Jump to content

I know I'm infected


Recommended Posts

Hello Malc1966 and welcome to Malwarebytes!

I am D-FRED-BROWN and I will be helping you. :)

Please print or save this topic. It will make it easier for you to follow the instructions and complete all of the necessary steps.

----------Step 1----------------

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!

  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not an option, Skip instead, do not choose Delete unless instructed.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

----------Step 2----------------

Please download Malwarebytes Anti-Rootkit from HERE

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder... mbar-log.txt and system-log.txt

----------Step 3----------------

Please download ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

***IMPORTANT: save ComboFix to your Desktop***

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please go here to see a list of programs that should be disabled.

**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall**

Please include the C:\ComboFix.txt in your next reply for further review.

NOTE: If you receive the message "illegal operation has been attempted on a registry key that has been marked for deletion", just reboot the computer.

----------Step 4----------------

Please download Security Check by screen317 from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

----------Step 5----------------

In your next reply, please include the following:

  • TDSSKiller's logfile
  • MBAR mbar-log.txt and system-log.txt
  • ComboFix's report (C:\ComboFix.txt)
  • Security Check checkup.txt

After that, please let me know: How is your computer running now? Do you have any questions or concerns you'd like me to address? Don't hesitate to ask. :)

-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Note:

Please make sure you are subscribed to this topic: Click on the "Follow This Topic" Button (at the top right of this page), make sure that the "Receive notification" box is checked and that it is set to "Instantly"

-------> Your topic will be closed if you haven't replied within 3 days! <--------

(If I don't respond within 24 hours, please send me a PM)

-DFB

Link to post
Share on other sites

Thanks for the assistance, I have attached all required logs. Can you please let me know the outcome. Thanks again

Saying post too long, therefore I have uploaded the files, hope this is ok.

TDSSKiller.2.8.17.0_26.05.2013_06.46.11_log.txt

TDSSKiller.2.8.17.0_26.05.2013_06.47.08_log.txt

mbar-log-2013-05-26 (06-53-24).txt

system-log.txt

ComboFix.txt

checkup.txt

Link to post
Share on other sites

Malwarebytes Anti-Malware (Trial) 1.75.0.1300

www.malwarebytes.org

Database version: v2013.05.26.02

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Malc :: MALC-PC [administrator]

Protection: Enabled

26/05/2013 09:38:46

mbam-log-2013-05-26 (09-38-46).txt

Scan type: Custom scan (C:\Z™?|)

Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM

Scan options disabled: Memory | Startup | Registry | Heuristics/Extra | P2P

Objects scanned: 0

Time elapsed: 12 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Could you possibly tell me what this file (C:\Z™?|) is please?

Link to post
Share on other sites

Could you possibly tell me what this file (C:\Z™?|) is please?

Never heard of it, I'd just delete it if I were you.

Please run TDSSKiller one more time.

If you see the following entries:

06:49:15.0635 4608 \Device\Harddisk1\DR1 ( TDSS File System )

06:49:15.0635 4608 \Device\Harddisk1\DR1 ( TDSS File System )

I need you to select "Cure" for them. Leave all the other entries alone. Let me know how things go.

Link to post
Share on other sites

Please do the following:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KILLALL::

File::

C:\Z™?|

Reboot::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I shall require in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Please include the newly-created C:\ComboFix.txt in your next reply, and let me know how things are running now

Link to post
Share on other sites

ComboFix 13-05-27.02 - Malc 27/05/2013 17:17:53.2.2 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.2773 [GMT 1:00]

Running from: c:\users\Malc\Downloads\ComboFix.exe

Command switches used :: c:\users\Malc\Desktop\CFScript.txt

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}

AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

FW: McAfee Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}

SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((( Files Created from 2013-04-27 to 2013-05-27 )))))))))))))))))))))))))))))))

.

.

2013-05-27 16:29 . 2013-05-27 16:29 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-05-27 16:05 . 2013-05-27 16:05 964552 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A5938773-3E47-46F8-B73A-FF7BC2477528}\gapaengine.dll

2013-05-27 16:05 . 2013-05-14 00:48 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C923E9FF-510D-49BE-AA7D-84641E9B7750}\mpengine.dll

2013-05-26 06:14 . 2013-05-26 06:14 -------- d-----w- c:\users\Malc\AppData\Roaming\DSite

2013-05-26 05:53 . 2013-05-26 06:12 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)

2013-05-26 05:50 . 2013-05-14 00:48 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-05-23 17:40 . 2013-05-23 17:40 -------- d-----w- c:\program files (x86)\Tweaking.com

2013-05-23 17:32 . 2013-05-23 17:32 12872 ----a-w- c:\windows\system32\bootdelete.exe

2013-05-23 17:25 . 2013-05-23 17:25 -------- d-----w- c:\program files\HitmanPro

2013-05-23 17:25 . 2013-05-23 17:33 -------- d-----w- c:\programdata\HitmanPro

2013-05-23 17:08 . 2013-05-26 08:08 -------- d-----w- c:\program files (x86)\MyPC Backup

2013-05-23 17:06 . 2013-05-23 17:06 -------- d-----w- c:\program files (x86)\Microsoft Security Client

2013-05-23 17:05 . 2013-05-23 17:06 -------- d-----w- c:\program files\Microsoft Security Client

2013-05-22 06:38 . 2013-05-22 06:38 -------- d-----w- c:\users\Malc\AppData\Roaming\CheckPoint

2013-05-22 06:28 . 2013-05-22 06:28 -------- d-----w- c:\programdata\CheckPoint

2013-05-18 15:04 . 2013-05-18 15:04 -------- d-----w- c:\users\Malc\AppData\Roaming\Malwarebytes

2013-05-18 15:03 . 2013-05-18 15:03 -------- d-----w- c:\programdata\Malwarebytes

2013-05-18 15:03 . 2013-05-23 18:10 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-05-18 15:03 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-15 21:58 . 2013-05-05 21:36 17818624 ----a-w- c:\windows\system32\mshtml.dll

2013-05-15 21:58 . 2013-05-05 21:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2013-05-15 21:58 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2013-05-15 20:58 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys

2013-05-12 12:57 . 2012-06-05 07:37 256904 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys

2013-05-12 11:46 . 2012-04-20 15:40 196440 ----a-w- c:\windows\system32\drivers\HipShieldK.sys

2013-05-12 11:45 . 2013-02-19 12:55 10728 ----a-w- c:\windows\system32\drivers\mfeclnk.sys

2013-05-12 11:45 . 2013-05-12 11:46 -------- d-----w- c:\program files (x86)\Common Files\McAfee

2013-05-12 11:45 . 2013-02-19 12:59 70112 ----a-w- c:\windows\system32\drivers\cfwids.sys

2013-05-12 11:45 . 2013-02-19 12:55 106552 ----a-w- c:\windows\system32\drivers\mferkdet.sys

2013-05-12 11:45 . 2013-02-19 12:53 515968 ----a-w- c:\windows\system32\drivers\mfefirek.sys

2013-05-12 11:45 . 2013-02-19 12:53 309840 ----a-w- c:\windows\system32\drivers\mfeavfk.sys

2013-05-12 11:45 . 2013-05-12 11:46 -------- d-----w- c:\program files\Common Files\McAfee

2013-05-12 11:45 . 2013-05-14 07:04 -------- d-----w- c:\program files\McAfee

2013-05-12 11:45 . 2013-05-23 21:41 -------- d-----w- c:\program files (x86)\McAfee

2013-05-12 11:38 . 2013-02-19 12:56 182752 ----a-w- c:\windows\system32\mfevtps.exe

2013-05-12 11:38 . 2013-05-14 11:24 -------- d-----w- c:\programdata\McAfee

2013-05-12 11:24 . 2013-05-12 11:24 -------- d-----w- c:\programdata\Citrix

2013-05-10 23:23 . 2013-05-10 23:23 -------- d-----w- c:\program files (x86)\Citrix

2013-05-10 23:23 . 2013-05-10 23:23 -------- d-----w- c:\users\Malc\AppData\Local\Citrix

2013-05-10 23:18 . 2013-05-10 23:18 -------- d-----w- c:\users\Malc\AppData\Roaming\McAfee

2013-05-10 19:40 . 2013-05-10 19:40 -------- d-----w- c:\users\Malc\AppData\Roaming\Simply Super Software

2013-05-10 19:10 . 2003-02-02 19:06 153088 ----a-w- c:\windows\SysWow64\UNRAR3.dll

2013-05-10 19:10 . 2002-03-06 00:00 75264 ----a-w- c:\windows\SysWow64\unacev2.dll

2013-05-10 19:10 . 2013-05-10 19:10 -------- d-----w- c:\programdata\Simply Super Software

2013-05-10 19:09 . 2013-05-10 19:09 -------- d-----w- c:\users\Malc\AppData\Local\WPFBChanger

2013-05-10 19:04 . 2013-05-12 12:30 -------- d-----w- c:\program files (x86)\Trojan Remover

2013-05-10 18:47 . 2013-05-27 16:04 -------- d-----w- c:\program files (x86)\GridinSoft Trojan Killer

2013-05-10 17:30 . 2013-05-10 17:30 -------- d-----w- c:\users\Malc\AppData\Roaming\SparkTrust

2013-05-10 17:30 . 2013-05-10 17:30 -------- d-----w- c:\users\Malc\AppData\Roaming\DriverCure

2013-05-10 17:30 . 2013-05-10 17:41 -------- d-----w- c:\programdata\SparkTrust

2013-05-10 07:57 . 2013-05-10 07:57 187456 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll

2013-05-08 19:00 . 2013-04-10 03:46 9317456 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76EA5EC2-2E18-4466-A36F-87E27BADBC46}\mpengine.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-17 20:32 . 2012-04-01 09:33 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-05-17 20:32 . 2011-05-14 16:47 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-05-15 22:03 . 2011-02-13 14:38 75016696 ----a-w- c:\windows\system32\MRT.exe

2013-05-10 19:42 . 2012-07-20 19:35 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2013-05-09 21:13 . 2013-02-25 08:13 24576 ----a-w- c:\windows\SysWow64\spcvchm.dll

2013-05-02 15:29 . 2011-02-10 21:32 278800 ------w- c:\windows\system32\MpSigStub.exe

2013-04-13 05:49 . 2013-05-15 20:58 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2013-04-13 05:49 . 2013-05-15 20:58 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2013-04-13 05:49 . 2013-05-15 20:58 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll

2013-04-13 05:49 . 2013-05-15 20:58 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll

2013-04-13 04:45 . 2013-05-15 20:58 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-04-13 04:45 . 2013-05-15 20:58 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-04-12 14:45 . 2013-04-24 20:36 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-03-19 06:04 . 2013-04-11 17:32 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-03-19 05:46 . 2013-04-11 17:32 43520 ----a-w- c:\windows\system32\csrsrv.dll

2013-03-19 05:04 . 2013-04-11 17:32 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-03-19 05:04 . 2013-04-11 17:32 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-03-19 04:47 . 2013-04-11 17:32 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll

2013-03-19 03:06 . 2013-04-11 17:32 112640 ----a-w- c:\windows\system32\smss.exe

2009-12-06 09:18 26624 --sh--w- c:\windows\bfcs2.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ccleaner"="c:\program files\CCleaner\CCleaner64.exe" [2013-04-23 6070040]

"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2013-04-05 59720]

"15EDEB4BE9AC98F66CE83161A51D7C6EE293BF37._service_run"="c:\users\Malc\AppData\Local\Google\Chrome\Application\chrome.exe" [2013-05-23 825808]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]

"AsioThk32Reg"="CTASIO.DLL" [2010-03-18 47104]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]

"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-05-12 1648400]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-03-13 1532992]

"Trend Micro RUBotted V2.0 Beta"="c:\program files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 1103184]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoSearchFilesInStartMenu"= 0 (0x0)

"NoSearchProgramsInStartMenu"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2010-03-18 158808]

R3 cpuz134;cpuz134;c:\users\Malc\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-01-19 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-10-03 79360]

R3 Creative Dolby Digital Live Pack Licensing Service;Creative Dolby Digital Live Pack Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe [2012-01-19 79360]

R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2010-03-18 706648]

R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [2010-03-18 141912]

R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2010-03-18 141912]

R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2010-03-18 681048]

R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2012-04-20 196440]

R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216]

R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2013-02-19 106552]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]

R4 EaseUS Agent;EaseUS Agent Service;c:\program files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2012-12-19 69192]

R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [x]

R4 RUBotSrv;Trend Micro RUBotted Service;c:\program files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2010-12-17 439632]

R4 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-11 1255736]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2012-12-19 58952]

S0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2012-12-19 48200]

S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2013-02-19 340216]

S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2013-01-21 236248]

S1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2012-12-19 18504]

S1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [2012-12-19 189000]

S1 RapportCerberus_50414;RapportCerberus_50414;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\50414\RapportCerberus64_50414.sys [2013-02-09 585944]

S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-01-21 228760]

S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-01-21 357272]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-07-04 238080]

S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-07-04 361984]

S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]

S2 Guard Agent;Guard Agent Service;c:\program files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe [2012-12-19 23624]

S2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\HitmanPro\hmpsched.exe [2013-05-26 109352]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2013-02-19 218760]

S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2013-02-19 182752]

S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]

S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-01-21 1124184]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2013-02-19 70112]

S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [2010-03-18 158808]

S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [2010-03-18 706648]

S3 ctgame;Game Port;c:\windows\system32\DRIVERS\ctgame.sys [2010-03-18 26328]

S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [2010-03-18 681048]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 25928]

S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2013-02-19 515968]

S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-05-10 22528]

S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - mfeavfk01

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-27 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 20:32]

.

