERS\ndiswan.sys

\SystemRoot\system32\DRIVERS\raspppoe.sys

\SystemRoot\system32\DRIVERS\raspptp.sys

\SystemRoot\system32\DRIVERS\rassstp.sys

\SystemRoot\system32\DRIVERS\hamachi.sys

\SystemRoot\system32\drivers\kbdclass.sys

\SystemRoot\system32\drivers\mouclass.sys

\SystemRoot\system32\drivers\swenum.sys

\SystemRoot\system32\drivers\ks.sys

\SystemRoot\system32\DRIVERS\umbus.sys

\SystemRoot\system32\DRIVERS\vmnetadapter.sys

\SystemRoot\system32\DRIVERS\VMNET.SYS

\SystemRoot\system32\DRIVERS\usbhub.sys

\SystemRoot\System32\Drivers\NDProxy.SYS

\SystemRoot\system32\DRIVERS\stwrt64.sys

\SystemRoot\system32\DRIVERS\portcls.sys

\SystemRoot\system32\DRIVERS\drmk.sys

\SystemRoot\system32\drivers\ksthunk.sys

\SystemRoot\System32\win32k.sys

\SystemRoot\System32\drivers\Dxapi.sys

\SystemRoot\System32\Drivers\crashdmp.sys

\SystemRoot\System32\Drivers\dump_iaStor.sys

\SystemRoot\System32\Drivers\dump_dumpfve.sys

\SystemRoot\system32\DRIVERS\usbccgp.sys

\SystemRoot\system32\DRIVERS\USBD.SYS

\SystemRoot\system32\drivers\hidusb.sys

\SystemRoot\system32\drivers\HIDCLASS.SYS

\SystemRoot\system32\drivers\HIDPARSE.SYS

\SystemRoot\system32\drivers\kbdhid.sys

\SystemRoot\system32\DRIVERS\mouhid.sys

\SystemRoot\system32\DRIVERS\USBSTOR.SYS

\SystemRoot\system32\DRIVERS\monitor.sys

\SystemRoot\System32\TSDDD.dll

\SystemRoot\System32\cdd.dll

\SystemRoot\System32\ATMFD.DLL

\SystemRoot\system32\drivers\luafv.sys

\??\C:\Windows\system32\drivers\mbam.sys

\SystemRoot\system32\DRIVERS\Sftvollh.sys

\SystemRoot\system32\DRIVERS\RMCAST.sys

\SystemRoot\system32\DRIVERS\vmnetbridge.sys

\SystemRoot\system32\DRIVERS\lltdio.sys

\SystemRoot\system32\DRIVERS\nwifi.sys

\SystemRoot\system32\DRIVERS\ndisuio.sys

\SystemRoot\system32\DRIVERS\rspndr.sys

\SystemRoot\system32\DRIVERS\vwifimp.sys

\SystemRoot\system32\drivers\HTTP.sys

\SystemRoot\system32\DRIVERS\bowser.sys

\SystemRoot\System32\drivers\mpsdrv.sys

\SystemRoot\system32\DRIVERS\mrxsmb.sys

\SystemRoot\system32\DRIVERS\mrxsmb10.sys

\SystemRoot\system32\DRIVERS\mrxsmb20.sys

\??\C:\Windows\system32\drivers\hcmon.sys

\??\C:\Windows\system32\drivers\vmx86.sys

\??\C:\Windows\system32\Drivers\rikvm_C6F09094.sys

\SystemRoot\system32\DRIVERS\BSecACFltr.sys

\SystemRoot\system32\drivers\peauth.sys

\SystemRoot\System32\Drivers\secdrv.SYS

\SystemRoot\system32\DRIVERS\Sftfslh.sys

\SystemRoot\system32\DRIVERS\Sftplaylh.sys

\SystemRoot\System32\DRIVERS\srvnet.sys

\SystemRoot\System32\drivers\tcpipreg.sys

\??\C:\Windows\system32\drivers\vmnetuserif.sys

\SystemRoot\SysWOW64\drivers\vstor2-mntapi10-shared.sys

\SystemRoot\System32\DRIVERS\srv2.sys

\SystemRoot\system32\DRIVERS\Sftredirlh.sys

\SystemRoot\System32\DRIVERS\srv.sys

\SystemRoot\system32\drivers\WudfPf.sys

\SystemRoot\system32\DRIVERS\WUDFRd.sys

\SystemRoot\system32\DRIVERS\WSDPrint.sys

\SystemRoot\system32\DRIVERS\WSDScan.sys

\??\C:\Windows\system32\Drivers\PROCEXP113.SYS

\??\C:\Windows\system32\drivers\mbamchameleon.sys

\??\C:\Windows\system32\drivers\mbamswissarmy.sys

\Windows\System32\ntdll.dll