2013-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001Core.job

- c:\users\Malc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-26 18:31]

.

2013-05-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001UA.job

- c:\users\Malc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-26 18:31]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

uInternet Settings,ProxyOverride = *.local

TCP: DhcpNameServer = 192.168.1.254

FF - ProfilePath - c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\

FF - prefs.js: browser.search.defaulturl -

FF - prefs.js: browser.search.selectedEngine - Search By ZoneAlarm

FF - prefs.js: browser.startup.homepage - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - ExtSQL: 2013-04-17 16:03; pricepeep@getpricepeep.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\pricepeep@getpricepeep.com.xpi

FF - ExtSQL: 2013-05-22 07:38; donottrack@checkpoint.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\donottrack@checkpoint.com

FF - ExtSQL: 2013-05-22 07:38; ffxtlbr@zonealarm.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\ffxtlbr@zonealarm.com

FF - ExtSQL: !HIDDEN! 2012-10-17 17:19; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=8c87dd910000000000000025226f3af6&q=

FF - user.js: extensions.BabylonToolbar.id - 8c87dd910000000000000025226f3af6

FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}

FF - user.js: extensions.BabylonToolbar.instlDay - 15724

FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.7.2

FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.7.2

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.7.221:02

FF - user.js: extensions.BabylonToolbar.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar.tlbrId - base

FF - user.js: extensions.BabylonToolbar.instlRef - sst

FF - user.js: extensions.BabylonToolbar.dfltLng - en

FF - user.js: extensions.BabylonToolbar_i.excTlbr - false

FF - user.js: extensions.BabylonToolbar.excTlbr - false

FF - user.js: extensions.BabylonToolbar.admin - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109220&tt=0313_5

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar.autoRvrt - false

FF - user.js: extensions.BabylonToolbar.rvrt - false

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.zonealarm.autoRvrt - false

FF - user.js: extensions.zonealarm_i.hmpg - true

FF - user.js: extensions.zonealarm.hmpgUrl - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm.dfltSrch - true

FF - user.js: extensions.zonealarm.srchPrvdr - Search By ZoneAlarm

FF - user.js: extensions.zonealarm.keyWordUrl - hxxp://search.zonealarm.com/search?src=sp&tbid=base2013&Lan=en&q={searchTerms}&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm_i.dnsErr - true

FF - user.js: extensions.zonealarm_i.newTab - true

FF - user.js: extensions.zonealarm.newTabUrl - hxxp://search.zonealarm.com/?src=nt&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=base2013&Lan={dfltLng}&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&&q=

FF - user.js: extensions.zonealarm.id - 8c87dd910000000000000025226f3af6

FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84}

FF - user.js: extensions.zonealarm.instlDay - 15847

FF - user.js: extensions.zonealarm.vrsn - 1.8.3.16

FF - user.js: extensions.zonealarm.vrsni - 1.8.3.16

FF - user.js: extensions.zonealarm_i.vrsnTs - 1.8.3.167:29

FF - user.js: extensions.zonealarm.prtnrId - checkpoint

FF - user.js: extensions.zonealarm.prdct - zonealarm

FF - user.js: extensions.zonealarm.aflt - 5043

FF - user.js: extensions.zonealarm_i.smplGrp - none

FF - user.js: extensions.zonealarm.tlbrId - base2013

FF - user.js: extensions.zonealarm.instlRef - ZLN118157157996617-5043

FF - user.js: extensions.zonealarm.dfltLng - en

FF - user.js: extensions.zonealarm.excTlbr - false

FF - user.js: extensions.zonealarm.admin - false

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,

0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70

"{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54,

07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75

"{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}"=hex:51,66,7a,6c,4c,1d,38,12,c3,8a,99,

0a,e5,db,85,05,f2,8b,4b,7e,f2,58,2e,15

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{27B4851A-3207-45A2-B947-BE8AFE6163AB}"=hex:51,66,7a,6c,4c,1d,38,12,74,86,a7,

23,35,7c,cc,00,c6,51,fd,ca,fb,3f,27,bf

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,

76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,

72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57

"{7DB2D5A0-7241-4E79-B68D-6309F01C5231}"=hex:51,66,7a,6c,4c,1d,38,12,ce,d6,a1,

79,73,3c,17,0b,c9,9b,20,49,f5,42,16,25

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,

b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb

"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,

b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec,

fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,

2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85

"{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e,

51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:05,eb,d3,b9,37,02,ce,01

.

[HKEY_USERS\S-1-5-21-479276331-2682851880-1986698195-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-479276331-2682851880-1986698195-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]

"value"="?\08\00\05\0d\04$?"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\ExpressFiles\EFUpdater.exe

c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

c:\windows\SysWOW64\rundll32.exe

.

**************************************************************************

.

Completion time: 2013-05-27 17:37:18 - machine was rebooted

ComboFix-quarantined-files.txt 2013-05-27 16:37

ComboFix2.txt 2013-05-26 06:42

.

Pre-Run: 115,185,623,040 bytes free

Post-Run: 115,087,450,112 bytes free

.

- - End Of File - - E26AF3FA4B697C6D927B8854C3448FF5

Managed to delete file via booting in Safe mode, still a few minor glitches but thing working a lot better thanks Malcolm

Link to post
Share on other sites

Glad to hear you were able to delete that file.

I'd like to get a few more scans to get rid of any leftover malware:

We need to create a New FULL OTL Report

  • Please download OTL from here if you have not done so already:

    [*]Save it to your desktop.

    [*]Double click on the otlicon.png icon on your desktop.

    [*]Click the "Scan All Users" checkbox.

    [*]Change the "Extra Registry" option to "SafeList"

    [*]Push the runscan.png button.

    [*]Two reports will open, copy and paste them in a reply here:

    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized

Link to post
Share on other sites

We need to run an OTL Fix

  • Please reopen otlicon.png on your desktop.
  • Copy and Paste the following code into the customscanfix.png textbox.

    :OTL
    @Alternate Data Stream - 460 bytes -> C:\Users\Malc\Documents\Regulars Clive.ppp:SummaryInformation
    @Alternate Data Stream - 460 bytes -> C:\Users\Malc\Documents\club tropicana.ppp:SummaryInformation
    @Alternate Data Stream - 452 bytes -> C:\Users\Malc\Documents\Clive Poker.ppp:SummaryInformation
    @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:CB0AACC9
    @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:B3D74A13
    IE - HKU\S-1-5-21-479276331-2682851880-1986698195-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=109220&tt=0313_5&babsrc=SP_ss&mntrId=8c87dd910000000000000025226f3af6
    [2013/01/19 22:02:21 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]


  • Push runfix.png
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click the OK button.
  • A report will open. Copy and Paste that report in your next reply.

--------------------------------

Please do the following:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KILLALL::

Firefox::

FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=8c87dd910000000000000025226f3af6&q=

FF - user.js: extensions.BabylonToolbar.id - 8c87dd910000000000000025226f3af6

FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}

FF - user.js: extensions.BabylonToolbar.instlDay - 15724

FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.7.2

FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.7.2

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.7.221:02

FF - user.js: extensions.BabylonToolbar.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar.tlbrId - base

FF - user.js: extensions.BabylonToolbar.instlRef - sst

FF - user.js: extensions.BabylonToolbar.dfltLng - en

FF - user.js: extensions.BabylonToolbar_i.excTlbr - false

FF - user.js: extensions.BabylonToolbar.excTlbr - false

FF - user.js: extensions.BabylonToolbar.admin - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109220&tt=0313_5

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar.autoRvrt - false

FF - user.js: extensions.BabylonToolbar.rvrt - false

FF - user.js: extensions.BabylonToolbar_i.newTab - false

Reboot::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I shall require in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Please include the newly-created C:\ComboFix.txt in your next reply, and let me know how things are running now

Link to post
Share on other sites

All processes killed

========== OTL ==========

Unable to delete ADS C:\Users\Malc\Documents\Regulars .

Unable to delete ADS C:\Users\Malc\Documents\club .

Unable to delete ADS C:\Users\Malc\Documents\Clive .

ADS C:\ProgramData\TEMP:CB0AACC9 deleted successfully.

ADS C:\ProgramData\TEMP:B3D74A13 deleted successfully.

Registry key HKEY_USERS\S-1-5-21-479276331-2682851880-1986698195-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.

File C:\Program Files not found.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Lauren

->Temp folder emptied: 0 bytes

User: Malc

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 524355 bytes

->Java cache emptied: 11666 bytes

->FireFox cache emptied: 64581455 bytes

->Google Chrome cache emptied: 200231060 bytes

->Apple Safari cache emptied: 0 bytes

->Flash cache emptied: 36750 bytes

User: Public

->Temp folder emptied: 0 bytes

User: Sarah

->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 10972 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 367450 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 253.00 mb

[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Lauren

User: Malc

->Java cache emptied: 0 bytes

User: Public

User: Sarah

Total Java Files Cleaned = 0.00 mb

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Lauren

User: Malc

->Flash cache emptied: 0 bytes

User: Public

User: Sarah

Total Flash Files Cleaned = 0.00 mb

OTL by OldTimer - Version 3.2.69.0 log created on 05282013_212608

Files\Folders moved on Reboot...

C:\Users\Malc\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

ComboFix 13-05-28.02 - Malc 28/05/2013 20:54:32.3.2 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.2227 [GMT 1:00]

Running from: c:\users\Malc\Downloads\ComboFix.exe

Command switches used :: c:\users\Malc\Documents\CFScript.txt

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}

AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

FW: McAfee Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}

SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-28 )))))))))))))))))))))))))))))))

.

.

2013-05-28 20:06 . 2013-05-28 20:06 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-05-28 13:31 . 2013-05-28 13:31 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll

2013-05-28 13:31 . 2013-05-28 13:31 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll

2013-05-28 13:30 . 2013-05-28 13:30 -------- d-----w- c:\program files (x86)\QuickTime

2013-05-28 13:27 . 2013-05-28 13:27 -------- d-----w- c:\program files\iPod

2013-05-28 13:27 . 2013-05-28 13:28 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69

2013-05-28 13:27 . 2013-05-28 13:28 -------- d-----w- c:\program files\iTunes

2013-05-27 17:10 . 2013-05-14 00:48 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{14D8C76B-FCC7-46A6-9806-70A1CCF941DE}\mpengine.dll

2013-05-27 16:05 . 2013-05-27 16:05 964552 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A5938773-3E47-46F8-B73A-FF7BC2477528}\gapaengine.dll

2013-05-26 06:14 . 2013-05-26 06:14 -------- d-----w- c:\users\Malc\AppData\Roaming\DSite

2013-05-26 05:53 . 2013-05-26 06:12 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)

2013-05-26 05:50 . 2013-05-14 00:48 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-05-23 17:40 . 2013-05-23 17:40 -------- d-----w- c:\program files (x86)\Tweaking.com

2013-05-23 17:32 . 2013-05-23 17:32 12872 ----a-w- c:\windows\system32\bootdelete.exe

2013-05-23 17:25 . 2013-05-23 17:25 -------- d-----w- c:\program files\HitmanPro

2013-05-23 17:25 . 2013-05-23 17:33 -------- d-----w- c:\programdata\HitmanPro

2013-05-23 17:08 . 2013-05-26 08:08 -------- d-----w- c:\program files (x86)\MyPC Backup

2013-05-23 17:06 . 2013-05-23 17:06 -------- d-----w- c:\program files (x86)\Microsoft Security Client

2013-05-23 17:05 . 2013-05-23 17:06 -------- d-----w- c:\program files\Microsoft Security Client

2013-05-22 06:38 . 2013-05-22 06:38 -------- d-----w- c:\users\Malc\AppData\Roaming\CheckPoint

2013-05-22 06:28 . 2013-05-22 06:28 -------- d-----w- c:\programdata\CheckPoint

2013-05-18 15:04 . 2013-05-18 15:04 -------- d-----w- c:\users\Malc\AppData\Roaming\Malwarebytes

2013-05-18 15:03 . 2013-05-18 15:03 -------- d-----w- c:\programdata\Malwarebytes

2013-05-18 15:03 . 2013-05-23 18:10 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-05-18 15:03 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-15 21:58 . 2013-05-05 21:36 17818624 ----a-w- c:\windows\system32\mshtml.dll

2013-05-15 21:58 . 2013-05-05 21:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2013-05-15 21:58 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2013-05-15 20:58 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys

2013-05-12 12:57 . 2012-06-05 07:37 256904 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys

2013-05-12 11:46 . 2012-04-20 15:40 196440 ----a-w- c:\windows\system32\drivers\HipShieldK.sys

2013-05-12 11:45 . 2013-02-19 12:55 10728 ----a-w- c:\windows\system32\drivers\mfeclnk.sys

2013-05-12 11:45 . 2013-05-12 11:46 -------- d-----w- c:\program files (x86)\Common Files\McAfee

2013-05-12 11:45 . 2013-02-19 12:59 70112 ----a-w- c:\windows\system32\drivers\cfwids.sys

2013-05-12 11:45 . 2013-02-19 12:55 106552 ----a-w- c:\windows\system32\drivers\mferkdet.sys

2013-05-12 11:45 . 2013-02-19 12:53 515968 ----a-w- c:\windows\system32\drivers\mfefirek.sys

2013-05-12 11:45 . 2013-02-19 12:53 309840 ----a-w- c:\windows\system32\drivers\mfeavfk.sys

2013-05-12 11:45 . 2013-05-12 11:46 -------- d-----w- c:\program files\Common Files\McAfee

2013-05-12 11:45 . 2013-05-14 07:04 -------- d-----w- c:\program files\McAfee

2013-05-12 11:45 . 2013-05-23 21:41 -------- d-----w- c:\program files (x86)\McAfee

2013-05-12 11:38 . 2013-02-19 12:56 182752 ----a-w- c:\windows\system32\mfevtps.exe

2013-05-12 11:38 . 2013-05-14 11:24 -------- d-----w- c:\programdata\McAfee

2013-05-12 11:24 . 2013-05-12 11:24 -------- d-----w- c:\programdata\Citrix

2013-05-10 23:23 . 2013-05-10 23:23 -------- d-----w- c:\program files (x86)\Citrix

2013-05-10 23:23 . 2013-05-10 23:23 -------- d-----w- c:\users\Malc\AppData\Local\Citrix

2013-05-10 23:18 . 2013-05-10 23:18 -------- d-----w- c:\users\Malc\AppData\Roaming\McAfee

2013-05-10 19:40 . 2013-05-10 19:40 -------- d-----w- c:\users\Malc\AppData\Roaming\Simply Super Software

2013-05-10 19:10 . 2003-02-02 19:06 153088 ----a-w- c:\windows\SysWow64\UNRAR3.dll

2013-05-10 19:10 . 2002-03-06 00:00 75264 ----a-w- c:\windows\SysWow64\unacev2.dll

2013-05-10 19:10 . 2013-05-10 19:10 -------- d-----w- c:\programdata\Simply Super Software

2013-05-10 19:09 . 2013-05-10 19:09 -------- d-----w- c:\users\Malc\AppData\Local\WPFBChanger

2013-05-10 19:04 . 2013-05-12 12:30 -------- d-----w- c:\program files (x86)\Trojan Remover

2013-05-10 18:47 . 2013-05-27 16:04 -------- d-----w- c:\program files (x86)\GridinSoft Trojan Killer

2013-05-10 17:30 . 2013-05-10 17:30 -------- d-----w- c:\users\Malc\AppData\Roaming\SparkTrust

2013-05-10 17:30 . 2013-05-10 17:30 -------- d-----w- c:\users\Malc\AppData\Roaming\DriverCure

2013-05-10 17:30 . 2013-05-10 17:41 -------- d-----w- c:\programdata\SparkTrust

2013-05-10 07:57 . 2013-05-10 07:57 187456 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll

2013-05-08 19:00 . 2013-04-10 03:46 9317456 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76EA5EC2-2E18-4466-A36F-87E27BADBC46}\mpengine.dll

2013-05-01 02:59 . 2013-05-01 02:59 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx

2013-05-01 02:59 . 2013-05-01 02:59 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-17 20:32 . 2012-04-01 09:33 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-05-17 20:32 . 2011-05-14 16:47 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-05-15 22:03 . 2011-02-13 14:38 75016696 ----a-w- c:\windows\system32\MRT.exe

2013-05-10 19:42 . 2012-07-20 19:35 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2013-05-09 21:13 . 2013-02-25 08:13 24576 ----a-w- c:\windows\SysWow64\spcvchm.dll

2013-05-02 15:29 . 2011-02-10 21:32 278800 ------w- c:\windows\system32\MpSigStub.exe

2013-04-13 05:49 . 2013-05-15 20:58 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2013-04-13 05:49 . 2013-05-15 20:58 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2013-04-13 05:49 . 2013-05-15 20:58 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll

2013-04-13 05:49 . 2013-05-15 20:58 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll

2013-04-13 04:45 . 2013-05-15 20:58 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-04-13 04:45 . 2013-05-15 20:58 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-04-12 14:45 . 2013-04-24 20:36 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-03-19 06:04 . 2013-04-11 17:32 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-03-19 05:46 . 2013-04-11 17:32 43520 ----a-w- c:\windows\system32\csrsrv.dll

2013-03-19 05:04 . 2013-04-11 17:32 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-03-19 05:04 . 2013-04-11 17:32 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-03-19 04:47 . 2013-04-11 17:32 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll

2013-03-19 03:06 . 2013-04-11 17:32 112640 ----a-w- c:\windows\system32\smss.exe

2009-12-06 09:18 26624 --sh--w- c:\windows\bfcs2.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ccleaner"="c:\program files\CCleaner\CCleaner64.exe" [2013-04-23 6070040]

"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2013-04-05 59720]

"15EDEB4BE9AC98F66CE83161A51D7C6EE293BF37._service_run"="c:\users\Malc\AppData\Local\Google\Chrome\Application\chrome.exe" [2013-05-23 825808]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]

"AsioThk32Reg"="CTASIO.DLL" [2010-03-18 47104]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]

"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-05-12 1648400]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-03-13 1532992]

"Trend Micro RUBotted V2.0 Beta"="c:\program files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 1103184]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-15 152392]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoSearchFilesInStartMenu"= 0 (0x0)

"NoSearchProgramsInStartMenu"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2010-03-18 158808]

R3 cpuz134;cpuz134;c:\users\Malc\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-01-19 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-10-03 79360]

R3 Creative Dolby Digital Live Pack Licensing Service;Creative Dolby Digital Live Pack Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe [2012-01-19 79360]

R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2010-03-18 706648]

R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [2010-03-18 141912]

R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2010-03-18 141912]

R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2010-03-18 681048]

R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2012-04-20 196440]

R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216]

R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2013-02-19 106552]

R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-05-10 22528]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]

R4 EaseUS Agent;EaseUS Agent Service;c:\program files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2012-12-19 69192]

R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [x]

R4 RUBotSrv;Trend Micro RUBotted Service;c:\program files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2010-12-17 439632]

R4 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-11 1255736]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2012-12-19 58952]

S0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2012-12-19 48200]

S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2013-02-19 340216]

S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2013-01-21 236248]

S1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2012-12-19 18504]

S1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [2012-12-19 189000]

S1 RapportCerberus_53984;RapportCerberus_53984;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\53984\RapportCerberus64_53984.sys [2013-05-28 588048]

S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-01-21 228760]

S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-01-21 357272]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-07-04 238080]

S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-07-04 361984]

S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]

S2 Guard Agent;Guard Agent Service;c:\program files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe [2012-12-19 23624]

S2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\HitmanPro\hmpsched.exe [2013-05-26 109352]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2013-02-19 218760]

S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2013-02-19 182752]

S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]

S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-01-21 1124184]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2013-02-19 70112]

S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [2010-03-18 158808]

S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [2010-03-18 706648]

S3 ctgame;Game Port;c:\windows\system32\DRIVERS\ctgame.sys [2010-03-18 26328]

S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [2010-03-18 681048]

S3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys [2013-05-28 32000]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 25928]

S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2013-02-19 515968]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - HITMANPRO37

*Deregistered* - mfeavfk01

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-28 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 20:32]

.

2013-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001Core.job

- c:\users\Malc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-26 18:31]

.

2013-05-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001UA.job

- c:\users\Malc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-26 18:31]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

uInternet Settings,ProxyOverride = *.local

TCP: DhcpNameServer = 192.168.1.254

FF - ProfilePath - c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\

FF - prefs.js: browser.search.defaulturl -

FF - prefs.js: browser.search.selectedEngine - Search By ZoneAlarm

FF - prefs.js: browser.startup.homepage - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - ExtSQL: 2013-04-17 16:03; pricepeep@getpricepeep.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\pricepeep@getpricepeep.com.xpi

FF - ExtSQL: 2013-05-22 07:38; donottrack@checkpoint.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\donottrack@checkpoint.com

FF - ExtSQL: 2013-05-22 07:38; ffxtlbr@zonealarm.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\ffxtlbr@zonealarm.com

FF - ExtSQL: !HIDDEN! 2012-10-17 17:19; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=8c87dd910000000000000025226f3af6&q=

FF - user.js: extensions.BabylonToolbar.id - 8c87dd910000000000000025226f3af6

FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}

FF - user.js: extensions.BabylonToolbar.instlDay - 15724

FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.7.2

FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.7.2

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.7.221:02

FF - user.js: extensions.BabylonToolbar.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar.tlbrId - base

FF - user.js: extensions.BabylonToolbar.instlRef - sst

FF - user.js: extensions.BabylonToolbar.dfltLng - en

FF - user.js: extensions.BabylonToolbar_i.excTlbr - false

FF - user.js: extensions.BabylonToolbar.excTlbr - false

FF - user.js: extensions.BabylonToolbar.admin - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109220&tt=0313_5

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar.autoRvrt - false

FF - user.js: extensions.BabylonToolbar.rvrt - false

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.zonealarm.autoRvrt - false

FF - user.js: extensions.zonealarm_i.hmpg - true

FF - user.js: extensions.zonealarm.hmpgUrl - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm.dfltSrch - true

FF - user.js: extensions.zonealarm.srchPrvdr - Search By ZoneAlarm

FF - user.js: extensions.zonealarm.keyWordUrl - hxxp://search.zonealarm.com/search?src=sp&tbid=base2013&Lan=en&q={searchTerms}&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm_i.dnsErr - true

FF - user.js: extensions.zonealarm_i.newTab - true

FF - user.js: extensions.zonealarm.newTabUrl - hxxp://search.zonealarm.com/?src=nt&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=base2013&Lan={dfltLng}&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&&q=

FF - user.js: extensions.zonealarm.id - 8c87dd910000000000000025226f3af6

FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84}

FF - user.js: extensions.zonealarm.instlDay - 15847

FF - user.js: extensions.zonealarm.vrsn - 1.8.3.16

FF - user.js: extensions.zonealarm.vrsni - 1.8.3.16

FF - user.js: extensions.zonealarm_i.vrsnTs - 1.8.3.167:29

FF - user.js: extensions.zonealarm.prtnrId - checkpoint

FF - user.js: extensions.zonealarm.prdct - zonealarm

FF - user.js: extensions.zonealarm.aflt - 5043

FF - user.js: extensions.zonealarm_i.smplGrp - none

FF - user.js: extensions.zonealarm.tlbrId - base2013

FF - user.js: extensions.zonealarm.instlRef - ZLN118157157996617-5043

FF - user.js: extensions.zonealarm.dfltLng - en

FF - user.js: extensions.zonealarm.excTlbr - false

FF - user.js: extensions.zonealarm.admin - false

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,

0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70

"{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54,

07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75

"{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}"=hex:51,66,7a,6c,4c,1d,38,12,c3,8a,99,

0a,e5,db,85,05,f2,8b,4b,7e,f2,58,2e,15

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{27B4851A-3207-45A2-B947-BE8AFE6163AB}"=hex:51,66,7a,6c,4c,1d,38,12,74,86,a7,

23,35,7c,cc,00,c6,51,fd,ca,fb,3f,27,bf

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,

76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,

72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57

"{7DB2D5A0-7241-4E79-B68D-6309F01C5231}"=hex:51,66,7a,6c,4c,1d,38,12,ce,d6,a1,

79,73,3c,17,0b,c9,9b,20,49,f5,42,16,25

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,

b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb

"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,

b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec,

fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,

2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85

"{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e,

51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:05,eb,d3,b9,37,02,ce,01

.