\Windows\System32\smss.exe

\Windows\System32\apisetschema.dll

----------- End -----------

<<<1>>>

Upper Device Name: \Device\Harddisk4\DR4

Upper Device Object: 0xfffffa800bbaa060

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\0000008d\

Lower Device Object: 0xfffffa800bb9b750

Lower Device Driver Name: \Driver\USBSTOR\

Driver name found: USBSTOR

Initialization returned 0x0

Load Function returned 0x0

<<<1>>>

Upper Device Name: \Device\Harddisk3\DR3

Upper Device Object: 0xfffffa800bba9060

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\0000008c\

Lower Device Object: 0xfffffa800bbc4750

Lower Device Driver Name: \Driver\USBSTOR\

Driver name found: USBSTOR

<<<1>>>

Upper Device Name: \Device\Harddisk2\DR2

Upper Device Object: 0xfffffa800bba8060

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\0000008b\

Lower Device Object: 0xfffffa800bb88a20

Lower Device Driver Name: \Driver\USBSTOR\

Driver name found: USBSTOR

<<<1>>>

Upper Device Name: \Device\Harddisk1\DR1

Upper Device Object: 0xfffffa800bbad060

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\0000008a\

Lower Device Object: 0xfffffa800bb86b60

Lower Device Driver Name: \Driver\USBSTOR\

Driver name found: USBSTOR

<<<1>>>

Upper Device Name: \Device\Harddisk0\DR0

Upper Device Object: 0xfffffa8009696060

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\Ide\IAAStorageDevice-1\

Lower Device Object: 0xfffffa80083e4050

Lower Device Driver Name: \Driver\iaStor\

Driver name found: iaStor

Initialization returned 0x0

Load Function returned 0x0

Downloaded database version: v2013.02.06.10

Downloaded database version: v2013.01.23.01

Initializing...

Done!

<<<2>>>

Device number: 0, partition: 2

Physical Sector Size: 512

Drive: 0, DevicePointer: 0xfffffa8009696060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xfffffa80094f6990, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xfffffa8009696060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

DevicePointer: 0xfffffa80083e4050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\

------------ End ----------

Upper DeviceData: 0xfffff8a00e067440, 0xfffffa8009696060, 0xfffffa800dbb9090

Lower DeviceData: 0xfffff8a0130e4520, 0xfffffa80083e4050, 0xfffffa8007a429e0

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Scanning directory: C:\Windows\system32\drivers...

Done!

Drive 0

Scanning MBR on drive 0...

Inspecting partition table:

MBR Signature: 55AA

Disk Signature: 40B3A861

Partition information:

Partition 0 type is Primary (0x7)

Partition is ACTIVE.

Partition starts at LBA: 2048 Numsec = 204800

Partition file system is NTFS

Partition is bootable

Partition 1 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 206848 Numsec = 3879636992

Partition 2 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 3879843840 Numsec = 27183104

Partition 3 type is Empty (0x0)

Partition is NOT ACTIVE.

Partition starts at LBA: 0 Numsec = 0

Disk Size: 2000398934016 bytes

Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-3907009168-3907029168)...