[HKEY_USERS\S-1-5-21-479276331-2682851880-1986698195-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-479276331-2682851880-1986698195-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]

"value"="?\08\00\05\0d\04$?"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\ExpressFiles\EFUpdater.exe

c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

c:\windows\SysWOW64\rundll32.exe

.

**************************************************************************

.

Completion time: 2013-05-28 21:15:05 - machine was rebooted

ComboFix-quarantined-files.txt 2013-05-28 20:15

ComboFix2.txt 2013-05-27 16:37

ComboFix3.txt 2013-05-26 06:42

.

Pre-Run: 114,488,565,760 bytes free

Post-Run: 114,460,524,544 bytes free

.

- - End Of File - - 94BED69D71565BFD81B03C0F9946C622

Link to post
Share on other sites

Looks like you're clean ;).

Please run this online scan to verify we haven't missed anything:

I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the esetOnline.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetSmartInstallDesktopIcon.png icon on your desktop.

    [*]Check esetAcceptTerms.png

    [*]Click the esetStart.png button.

    [*]Accept any security warnings from your browser.

    [*]Check esetScanArchives.png

    [*]Push the Start button.

    [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

    [*]When the scan completes, push esetListThreats.png

    [*]Push esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

    [*]Push the esetBack.png button.

    [*]Push esetFinish.png

A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Link to post
Share on other sites

C:\Users\All Users\OptimizerPro\runtime.dll Win32/GenUpdater application

C:\Users\Malc\My Documents\Vuze Downloads\Trojan Killer v2.1.5.0 + Patch\Trojan Killer v2.1.5.0-setup.exe probably a variant of Win32/1AntiVirus application

C:\Program Files (x86)\EaseUS\Todo Backup\bin\PxeServer.dll a variant of Win32/TFTPD32.A application cleaned by deleting - quarantined

C:\Program Files (x86)\ExpressFiles\EFUpdater.exe a variant of Win32/YourFileDownloader.B application cleaned by deleting - quarantined

C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe a variant of Win32/ExpressFiles.A application cleaned by deleting - quarantined

C:\Program Files (x86)\ExpressFiles\uninstall.exe a variant of Win32/ExpressFiles.B application cleaned by deleting - quarantined

C:\Program Files (x86)\Vuze\.install4j\i4j_extf_27_5p83tu.dll a variant of Win32/Bunndle application cleaned by deleting - quarantined

C:\ProgramData\OptimizerPro\runtime.dll Win32/GenUpdater application cleaned by deleting - quarantined

C:\Users\Malc\Documents\Vuze Downloads\Trojan Killer v2.1.5.0 + Patch\Trojan Killer v2.1.5.0-setup.exe probably a variant of Win32/1AntiVirus application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\cbsidlm-tr1_13-Garmin_MapSource-ORG-75123302.exe Win32/DownloadAdmin.G application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\cbsidlm-tr1_13-LSPFix-ORG-10417026.exe Win32/DownloadAdmin.G application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\easy_duplicate_setup.exe a variant of Win32/Bundled.Toolbar.Ask.C application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\easy_duplicate_setup_adwords_dupfiles_install.exe a variant of Win32/Bundled.Toolbar.Ask.C application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\FreeEasyCDDVDBurnerSetup-r101-w.exe Win32/Toolbar.SearchSuite application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\gtk2137-setup.exe a variant of Win32/1AntiVirus application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\gtk2159-setup.exe probably a variant of Win32/1AntiVirus application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\ImproveSpeedPC.exe a variant of Win32/Bundled.Toolbar.Ask.C application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\Setup_FreeConverter.exe Win32/Toolbar.SearchSuite application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\tb_free.exe a variant of Win32/TFTPD32.A application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\trojan_killer_2.1_5.0_activation_code_0_downloader_gb_98926.exe a variant of Win32/ExpressFiles.B application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\Tune_sweeper_activation_code_incl_Crack_Downloader (1).exe a variant of Win32/BundleInstaller.B application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\Tune_sweeper_activation_code_incl_Crack_Downloader.exe a variant of Win32/BundleInstaller.B application cleaned by deleting - quarantined

C:\Users\Malc\Downloads\ZipOpenerSetup.exe Win32/InstallCore.BN.Gen application cleaned by deleting - quarantined

G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 19.zip Win32/Adware.Yontoo application deleted - quarantined

G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 23.zip multiple threats deleted - quarantined

G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 24.zip multiple threats deleted - quarantined

G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 25.zip multiple threats deleted - quarantined

G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 26.zip multiple threats deleted - quarantined

G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 94.zip a variant of Win32/TFTPD32.A application deleted - quarantined

ESETSmartInstaller@High as downloader log:

all ok

# version=8

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6920

# api_version=3.0.2

# EOSSerial=3a2be295e924a346af3cef7a7c408aa7

# engine=13949

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=false

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2013-05-29 09:02:40

# local_time=2013-05-29 10:02:40 (+0000, GMT Daylight Time)

# country="United Kingdom"

# lang=1033

# osver=6.1.7601 NT Service Pack 1

# compatibility_mode=5122 16777213 100 90 980973 118643956 0 0

# compatibility_mode=5893 16776574 100 94 1813868 122326410 0 0

# scanned=338461

# found=3

# cleaned=2

# scan_time=9050

sh=3AEF532A0211CE7869F0EB51E940D9E0C7CAE321 ft=1 fh=c7560653d3ee2314 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\Users\All Users\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll"

sh=3AEF532A0211CE7869F0EB51E940D9E0C7CAE321 ft=1 fh=c7560653d3ee2314 vn="a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll"

sh=E6BD65F3D971A489C1D0826655CFAD02A1110514 ft=1 fh=a5612368331ebf3b vn="Win32/Adware.RK.AN application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\Chris_3.exe"

ESETSmartInstaller@High as downloader log:

all ok

# version=8

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6920

# api_version=3.0.2

# EOSSerial=3a2be295e924a346af3cef7a7c408aa7

# engine=13949

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2013-05-30 04:27:08

# local_time=2013-05-30 05:27:08 (+0000, GMT Daylight Time)

# country="United Kingdom"

# lang=1033

# osver=6.1.7601 NT Service Pack 1

# compatibility_mode=5122 16777213 100 90 1007641 118670624 0 0

# compatibility_mode=5893 16776574 100 94 1840536 122353078 0 0

# scanned=338509

# found=29

# cleaned=27

# scan_time=24451

sh=5F83EC091F2E56C574A626FFEF768EFB632D7EDE ft=1 fh=4031d79ff4418eb0 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\OptimizerPro\runtime.dll"

sh=715658D35F536A987F7EB54C4AFA5C8ECB9F215B ft=1 fh=27000f20244aa75a vn="probably a variant of Win32/1AntiVirus application" ac=I fn="C:\Users\Malc\My Documents\Vuze Downloads\Trojan Killer v2.1.5.0 + Patch\Trojan Killer v2.1.5.0-setup.exe"

sh=3ED15B52B8F14C40C063E6E244DC025780C7D1E1 ft=1 fh=a9ca77ffe510d14d vn="a variant of Win32/TFTPD32.A application (cleaned by deleting - quarantined)" ac=C fn="C:\Program Files (x86)\EaseUS\Todo Backup\bin\PxeServer.dll"

sh=36C513B8D860984CDA7C81A6FC4261D8D37A9032 ft=1 fh=6351dabb7e38847a vn="a variant of Win32/YourFileDownloader.B application (cleaned by deleting - quarantined)" ac=C fn="C:\Program Files (x86)\ExpressFiles\EFUpdater.exe"

sh=4295A2EFCA73FFC8AFD9DE8D3CCB4FB5FB5020DD ft=1 fh=c71c0011eee1ed15 vn="a variant of Win32/ExpressFiles.A application (cleaned by deleting - quarantined)" ac=C fn="C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe"

sh=7F3767F94B217247244CD6AF7E835FD37C2A38C3 ft=1 fh=60357334690b4474 vn="a variant of Win32/ExpressFiles.B application (cleaned by deleting - quarantined)" ac=C fn="C:\Program Files (x86)\ExpressFiles\uninstall.exe"

sh=0AC76F0DCEC5A2957E9135A82012933D40AC6A63 ft=1 fh=f9c9bf4621013cb3 vn="a variant of Win32/Bunndle application (cleaned by deleting - quarantined)" ac=C fn="C:\Program Files (x86)\Vuze\.install4j\i4j_extf_27_5p83tu.dll"

sh=5F83EC091F2E56C574A626FFEF768EFB632D7EDE ft=1 fh=4031d79ff4418eb0 vn="Win32/GenUpdater application (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\OptimizerPro\runtime.dll"

sh=715658D35F536A987F7EB54C4AFA5C8ECB9F215B ft=1 fh=27000f20244aa75a vn="probably a variant of Win32/1AntiVirus application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Documents\Vuze Downloads\Trojan Killer v2.1.5.0 + Patch\Trojan Killer v2.1.5.0-setup.exe"

sh=8A893FE3C1376F3C1B0F67A9514CBE621B717D98 ft=1 fh=667b25980f774106 vn="Win32/DownloadAdmin.G application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\cbsidlm-tr1_13-Garmin_MapSource-ORG-75123302.exe"

sh=8A893FE3C1376F3C1B0F67A9514CBE621B717D98 ft=1 fh=667b25980f774106 vn="Win32/DownloadAdmin.G application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\cbsidlm-tr1_13-LSPFix-ORG-10417026.exe"

sh=0C16B9303EA7F820D79CAACE180A28C76BFE7BBC ft=1 fh=ae2b320505ee0638 vn="a variant of Win32/Bundled.Toolbar.Ask.C application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\easy_duplicate_setup.exe"

sh=268BD1CF5284D1166700B061C26D7088A908CB67 ft=1 fh=97fa19f5a4c73f0a vn="a variant of Win32/Bundled.Toolbar.Ask.C application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\easy_duplicate_setup_adwords_dupfiles_install.exe"

sh=C23C05A19CA54671C2D5C64E11237B95093BB32B ft=1 fh=3dfe06a80c5cbf16 vn="Win32/Toolbar.SearchSuite application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\FreeEasyCDDVDBurnerSetup-r101-w.exe"

sh=8BF8ECF9D030EEDB26FDC47A9AC342FB95F5789B ft=1 fh=4020a56609a94d28 vn="a variant of Win32/1AntiVirus application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\gtk2137-setup.exe"

sh=2AC3FC0AE8E7295D7DD8F73A6639ADD98ED10D18 ft=1 fh=9e6f83ef848369f5 vn="probably a variant of Win32/1AntiVirus application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\gtk2159-setup.exe"

sh=8219B90A046E0AEA47AFB0F88D46F7594A38E17C ft=1 fh=591654820a5919f5 vn="a variant of Win32/Bundled.Toolbar.Ask.C application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\ImproveSpeedPC.exe"

sh=C6F83C97FD9BF1B3A19B9D62AB4833319D757D5E ft=1 fh=a7d843b87ec073ee vn="Win32/Toolbar.SearchSuite application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\Setup_FreeConverter.exe"

sh=376CB25C1DD135AB4D3F80023F9D869C42B916BC ft=1 fh=32ded87c6a31c723 vn="a variant of Win32/TFTPD32.A application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\tb_free.exe"

sh=8F0B099D36C18647C54B21BECD3AC6CEA2F3F2D6 ft=1 fh=ba1aae4d5bbf1731 vn="a variant of Win32/ExpressFiles.B application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\trojan_killer_2.1_5.0_activation_code_0_downloader_gb_98926.exe"

sh=3569C189AF9A33F6BA44A09CBF4B8CCA0DEFE466 ft=1 fh=e82f4d89b143c872 vn="a variant of Win32/BundleInstaller.B application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\Tune_sweeper_activation_code_incl_Crack_Downloader (1).exe"

sh=3569C189AF9A33F6BA44A09CBF4B8CCA0DEFE466 ft=1 fh=e82f4d89b143c872 vn="a variant of Win32/BundleInstaller.B application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\Tune_sweeper_activation_code_incl_Crack_Downloader.exe"

sh=2A35544622F2B98A8317570DBE2F7B2398A5150E ft=1 fh=c08717a9609539f6 vn="Win32/InstallCore.BN.Gen application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Malc\Downloads\ZipOpenerSetup.exe"

sh=E6476DFD774EBBBC586FC73537BA762CD2DBC09D ft=0 fh=0000000000000000 vn="Win32/Adware.Yontoo application (deleted - quarantined)" ac=C fn="G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 19.zip"

sh=3ACA2EF59C6B373621E6C0E63CF258C64A8E895A ft=0 fh=0000000000000000 vn="multiple threats (deleted - quarantined)" ac=C fn="G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 23.zip"

sh=CD4382FD5425BD929B3104EDB25A8046BD6A420F ft=0 fh=0000000000000000 vn="multiple threats (deleted - quarantined)" ac=C fn="G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 24.zip"

sh=4AE30E6B386D61EA9D045266DA14189F8C3844CE ft=0 fh=0000000000000000 vn="multiple threats (deleted - quarantined)" ac=C fn="G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 25.zip"

sh=9C5099802326B50596C40AE7B8BBF42042872719 ft=0 fh=0000000000000000 vn="multiple threats (deleted - quarantined)" ac=C fn="G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 26.zip"

sh=D0EA55CEC5730F1DD64A7DAE64DD7C3390E23A4D ft=0 fh=0000000000000000 vn="a variant of Win32/TFTPD32.A application (deleted - quarantined)" ac=C fn="G:\MALC-PC\Backup Set 2013-01-07 190540\Backup Files 2013-01-07 190540\Backup files 94.zip"

Link to post
Share on other sites

ComboFix 13-05-30.02 - Malc 30/05/2013 20:20:15.4.2 - x64 NETWORK

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.3207 [GMT 1:00]

Running from: c:\users\Malc\Downloads\ComboFix.exe

AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}

AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}

SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}

SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-30 )))))))))))))))))))))))))))))))

.

.

2013-05-30 19:28 . 2013-05-30 19:28 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-05-30 18:40 . 2013-05-30 18:40 32000 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys

2013-05-30 05:50 . 2013-05-14 00:48 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{126AF75F-A8C1-481D-99CC-0080E8BB5944}\mpengine.dll

2013-05-30 00:15 . 2013-05-14 00:48 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-05-28 20:26 . 2013-05-28 20:26 -------- d-----w- C:\_OTL

2013-05-28 13:31 . 2013-05-28 13:31 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll

2013-05-28 13:31 . 2013-05-28 13:31 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npqtplugin.dll

2013-05-28 13:31 . 2013-05-28 13:30 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll

2013-05-28 13:30 . 2013-05-28 13:30 -------- d-----w- c:\program files (x86)\QuickTime

2013-05-28 13:27 . 2013-05-28 13:27 -------- d-----w- c:\program files\iPod

2013-05-28 13:27 . 2013-05-28 13:28 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69

2013-05-28 13:27 . 2013-05-28 13:28 -------- d-----w- c:\program files\iTunes

2013-05-27 16:05 . 2013-05-27 16:05 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A5938773-3E47-46F8-B73A-FF7BC2477528}\gapaengine.dll

2013-05-26 06:14 . 2013-05-26 06:14 -------- d-----w- c:\users\Malc\AppData\Roaming\DSite

2013-05-26 05:53 . 2013-05-26 06:12 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)

2013-05-23 17:40 . 2013-05-23 17:40 -------- d-----w- c:\program files (x86)\Tweaking.com

2013-05-23 17:32 . 2013-05-23 17:32 12872 ----a-w- c:\windows\system32\bootdelete.exe

2013-05-23 17:25 . 2013-05-23 17:25 -------- d-----w- c:\program files\HitmanPro

2013-05-23 17:25 . 2013-05-23 17:33 -------- d-----w- c:\programdata\HitmanPro

2013-05-23 17:08 . 2013-05-26 08:08 -------- d-----w- c:\program files (x86)\MyPC Backup

2013-05-23 17:06 . 2013-05-23 17:06 -------- d-----w- c:\program files (x86)\Microsoft Security Client

2013-05-23 17:05 . 2013-05-23 17:06 -------- d-----w- c:\program files\Microsoft Security Client

2013-05-22 06:38 . 2013-05-22 06:38 -------- d-----w- c:\users\Malc\AppData\Roaming\CheckPoint

2013-05-22 06:28 . 2013-05-22 06:28 -------- d-----w- c:\programdata\CheckPoint

2013-05-18 15:04 . 2013-05-18 15:04 -------- d-----w- c:\users\Malc\AppData\Roaming\Malwarebytes

2013-05-18 15:03 . 2013-05-18 15:03 -------- d-----w- c:\programdata\Malwarebytes

2013-05-18 15:03 . 2013-05-23 18:10 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-05-18 15:03 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-05-15 21:58 . 2013-05-05 21:36 17818624 ----a-w- c:\windows\system32\mshtml.dll

2013-05-15 21:58 . 2013-05-05 21:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2013-05-15 21:58 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb

2013-05-15 20:58 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys

2013-05-12 12:57 . 2012-06-05 07:37 256904 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys

2013-05-12 11:46 . 2012-04-20 15:40 196440 ----a-w- c:\windows\system32\drivers\HipShieldK.sys

2013-05-12 11:45 . 2013-02-19 12:55 10728 ----a-w- c:\windows\system32\drivers\mfeclnk.sys

2013-05-12 11:45 . 2013-05-12 11:46 -------- d-----w- c:\program files (x86)\Common Files\McAfee

2013-05-12 11:45 . 2013-02-19 12:59 70112 ----a-w- c:\windows\system32\drivers\cfwids.sys

2013-05-12 11:45 . 2013-02-19 12:55 106552 ----a-w- c:\windows\system32\drivers\mferkdet.sys

2013-05-12 11:45 . 2013-02-19 12:53 515968 ----a-w- c:\windows\system32\drivers\mfefirek.sys

2013-05-12 11:45 . 2013-02-19 12:53 309840 ----a-w- c:\windows\system32\drivers\mfeavfk.sys

2013-05-12 11:45 . 2013-05-12 11:46 -------- d-----w- c:\program files\Common Files\McAfee

2013-05-12 11:45 . 2013-05-14 07:04 -------- d-----w- c:\program files\McAfee

2013-05-12 11:45 . 2013-05-23 21:41 -------- d-----w- c:\program files (x86)\McAfee

2013-05-12 11:38 . 2013-02-19 12:56 182752 ----a-w- c:\windows\system32\mfevtps.exe

2013-05-12 11:38 . 2013-05-14 11:24 -------- d-----w- c:\programdata\McAfee

2013-05-12 11:24 . 2013-05-12 11:24 -------- d-----w- c:\programdata\Citrix

2013-05-10 23:23 . 2013-05-10 23:23 -------- d-----w- c:\program files (x86)\Citrix

2013-05-10 23:23 . 2013-05-10 23:23 -------- d-----w- c:\users\Malc\AppData\Local\Citrix

2013-05-10 23:18 . 2013-05-10 23:18 -------- d-----w- c:\users\Malc\AppData\Roaming\McAfee

2013-05-10 19:40 . 2013-05-10 19:40 -------- d-----w- c:\users\Malc\AppData\Roaming\Simply Super Software

2013-05-10 19:10 . 2003-02-02 19:06 153088 ----a-w- c:\windows\SysWow64\UNRAR3.dll

2013-05-10 19:10 . 2002-03-06 00:00 75264 ----a-w- c:\windows\SysWow64\unacev2.dll

2013-05-10 19:10 . 2013-05-10 19:10 -------- d-----w- c:\programdata\Simply Super Software

2013-05-10 19:09 . 2013-05-10 19:09 -------- d-----w- c:\users\Malc\AppData\Local\WPFBChanger

2013-05-10 19:04 . 2013-05-12 12:30 -------- d-----w- c:\program files (x86)\Trojan Remover

2013-05-10 18:47 . 2013-05-27 16:04 -------- d-----w- c:\program files (x86)\GridinSoft Trojan Killer

2013-05-10 17:30 . 2013-05-10 17:30 -------- d-----w- c:\users\Malc\AppData\Roaming\SparkTrust

2013-05-10 17:30 . 2013-05-10 17:30 -------- d-----w- c:\users\Malc\AppData\Roaming\DriverCure

2013-05-10 17:30 . 2013-05-10 17:41 -------- d-----w- c:\programdata\SparkTrust

2013-05-10 07:57 . 2013-05-10 07:57 187456 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll

2013-05-08 19:00 . 2013-04-10 03:46 9317456 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{76EA5EC2-2E18-4466-A36F-87E27BADBC46}\mpengine.dll

2013-05-01 02:59 . 2013-05-01 02:59 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx

2013-05-01 02:59 . 2013-05-01 02:59 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-17 20:32 . 2012-04-01 09:33 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-05-17 20:32 . 2011-05-14 16:47 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-05-15 22:03 . 2011-02-13 14:38 75016696 ----a-w- c:\windows\system32\MRT.exe

2013-05-10 19:42 . 2012-07-20 19:35 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2013-05-09 21:13 . 2013-02-25 08:13 24576 ----a-w- c:\windows\SysWow64\spcvchm.dll

2013-05-02 15:29 . 2011-02-10 21:32 278800 ------w- c:\windows\system32\MpSigStub.exe

2013-04-13 05:49 . 2013-05-15 20:58 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2013-04-13 05:49 . 2013-05-15 20:58 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2013-04-13 05:49 . 2013-05-15 20:58 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll

2013-04-13 05:49 . 2013-05-15 20:58 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll

2013-04-13 04:45 . 2013-05-15 20:58 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-04-13 04:45 . 2013-05-15 20:58 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-04-12 14:45 . 2013-04-24 20:36 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-03-19 06:04 . 2013-04-11 17:32 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-03-19 05:46 . 2013-04-11 17:32 43520 ----a-w- c:\windows\system32\csrsrv.dll

2013-03-19 05:04 . 2013-04-11 17:32 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-03-19 05:04 . 2013-04-11 17:32 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-03-19 04:47 . 2013-04-11 17:32 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll

2013-03-19 03:06 . 2013-04-11 17:32 112640 ----a-w- c:\windows\system32\smss.exe

2009-12-06 09:18 26624 --sh--w- c:\windows\bfcs2.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ccleaner"="c:\program files\CCleaner\CCleaner64.exe" [2013-04-23 6070040]

"iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2013-04-05 59720]

"15EDEB4BE9AC98F66CE83161A51D7C6EE293BF37._service_run"="c:\users\Malc\AppData\Local\Google\Chrome\Application\chrome.exe" [2013-05-23 825808]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-04 641704]

"AsioThk32Reg"="CTASIO.DLL" [2010-03-18 47104]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]

"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-05-12 1648400]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-03-13 1532992]

"Trend Micro RUBotted V2.0 Beta"="c:\program files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 1103184]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-15 152392]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]

"GrpConv"="grpconv -o" [X]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoSearchFilesInStartMenu"= 0 (0x0)

"NoSearchProgramsInStartMenu"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

.

R0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2013-01-21 236248]

R1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2012-12-19 18504]

R1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [2012-12-19 189000]

R1 RapportCerberus_53984;RapportCerberus_53984;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\53984\RapportCerberus64_53984.sys [2013-05-28 588048]

R1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-01-21 228760]

R1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-01-21 357272]

R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-07-04 238080]

R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-07-04 361984]

R2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 Guard Agent;Guard Agent Service;c:\program files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe [2012-12-19 23624]

R2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\HitmanPro\hmpsched.exe [2013-05-26 109352]

R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]

R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]

R2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-01-21 1124184]

R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [2010-03-18 158808]

R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2010-03-18 158808]

R3 cpuz134;cpuz134;c:\users\Malc\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-01-19 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-10-03 79360]

R3 Creative Dolby Digital Live Pack Licensing Service;Creative Dolby Digital Live Pack Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe [2012-01-19 79360]

R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [2010-03-18 706648]

R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2010-03-18 706648]

R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [2010-03-18 141912]

R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2010-03-18 141912]

R3 ctgame;Game Port;c:\windows\system32\DRIVERS\ctgame.sys [2010-03-18 26328]

R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [2010-03-18 681048]

R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2010-03-18 681048]

R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2012-04-20 196440]

R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys [2013-05-30 32000]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 25928]

R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216]

R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2013-02-19 106552]

R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-05-10 22528]

R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]

R4 EaseUS Agent;EaseUS Agent Service;c:\program files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2012-12-19 69192]

R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [x]

R4 RUBotSrv;Trend Micro RUBotted Service;c:\program files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2010-12-17 439632]

R4 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-11 1255736]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2012-12-19 58952]

S0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2012-12-19 48200]

S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2013-02-19 340216]

S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]

S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2013-02-19 218760]

S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2013-02-19 182752]

S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]

S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2013-02-19 70112]

S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2013-02-19 515968]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-30 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 20:32]

.