Physical Sector Size: 0

Drive: 1, DevicePointer: 0xfffffa800bbad060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xfffffa800bb9b040, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xfffffa800bbad060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\

DevicePointer: 0xfffffa800bb86b60, DeviceName: \Device\0000008a\, DriverName: \Driver\USBSTOR\

------------ End ----------

Physical Sector Size: 0

Drive: 2, DevicePointer: 0xfffffa800bba8060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xfffffa800bbada50, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xfffffa800bba8060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\

DevicePointer: 0xfffffa800bb88a20, DeviceName: \Device\0000008b\, DriverName: \Driver\USBSTOR\

------------ End ----------

Physical Sector Size: 0

Drive: 3, DevicePointer: 0xfffffa800bba9060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xfffffa800bba8b90, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xfffffa800bba9060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\

DevicePointer: 0xfffffa800bbc4750, DeviceName: \Device\0000008c\, DriverName: \Driver\USBSTOR\

------------ End ----------

Physical Sector Size: 0

Drive: 4, DevicePointer: 0xfffffa800bbaa060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xfffffa800bba9b90, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xfffffa800bbaa060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\

DevicePointer: 0xfffffa800bb9b750, DeviceName: \Device\0000008d\, DriverName: \Driver\USBSTOR\

------------ End ----------

Done!

Performing system, memory and registry scan...

Done!

Scan finished

=======================================

Malwarebytes Anti-Rootkit BETA 1.01.0.1017

www.malwarebytes.org

Database version: v2013.02.06.10

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Shawn :: MICHAEL-HP [administrator]

2/6/2013 2:22:53 PM

mbar-log-2013-02-06 (14-22-53).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 34338

Time elapsed: 11 minute(s), 52 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

Good afternoon QubicComputers,

Your logs appear clean.

I notice you have a few users. Did you create them?

I think your issues are only Cloud-related.

Please run a free online scan with the ESET Online Scanner.

Note: You can use Internet Explorer or Mozilla Firefox for this scan.

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start.
  • When asked, allow the ActiveX control to install.
  • Click Start.
  • Make sure that the option Remove found threats is unchecked and the option Scan unwanted applications is checked.
  • Click Scan.
    Wait for the scan to finish.
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Link to post
Share on other sites

ESETSmartInstaller@High as CAB hook log:

OnlineScanner64.ocx - registred OK

OnlineScanner.ocx - registred OK

# version=8

# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)

# OnlineScanner.ocx=1.0.0.6889

# api_version=3.0.2

# EOSSerial=6ff9aeee12bc764b8e6a1cec8e2a8a8f

# end=finished

# remove_checked=false

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2013-02-07 06:32:33

# local_time=2013-02-07 10:32:33 (-0800, Pacific Standard Time)

# country="United States"

# lang=1033

# osver=6.1.7601 NT Service Pack 1

# compatibility_mode=1023 16777215 0 0 0 0 0 0

# compatibility_mode=5893 16776573 100 94 2613 111805403 0 0

# scanned=1551740

# found=13

# cleaned=0

# scan_time=15399

C:\Old Terrabyte Drive\Shawn's Projects\Drive Backups\New Gateway\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.JAR Win32/Toolbar.MyWebSearch application F0EE29DE36F7EFECE9AEE507B045435584D994F9 I

C:\Old Terrabyte Drive\Users\Shawn\AppData\Local\Temp\softonic-us-silent.exe Win32/Toolbar.Zugo application 9714327B8C52096DA3AD1760030FEDA1E5DE80EC I

C:\Old Terrabyte Drive\Users\Shawn\Desktop\My Projects\installer_directx_uninstaller_0_13_English.exe multiple threats C19D51B62726F632F9D5E32A76F2EB50A1806664 I

C:\Old Terrabyte Drive\Users\Shawn\Documents\installer_cool_edit_pro_2_0_English.exe Win32/Toggle application 26AF5AD9A4637A65F06792DBD48F99E9A44CABB4 I