2013-05-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001Core.job

- c:\users\Malc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-26 18:31]

.

2013-05-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001UA.job

- c:\users\Malc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-26 18:31]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

uInternet Settings,ProxyOverride = *.local

TCP: DhcpNameServer = 192.168.1.254

FF - ProfilePath - c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\

FF - prefs.js: browser.search.defaulturl -

FF - prefs.js: browser.search.selectedEngine - Search By ZoneAlarm

FF - prefs.js: browser.startup.homepage - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - ExtSQL: 2013-04-17 16:03; pricepeep@getpricepeep.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\pricepeep@getpricepeep.com.xpi

FF - ExtSQL: 2013-05-22 07:38; donottrack@checkpoint.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\donottrack@checkpoint.com

FF - ExtSQL: 2013-05-22 07:38; ffxtlbr@zonealarm.com; c:\users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\ffxtlbr@zonealarm.com

FF - ExtSQL: !HIDDEN! 2012-10-17 17:19; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=8c87dd910000000000000025226f3af6&q=

FF - user.js: extensions.BabylonToolbar.id - 8c87dd910000000000000025226f3af6

FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}

FF - user.js: extensions.BabylonToolbar.instlDay - 15724

FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.7.2

FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.7.2

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.7.221:02

FF - user.js: extensions.BabylonToolbar.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar.tlbrId - base

FF - user.js: extensions.BabylonToolbar.instlRef - sst

FF - user.js: extensions.BabylonToolbar.dfltLng - en

FF - user.js: extensions.BabylonToolbar_i.excTlbr - false

FF - user.js: extensions.BabylonToolbar.excTlbr - false

FF - user.js: extensions.BabylonToolbar.admin - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109220&tt=0313_5

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar.autoRvrt - false

FF - user.js: extensions.BabylonToolbar.rvrt - false

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.zonealarm.autoRvrt - false

FF - user.js: extensions.zonealarm_i.hmpg - true

FF - user.js: extensions.zonealarm.hmpgUrl - hxxp://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm.dfltSrch - true

FF - user.js: extensions.zonealarm.srchPrvdr - Search By ZoneAlarm

FF - user.js: extensions.zonealarm.keyWordUrl - hxxp://search.zonealarm.com/search?src=sp&tbid=base2013&Lan=en&q={searchTerms}&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm_i.dnsErr - true

FF - user.js: extensions.zonealarm_i.newTab - true

FF - user.js: extensions.zonealarm.newTabUrl - hxxp://search.zonealarm.com/?src=nt&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&

FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?src=tb&tbid=base2013&Lan={dfltLng}&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&&q=

FF - user.js: extensions.zonealarm.id - 8c87dd910000000000000025226f3af6

FF - user.js: extensions.zonealarm.appId - {C56C48A0-DA4E-46F6-9859-1553DC865F84}

FF - user.js: extensions.zonealarm.instlDay - 15847

FF - user.js: extensions.zonealarm.vrsn - 1.8.3.16

FF - user.js: extensions.zonealarm.vrsni - 1.8.3.16

FF - user.js: extensions.zonealarm_i.vrsnTs - 1.8.3.167:29

FF - user.js: extensions.zonealarm.prtnrId - checkpoint

FF - user.js: extensions.zonealarm.prdct - zonealarm

FF - user.js: extensions.zonealarm.aflt - 5043

FF - user.js: extensions.zonealarm_i.smplGrp - none

FF - user.js: extensions.zonealarm.tlbrId - base2013

FF - user.js: extensions.zonealarm.instlRef - ZLN118157157996617-5043

FF - user.js: extensions.zonealarm.dfltLng - en

FF - user.js: extensions.zonealarm.excTlbr - false

FF - user.js: extensions.zonealarm.admin - false

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

Wow6432Node-HKLM-RunOnce-<NO NAME> - (no file)

WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)

AddRemove-ExpressFiles - c:\program files (x86)\ExpressFiles\uninstall.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}"=hex:51,66,7a,6c,4c,1d,38,12,26,bd,a8,

0a,e6,f4,22,0e,f1,4c,12,2a,bb,94,a4,70

"{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54,

07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75

"{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}"=hex:51,66,7a,6c,4c,1d,38,12,c3,8a,99,

0a,e5,db,85,05,f2,8b,4b,7e,f2,58,2e,15

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{27B4851A-3207-45A2-B947-BE8AFE6163AB}"=hex:51,66,7a,6c,4c,1d,38,12,74,86,a7,

23,35,7c,cc,00,c6,51,fd,ca,fb,3f,27,bf

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,

76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,

72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57

"{7DB2D5A0-7241-4E79-B68D-6309F01C5231}"=hex:51,66,7a,6c,4c,1d,38,12,ce,d6,a1,

79,73,3c,17,0b,c9,9b,20,49,f5,42,16,25

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{B164E929-A1B6-4A06-B104-2CD0E90A88FF}"=hex:51,66,7a,6c,4c,1d,38,12,47,ea,77,

b5,84,ef,68,0f,ce,12,6f,90,ec,54,cc,eb

"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,

b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec,

fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,

2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85

"{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e,

51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:05,eb,d3,b9,37,02,ce,01

.

[HKEY_USERS\S-1-5-21-479276331-2682851880-1986698195-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-479276331-2682851880-1986698195-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]

"value"="?\08\00\05\0d\04$?"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2013-05-30 20:30:46

ComboFix-quarantined-files.txt 2013-05-30 19:30

ComboFix2.txt 2013-05-28 20:15

ComboFix3.txt 2013-05-27 16:37

ComboFix4.txt 2013-05-26 06:42

.

Pre-Run: 113,505,017,856 bytes free

Post-Run: 113,175,633,920 bytes free

.

- - End Of File - - F610E426F3C79859B6DD361159EDD93F

have had two crashes today. Blue screen and dump files created.

Link to post
Share on other sites

Problem signature:

Problem Event Name: BlueScreen

OS Version: 6.1.7601.2.1.0.768.3

Locale ID: 2057

Additional information about the problem:

BCCode: e1

BCP1: FFFFF80003980D50

BCP2: 0000000000000002

BCP3: FFFFFA800731E060

BCP4: FFFFFA800731E060

OS Version: 6_1_7601

Service Pack: 1_0

Product: 768_1

Files that help describe the problem:

C:\Windows\Minidump\053113-27140-01.dmp

C:\Users\Malc\AppData\Local\Temp\WER-96203-0.sysdata.xml

Details of windows notification on reboot.

It occurs when I try to run Vuze

Link to post
Share on other sites

Latest OTL scan

OTL logfile created on: 09/06/2013 20:30:23 - Run 2

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Malc\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.10.9200.16576)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 2.27 Gb Available Physical Memory | 56.87% Memory free

8.00 Gb Paging File | 5.96 Gb Available in Paging File | 74.54% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 465.66 Gb Total Space | 103.08 Gb Free Space | 22.14% Space Free | Partition Type: NTFS

Drive E: | 149.05 Gb Total Space | 53.41 Gb Free Space | 35.83% Space Free | Partition Type: NTFS

Drive G: | 465.76 Gb Total Space | 285.84 Gb Free Space | 61.37% Space Free | Partition Type: NTFS

Computer Name: MALC-PC | User Name: Malc | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/05/27 20:04:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Malc\Desktop\OTL.exe

PRC - [2013/05/10 08:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

PRC - [2013/04/05 12:59:08 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

PRC - [2013/02/05 16:48:44 | 000,272,248 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe

PRC - [2013/01/21 14:31:00 | 001,124,184 | ---- | M] (Trusteer Ltd.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe

PRC - [2012/12/19 23:54:14 | 000,023,624 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) -- C:\Program Files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe

PRC - [2010/12/17 09:33:06 | 001,103,184 | ---- | M] (Trend Micro Inc.) -- C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe

PRC - [2010/02/12 11:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

PRC - [2009/11/16 17:54:44 | 003,536,904 | ---- | M] (ASRock) -- C:\Program Files (x86)\ASRock Utility\InstantBoot\InstantBoot.exe

========== Modules (No Company Name) ==========

MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

========== Services (SafeList) ==========

SRV:64bit: - [2013/02/25 23:05:10 | 000,384,048 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)

SRV:64bit: - [2013/02/19 13:56:14 | 000,182,752 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)

SRV:64bit: - [2013/02/19 13:53:32 | 000,218,760 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)

SRV:64bit: - [2013/02/19 13:51:54 | 000,241,456 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)

SRV:64bit: - [2013/01/27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)

SRV:64bit: - [2013/01/27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)

SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (MSK80Service)

SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)

SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)

SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)

SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)

SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)

SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)

SRV:64bit: - [2012/07/04 07:20:54 | 000,238,080 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:64bit: - [2012/07/04 02:36:06 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)

SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)

SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV - [2013/05/17 21:32:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/05/10 08:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)

SRV - [2013/02/05 16:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)

SRV - [2013/01/21 14:31:00 | 001,124,184 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)

SRV - [2012/12/19 23:54:14 | 000,023,624 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Auto | Running] -- C:\Program Files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe -- (Guard Agent)

SRV - [2012/12/19 23:54:06 | 000,069,192 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Disabled | Stopped] -- C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe -- (EaseUS Agent)

SRV - [2012/11/06 19:30:07 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)

SRV - [2012/01/19 20:22:03 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe -- (Creative Dolby Digital Live Pack Licensing Service)

SRV - [2012/01/19 20:06:47 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)

SRV - [2011/10/03 12:42:41 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)

SRV - [2010/12/17 09:33:10 | 000,439,632 | ---- | M] (Trend Micro Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe -- (RUBotSrv)

SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2010/02/12 11:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)

SRV - [2009/10/20 19:19:48 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)

SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/06/04 19:20:50 | 000,032,000 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hitmanpro37.sys -- (hitmanpro37)

DRV:64bit: - [2013/02/19 13:59:06 | 000,070,112 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)

DRV:64bit: - [2013/02/19 13:56:26 | 000,340,216 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)

DRV:64bit: - [2013/02/19 13:55:14 | 000,106,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)

DRV:64bit: - [2013/02/19 13:54:32 | 000,771,536 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)

DRV:64bit: - [2013/02/19 13:53:42 | 000,515,968 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)

DRV:64bit: - [2013/02/19 13:53:02 | 000,309,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)

DRV:64bit: - [2013/02/19 13:52:44 | 000,179,280 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)

DRV:64bit: - [2013/01/21 14:31:16 | 000,236,248 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\RapportKE64.sys -- (RapportKE64)

DRV:64bit: - [2013/01/20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)

DRV:64bit: - [2012/12/19 23:54:00 | 000,189,000 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\EuFdDisk.sys -- (EUFDDISK)

DRV:64bit: - [2012/12/19 23:53:58 | 000,048,200 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EUBKMON.sys -- (EUBKMON)

DRV:64bit: - [2012/12/19 23:53:54 | 000,018,504 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\eudskacs.sys -- (EUDSKACS)

DRV:64bit: - [2012/12/19 23:53:52 | 000,058,952 | ---- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\eubakup.sys -- (EUBAKUP)

DRV:64bit: - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)

DRV:64bit: - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV:64bit: - [2012/08/23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)

DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)

DRV:64bit: - [2012/07/04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)

DRV:64bit: - [2012/07/04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)

DRV:64bit: - [2012/07/04 06:10:56 | 000,359,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

DRV:64bit: - [2012/04/20 16:40:58 | 000,196,440 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)

DRV:64bit: - [2012/03/08 18:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)

DRV:64bit: - [2012/03/05 17:04:30 | 000,053,888 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)

DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2012/02/23 13:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)

DRV:64bit: - [2011/05/10 08:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)

DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2010/08/12 12:07:50 | 000,350,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)

DRV:64bit: - [2010/03/19 00:52:18 | 000,295,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\haP17v2k.sys -- (hap17v2k)

DRV:64bit: - [2010/03/19 00:52:10 | 000,259,672 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\haP16v2k.sys -- (hap16v2k)

DRV:64bit: - [2010/03/19 00:52:02 | 001,360,984 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha10kx2k.sys -- (ha10kx2k)

DRV:64bit: - [2010/03/19 00:51:50 | 000,147,544 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)

DRV:64bit: - [2010/03/19 00:51:34 | 000,290,392 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)

DRV:64bit: - [2010/03/19 00:51:26 | 000,016,984 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)

DRV:64bit: - [2010/03/19 00:51:18 | 000,221,272 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)

DRV:64bit: - [2010/03/19 00:51:00 | 000,026,328 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctgame.sys -- (ctgame)

DRV:64bit: - [2010/03/19 00:50:52 | 000,866,264 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k)

DRV:64bit: - [2010/03/19 00:50:42 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)

DRV:64bit: - [2010/03/19 00:40:10 | 000,141,912 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.sys -- (CTERFXFX.SYS)

DRV:64bit: - [2010/03/19 00:40:10 | 000,141,912 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.sys -- (CTERFXFX)

DRV:64bit: - [2010/03/19 00:40:02 | 000,681,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTSBLFX.sys -- (CTSBLFX.SYS)

DRV:64bit: - [2010/03/19 00:40:02 | 000,681,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTSBLFX.sys -- (CTSBLFX)

DRV:64bit: - [2010/03/19 00:39:54 | 000,706,648 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTAUDFX.sys -- (CTAUDFX.SYS)

DRV:64bit: - [2010/03/19 00:39:54 | 000,706,648 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTAUDFX.sys -- (CTAUDFX)

DRV:64bit: - [2010/03/19 00:39:44 | 000,158,808 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\COMMONFX.sys -- (COMMONFX.SYS)

DRV:64bit: - [2010/03/19 00:39:44 | 000,158,808 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\COMMONFX.sys -- (COMMONFX)

DRV:64bit: - [2010/02/18 10:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)

DRV:64bit: - [2009/10/20 19:19:54 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)

DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/06/10 21:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)

DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV - [2013/05/28 13:51:48 | 000,588,048 | ---- | M] () [Kernel | System | Running] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\53984\RapportCerberus64_53984.sys -- (RapportCerberus_53984)

DRV - [2013/01/21 14:31:18 | 000,228,760 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys -- (RapportEI64)

DRV - [2013/01/21 14:31:16 | 000,357,272 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys -- (RapportPG64)

DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKLM\..\URLSearchHook: - No CLSID value found

IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\..\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms}

IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms}

IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10005&barid={38737D42-6278-11E2-8553-0025226F3AF6}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1D AD 60 C2 2C C9 CB 01 [binary data]

IE - HKCU\..\SearchScopes,DefaultScope = {14AE9B60-76BE-4B6B-8DBA-27EF1647705F}

IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR

IE - HKCU\..\SearchScopes\{14AE9B60-76BE-4B6B-8DBA-27EF1647705F}: "URL" = http://search.zonealarm.com/search?src=sp&tbid=base2013&Lan=en&q={searchTerms}&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&&r=218

IE - HKCU\..\SearchScopes\{17FA2733-8382-445B-A2C6-5F25F277BF40}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaulturl: ""

FF - prefs.js..browser.search.selectedEngine: "Search By ZoneAlarm"

FF - prefs.js..browser.startup.homepage: "http://search.zonealarm.com/?src=hp&tbid=base2013&Lan=en&gu=d5aaffebb3c04a17bebc62b79b03fe8c&tu=11JL0008B2B000s&sku=&tstsId=&ver=&"

FF - prefs.js..extensions.enabledAddons: {5C46D283-ABDE-4dce-B83C-08881401921C}:2.1.8.2

FF - prefs.js..extensions.enabledAddons: donottrack@checkpoint.com:2.2.5.1213

FF - prefs.js..extensions.enabledAddons: ffxtlbr@zonealarm.com:1.6.0

FF - prefs.js..extensions.enabledAddons: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.6.0

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)

FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()

FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll File not found

FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll File not found

FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll File not found

FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Malc\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Malc\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2013/05/14 20:17:26 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/10/17 17:19:56 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ntfdsaftsfdfdxx@mozilla.org: C:\Users\Malc\AppData\Roaming\iPumper\extension_firefox.xpi

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/28 14:31:02 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/28 14:31:02 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013/05/22 20:16:18 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/10/17 17:19:56 | 000,000,000 | ---D | M]

[2012/12/11 21:09:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Extensions

[2012/12/11 21:09:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com

[2011/03/31 14:19:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org

[2013/04/11 23:36:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\extensions

[2013/05/22 07:53:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions

[2013/05/22 07:53:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions

[2013/05/22 07:38:36 | 000,000,000 | ---D | M] (ZoneAlarm Do Not Track) -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\donottrack@checkpoint.com

[2013/05/22 07:53:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\wjfbbvx9.default\extensions

[2013/01/27 21:45:37 | 000,234,233 | ---- | M] () (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi

[2013/05/22 07:37:28 | 000,007,919 | ---- | M] () (No name found) -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\extensions\donottrack@checkpoint.com\chrome\content\ff\view_expiry.js

[2013/01/19 22:02:34 | 000,002,432 | ---- | M] () -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\searchplugins\babylon1.xml

[2013/05/22 07:28:54 | 000,001,488 | ---- | M] () -- C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\searchplugins\zonealarm.xml

[2013/01/19 22:02:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2013/01/19 22:02:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com

[2013/05/14 20:17:26 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR

File not found (No name found) -- C:\USERS\MALC\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G6LZVSSG.DEFAULT-1358192917276\EXTENSIONS\FFXTLBR@ZONEALARM.COM

[2012/11/06 19:30:07 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2011/12/09 18:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll

[2012/07/18 14:09:09 | 000,001,525 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml

[2012/09/06 23:57:02 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

[2012/07/18 14:09:09 | 000,000,935 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml

[2012/07/18 14:09:09 | 000,001,166 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml

[2012/02/18 16:11:10 | 000,002,519 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml

[2012/10/16 19:51:54 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

[2012/07/18 14:09:09 | 000,001,121 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}

CHR - homepage: http://www.google.co.uk/

CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Malc\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Users\Malc\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Malc\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll

CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\McChPlg.dll

CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll

CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.13.20.29_0\plugins/np-cwmp.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll

CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll

CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll

CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll

CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll

CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll

CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll

CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll

CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL

CHR - plugin: Java Platform SE 7 U9 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll

CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

CHR - plugin: Google Update (Enabled) = C:\Users\Malc\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll

CHR - plugin: Java Deployment Toolkit 7.0.70.10 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll

CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL

CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

O1 HOSTS File: ([2013/06/04 20:07:01 | 000,000,855 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2:64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)

O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)

O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No CLSID value found.

O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\Run: [AsioThk32Reg] C:\Windows\SysWow64\ctasio.dll (Creative Technology Ltd)

O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)

O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [Trend Micro RUBotted V2.0 Beta] C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe (Trend Micro Inc.)

O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchFilesInStartMenu = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSearchProgramsInStartMenu = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)

O13 - gopher Prefix: missing

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{487C8E04-38C4-4E22-A9A5-B80676E2396D}: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9AE21BB6-5F1D-4202-89E3-2DA9CB380748}: DhcpNameServer = 82.132.254.2 82.132.254.3

O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O18:64bit: - Protocol\Handler\ms-help - No CLSID value found

O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)

O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found

O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)

O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)

O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)

O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\SYSTEM32\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKCU\...com [@ = comfile] -- Reg Error: Key error. File not found

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/09 20:02:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

[2013/06/04 20:37:28 | 001,054,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe

[2013/06/04 20:37:27 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll

[2013/06/04 20:37:27 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll

[2013/06/04 20:37:27 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe

[2013/06/04 20:37:26 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll

[2013/06/04 20:37:26 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll

[2013/06/04 20:37:26 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe

[2013/06/04 20:37:26 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe

[2013/06/04 20:37:26 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll

[2013/06/04 20:37:26 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll

[2013/06/04 20:37:26 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll

[2013/06/04 20:37:25 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll

[2013/06/04 20:37:25 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe

[2013/06/04 20:37:25 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll

[2013/06/04 20:37:25 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll

[2013/06/04 20:37:25 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe

[2013/06/04 20:37:24 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll

[2013/06/04 20:37:24 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll

[2013/06/04 20:37:24 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll

[2013/06/04 20:37:24 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe

[2013/06/04 20:37:24 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll

[2013/06/04 20:37:22 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl

[2013/06/04 20:37:22 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat

[2013/06/04 20:37:22 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll

[2013/06/04 20:37:22 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec

[2013/06/04 20:37:22 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll

[2013/06/04 20:37:22 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll

[2013/06/04 20:37:22 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx

[2013/06/04 20:37:22 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll

[2013/06/04 20:37:21 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll

[2013/06/04 20:37:21 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll

[2013/06/04 20:37:20 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat

[2013/06/04 20:37:20 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll

[2013/06/04 20:37:20 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll

[2013/06/04 20:37:20 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec

[2013/06/04 20:37:20 | 000,281,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll

[2013/06/04 20:37:20 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll

[2013/06/04 20:37:20 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll

[2013/06/04 20:37:20 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe

[2013/06/04 20:37:20 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll

[2013/06/04 20:37:20 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe

[2013/06/04 20:37:20 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll

[2013/06/04 20:37:19 | 001,509,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl

[2013/06/04 20:37:19 | 000,905,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll

[2013/06/04 20:37:19 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll

[2013/06/04 20:37:19 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll

[2013/06/04 20:37:19 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe

[2013/06/04 20:37:19 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe

[2013/06/04 20:37:19 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll

[2013/06/04 20:37:19 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll

[2013/06/04 20:37:19 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll

[2013/06/04 20:37:19 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll

[2013/06/04 20:37:18 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll

[2013/06/04 20:37:18 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll

[2013/06/04 20:37:18 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe

[2013/06/04 20:37:18 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll

[2013/06/04 20:37:18 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll

[2013/06/04 20:37:18 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll

[2013/06/04 20:37:18 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe

[2013/06/04 20:37:17 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll

[2013/06/04 20:37:17 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll

[2013/06/04 20:37:17 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll

[2013/06/04 20:37:17 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe

[2013/06/04 20:37:17 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll

[2013/06/04 20:37:17 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe

[2013/06/04 20:37:16 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll

[2013/06/04 20:37:16 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll

[2013/06/04 20:37:16 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx

[2013/06/04 20:26:07 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\catroot2

[2013/06/04 20:25:30 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution

[2013/06/04 20:21:45 | 000,000,000 | ---D | C] -- C:\Windows\temp

[2013/06/04 20:06:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Uninstall Information

[2013/06/04 19:59:04 | 000,181,064 | ---- | C] (Sysinternals) -- C:\Windows\PSEXESVC.EXE

[2013/06/04 19:56:39 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN

[2013/06/04 19:56:28 | 000,000,000 | --SD | C] -- C:\ComboFix

[2013/05/28 21:26:08 | 000,000,000 | ---D | C] -- C:\_OTL

[2013/05/28 14:30:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime

[2013/05/28 14:30:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime

[2013/05/28 14:28:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes

[2013/05/28 14:27:24 | 000,000,000 | ---D | C] -- C:\Program Files\iPod

[2013/05/28 14:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes

[2013/05/28 14:27:23 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

[2013/05/28 14:23:53 | 000,000,000 | ---D | C] -- C:\Config.Msi

[2013/05/27 20:50:19 | 000,000,000 | ---D | C] -- C:\Users\Malc\AppData\Local\{2798793C-0A3C-4EF8-86CC-CD2D05F20F77}

[2013/05/27 20:03:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Malc\Desktop\OTL.exe

[2013/05/26 07:17:23 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe

[2013/05/26 07:17:23 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe

[2013/05/26 07:17:22 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe

[2013/05/26 07:17:07 | 000,000,000 | ---D | C] -- C:\Qoobox

[2013/05/26 07:16:43 | 000,000,000 | ---D | C] -- C:\Windows\erdnt

[2013/05/26 07:14:55 | 000,000,000 | ---D | C] -- C:\Users\Malc\AppData\Roaming\DSite

[2013/05/26 06:53:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)

[2013/05/26 06:46:52 | 002,240,352 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Malc\Desktop\tdsskiller (1).exe

[2013/05/23 18:40:55 | 000,000,000 | ---D | C] -- C:\Users\Malc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com

[2013/05/23 18:40:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tweaking.com

[2013/05/23 18:25:24 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro

[2013/05/23 18:08:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyPC Backup

[2013/05/23 18:06:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client

[2013/05/23 18:05:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client

[2013/05/22 07:38:54 | 000,000,000 | ---D | C] -- C:\Users\Malc\AppData\Roaming\CheckPoint

[2013/05/22 07:28:43 | 000,000,000 | ---D | C] -- C:\ProgramData\CheckPoint

[2013/05/18 16:04:04 | 000,000,000 | ---D | C] -- C:\Users\Malc\AppData\Roaming\Malwarebytes