C:\Old Terrabyte Drive\Users\Shawn\Downloads\miniinstall.exe a variant of Win32/Multibar.AE application D2E81E4FFD141D212954A8DD5EF86736A46BDFBA I

C:\Old Terrabyte Drive\Users\Shawn\FLOPPY.IMG probably unknown TSR.BOOT virus FAE22FAFF2B4EDA30688B94DC8F38BC26CAFDACF I

C:\Users\Shawn.Michael-HP\Downloads\Computer Repair\cnet_EASEUS_Disk_Copy_exe.exe a variant of Win32/InstallCore.D application BB73A63B6F35AEA443B390445FA7030878807E54 I

C:\Users\Shawn.Michael-HP\Downloads\TestSand.bin probably unknown TSR.BOOT virus 9BAE6A486820CE0BD70ADB23C50EDA66508058A6 I

C:\Windows\Installer\{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}\ARPPRODUCTICON.exe Win32/Toolbar.Widgi application 0D6AC74FD0EE9E6E995EE389FE73CC939B691698 I

C:\Windows\Installer\{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe Win32/Toolbar.Widgi application 7E31CD1178F08E384A2587548CF7B1F2F68D825A I

C:\Windows\Installer\{C259BBE2-2531-4387-B5E3-9E6845854272}\ARPPRODUCTICON.exe Win32/Toolbar.Widgi application 3A0B3F06431196D8691FD0A21081E4248C7BAF17 I

C:\Windows\Installer\{C259BBE2-2531-4387-B5E3-9E6845854272}\NewShortcut11_F6FEAF0EA54E4BDF9FCA88B16752D30C.exe Win32/Toolbar.Widgi application C053C5F3873EBB8F5F4E29743B6AC4D7A18332C7 I

C:\Windows\Installer\{C259BBE2-2531-4387-B5E3-9E6845854272}\NewShortcut1_F4FD9C0EEE954F75BF1F96A939632550.exe Win32/Toolbar.Widgi application 3CE70D0B084F95318BDE6672E967A4E6C6FB46FF I

Link to post
Share on other sites

Users folder contents:

All Users: I think this is default

Default: And this one

Default User: And this one (though I'm not sure why there are two different ones)

Lisa: Family User

Michael: Family User

Patrick: Family User

Program Files: Don't know what this is

Public: Think this is default too

Shawn: Not really a user, leftover from initial user creation. Had older computer, moved "Shawn" manually, computer created below user

Shawn.Michael-HP: The actual user

SHAWN~1~MIC: Not exactly sure what this is

UpdatusUser: No idea what this is

Link to post
Share on other sites

Hello QubicComputers,

OK. I just thought I would check with you.

ESET has found a file of interest.

This one:

C:\Old Terrabyte Drive\Shawn's Projects\Drive Backups\New Gateway\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.JAR

Is part of MyWebSearch, one of the most annoying and resilient infections for browsers. I recommend deleting it.

=====

thisisujrt.gif Please download Junkware Removal Tool to your Desktop.

  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.

Link to post
Share on other sites

Here you go:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 4.6.2 (02.02.2013:2)

OS: Windows 7 Home Premium x64

Ran by Shawn on Mon 02/11/2013 at 14:47:12.93

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}

Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}

~~~ Files

Successfully deleted: [File] C:\install.res.1028.dll

Successfully deleted: [File] C:\install.res.1031.dll

Successfully deleted: [File] C:\install.res.1033.dll

Successfully deleted: [File] C:\install.res.1036.dll

Successfully deleted: [File] C:\install.res.1040.dll

Successfully deleted: [File] C:\install.res.1041.dll

Successfully deleted: [File] C:\install.res.1042.dll

Successfully deleted: [File] C:\install.res.2052.dll

Successfully deleted: [File] C:\install.res.3082.dll

~~~ Folders

Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Mon 02/11/2013 at 14:53:28.22

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.