[2013/05/18 16:03:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2013/05/17 20:14:59 | 000,000,000 | R--D | C] -- C:\Users\Malc\Saved Games

[2013/05/15 21:58:50 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys

[2013/05/15 21:58:50 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll

[2013/05/15 21:58:35 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll

[2013/05/15 21:58:35 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll

[2013/05/15 21:58:34 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll

[2013/05/15 21:58:34 | 000,111,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe

[2013/05/15 21:58:17 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll

[2013/05/12 14:08:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro RUBotted

[2013/05/12 13:57:50 | 000,256,904 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysWow64\drivers\tmcomm.sys

[2013/05/12 12:46:27 | 000,196,440 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\HipShieldK.sys

[2013/05/12 12:46:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee.com

[2013/05/12 12:45:54 | 000,010,728 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeclnk.sys

[2013/05/12 12:45:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\McAfee

[2013/05/12 12:45:50 | 000,515,968 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfefirek.sys

[2013/05/12 12:45:50 | 000,309,840 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeavfk.sys

[2013/05/12 12:45:50 | 000,106,552 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mferkdet.sys

[2013/05/12 12:45:50 | 000,070,112 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\cfwids.sys

[2013/05/12 12:45:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee

[2013/05/12 12:45:38 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee.com

[2013/05/12 12:45:38 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee

[2013/05/12 12:45:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee

[2013/05/12 12:38:53 | 000,182,752 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\mfevtps.exe

[2013/05/12 12:38:49 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee

[2013/05/12 12:24:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Citrix

[2013/05/11 00:23:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Citrix

[2013/05/11 00:23:44 | 000,000,000 | ---D | C] -- C:\Users\Malc\AppData\Local\Citrix

[2013/05/11 00:18:44 | 000,000,000 | ---D | C] -- C:\Users\Malc\AppData\Roaming\McAfee

========== Files - Modified Within 30 Days ==========

[2013/06/09 20:32:06 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job

[2013/06/09 19:49:06 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001UA.job

[2013/06/09 15:13:46 | 000,014,832 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2013/06/09 15:13:46 | 000,014,832 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2013/06/09 10:40:02 | 000,033,960 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000001-00000000-00000008-00001102-00000004-00511102}.rfx

[2013/06/09 10:40:02 | 000,033,960 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000001-00000000-00000008-00001102-00000004-00511102}.rfx

[2013/06/09 10:40:02 | 000,029,100 | ---- | M] () -- C:\Windows\SysNative\BMXCtrlState-{00000001-00000000-00000008-00001102-00000004-00511102}.rfx

[2013/06/09 10:40:02 | 000,029,100 | ---- | M] () -- C:\Windows\SysNative\BMXBkpCtrlState-{00000001-00000000-00000008-00001102-00000004-00511102}.rfx

[2013/06/09 10:40:02 | 000,011,564 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000001-00000000-00000008-00001102-00000004-00511102}.rfx

[2013/06/09 10:38:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2013/06/09 10:38:03 | 3220,676,608 | -HS- | M] () -- C:\hiberfil.sys

[2013/06/05 22:28:51 | 545,013,721 | ---- | M] () -- C:\Windows\MEMORY.DMP

[2013/06/05 22:01:51 | 000,002,358 | ---- | M] () -- C:\Users\Malc\Desktop\Google Chrome.lnk

[2013/06/05 13:04:04 | 000,779,306 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2013/06/05 13:04:04 | 000,664,548 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2013/06/05 13:04:04 | 000,125,284 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2013/06/05 00:49:03 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-479276331-2682851880-1986698195-1001Core.job

[2013/06/04 20:37:28 | 001,054,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe

[2013/06/04 20:37:27 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll

[2013/06/04 20:37:27 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll

[2013/06/04 20:37:27 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe

[2013/06/04 20:37:26 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll

[2013/06/04 20:37:26 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll

[2013/06/04 20:37:26 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe

[2013/06/04 20:37:26 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe

[2013/06/04 20:37:26 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll

[2013/06/04 20:37:26 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll

[2013/06/04 20:37:26 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll

[2013/06/04 20:37:25 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll

[2013/06/04 20:37:25 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe

[2013/06/04 20:37:25 | 000,125,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll

[2013/06/04 20:37:25 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll

[2013/06/04 20:37:25 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll

[2013/06/04 20:37:25 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe

[2013/06/04 20:37:24 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll

[2013/06/04 20:37:24 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll

[2013/06/04 20:37:24 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe

[2013/06/04 20:37:24 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll

[2013/06/04 20:37:22 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl

[2013/06/04 20:37:22 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat

[2013/06/04 20:37:22 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll

[2013/06/04 20:37:22 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec

[2013/06/04 20:37:22 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll

[2013/06/04 20:37:22 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll

[2013/06/04 20:37:22 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx

[2013/06/04 20:37:22 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll

[2013/06/04 20:37:22 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll

[2013/06/04 20:37:21 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll

[2013/06/04 20:37:21 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf

[2013/06/04 20:37:20 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat

[2013/06/04 20:37:20 | 000,762,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll

[2013/06/04 20:37:20 | 000,452,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll

[2013/06/04 20:37:20 | 000,441,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec

[2013/06/04 20:37:20 | 000,281,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll

[2013/06/04 20:37:20 | 000,216,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll

[2013/06/04 20:37:20 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll

[2013/06/04 20:37:20 | 000,089,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe

[2013/06/04 20:37:20 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll

[2013/06/04 20:37:20 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe

[2013/06/04 20:37:20 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll

[2013/06/04 20:37:19 | 001,509,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl

[2013/06/04 20:37:19 | 000,905,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll

[2013/06/04 20:37:19 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll

[2013/06/04 20:37:19 | 000,599,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll

[2013/06/04 20:37:19 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll

[2013/06/04 20:37:19 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe

[2013/06/04 20:37:19 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe

[2013/06/04 20:37:19 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll

[2013/06/04 20:37:19 | 000,097,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll

[2013/06/04 20:37:19 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll

[2013/06/04 20:37:19 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll

[2013/06/04 20:37:19 | 000,025,185 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf

[2013/06/04 20:37:18 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll

[2013/06/04 20:37:18 | 000,173,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe

[2013/06/04 20:37:18 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll

[2013/06/04 20:37:18 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll

[2013/06/04 20:37:18 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll

[2013/06/04 20:37:18 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll

[2013/06/04 20:37:18 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe

[2013/06/04 20:37:17 | 003,958,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll

[2013/06/04 20:37:17 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll

[2013/06/04 20:37:17 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe

[2013/06/04 20:37:17 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll

[2013/06/04 20:37:17 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe

[2013/06/04 20:37:16 | 000,526,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll

[2013/06/04 20:37:16 | 000,136,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll

[2013/06/04 20:37:16 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx

[2013/06/04 20:22:14 | 000,424,608 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2013/06/04 20:20:37 | 000,181,064 | ---- | M] (Sysinternals) -- C:\Windows\PSEXESVC.EXE

[2013/06/04 20:07:01 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts

[2013/06/04 19:20:50 | 000,032,000 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys

[2013/06/04 19:11:05 | 000,004,776 | ---- | M] () -- C:\Windows\SysNative\.crusader

[2013/05/30 19:27:08 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk

[2013/05/30 19:27:08 | 000,001,808 | ---- | M] () -- C:\Users\Malc\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk

[2013/05/30 19:25:33 | 000,000,000 | ---- | M] () -- C:\END

[2013/05/28 21:09:27 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts_bak_955

[2013/05/28 14:30:48 | 000,001,805 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk

[2013/05/28 14:28:23 | 000,001,743 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk

[2013/05/27 20:04:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Malc\Desktop\OTL.exe

[2013/05/26 09:41:36 | 000,013,423 | ---- | M] () -- C:\Users\Malc\Desktop\ComboFix - Shortcut.lnk

[2013/05/26 06:46:54 | 002,240,352 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Malc\Desktop\tdsskiller (1).exe

[2013/05/23 18:40:58 | 000,002,119 | ---- | M] () -- C:\Users\Malc\Desktop\Tweaking.com - Windows Repair (All in One).lnk

[2013/05/23 18:06:17 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif

[2013/05/22 07:00:08 | 000,000,154 | ---- | M] () -- C:\Windows\Reimage.ini

[2013/05/17 21:32:16 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe

[2013/05/17 21:32:16 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

[2013/05/12 14:08:55 | 000,002,060 | ---- | M] () -- C:\Users\Malc\Desktop\RUBotted.lnk

[2013/05/12 14:05:42 | 000,196,742 | ---- | M] () -- C:\Users\Malc\AppData\Local\census.cache

[2013/05/12 14:05:36 | 000,116,630 | ---- | M] () -- C:\Users\Malc\AppData\Local\ars.cache

[2013/05/12 13:57:20 | 000,000,036 | ---- | M] () -- C:\Users\Malc\AppData\Local\housecall.guid.cache

[2013/05/12 13:45:48 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk

[2013/05/12 12:46:52 | 000,001,900 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk

========== Files Created - No Company Name ==========

[2013/06/05 22:28:51 | 545,013,721 | ---- | C] () -- C:\Windows\MEMORY.DMP

[2013/06/04 20:37:21 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf

[2013/06/04 20:37:19 | 000,025,185 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf

[2013/06/04 19:20:50 | 000,032,000 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys

[2013/06/04 19:11:05 | 000,004,776 | ---- | C] () -- C:\Windows\SysNative\.crusader

[2013/05/28 14:30:48 | 000,001,805 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk

[2013/05/28 14:28:23 | 000,001,743 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk

[2013/05/26 09:41:36 | 000,013,423 | ---- | C] () -- C:\Users\Malc\Desktop\ComboFix - Shortcut.lnk

[2013/05/26 07:17:23 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe

[2013/05/26 07:17:23 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe

[2013/05/26 07:17:23 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe

[2013/05/26 07:17:23 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe

[2013/05/26 07:17:22 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe

[2013/05/23 18:40:58 | 000,002,119 | ---- | C] () -- C:\Users\Malc\Desktop\Tweaking.com - Windows Repair (All in One).lnk

[2013/05/23 18:06:17 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif

[2013/05/23 18:06:11 | 000,002,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk

[2013/05/22 06:58:36 | 000,000,154 | ---- | C] () -- C:\Windows\Reimage.ini

[2013/05/12 14:08:55 | 000,002,060 | ---- | C] () -- C:\Users\Malc\Desktop\RUBotted.lnk

[2013/05/12 14:05:42 | 000,196,742 | ---- | C] () -- C:\Users\Malc\AppData\Local\census.cache

[2013/05/12 14:05:36 | 000,116,630 | ---- | C] () -- C:\Users\Malc\AppData\Local\ars.cache

[2013/05/12 13:57:20 | 000,000,036 | ---- | C] () -- C:\Users\Malc\AppData\Local\housecall.guid.cache

[2013/05/12 12:46:48 | 000,001,900 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk

[2013/02/27 01:18:31 | 000,764,774 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2013/02/25 18:01:34 | 000,177,664 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL

[2013/02/25 18:01:34 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL

[2013/02/25 09:13:26 | 000,000,099 | ---- | C] () -- C:\Windows\SysWow64\SAFEPCVER.INI

[2013/02/25 09:13:25 | 000,000,279 | ---- | C] () -- C:\Windows\SAFEPCCL.INI

[2013/02/25 09:13:15 | 000,002,663 | ---- | C] () -- C:\Windows\SAFEPCSTR.INI

[2012/11/06 21:19:34 | 003,260,928 | ---- | C] () -- C:\Users\Malc\Audioburst_FX_System_2_-_FREEWARE.exe

[2012/10/17 17:14:04 | 000,164,914 | ---- | C] () -- C:\Windows\hpoins29.dat

[2012/10/17 17:14:04 | 000,000,457 | ---- | C] () -- C:\Windows\hpomdl29.dat

[2012/08/01 18:20:14 | 000,484,352 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll

[2012/07/04 06:34:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat

[2012/07/04 06:34:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat

[2012/06/20 22:48:50 | 000,007,609 | ---- | C] () -- C:\Users\Malc\AppData\Local\Resmon.ResmonCfg

[2012/04/18 20:39:10 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll

[2012/04/13 22:07:55 | 001,460,224 | ---- | C] () -- C:\Users\Malc\Club Tropicana Banner.pub

[2012/01/19 20:18:17 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI

[2011/11/09 21:14:21 | 000,040,023 | ---- | C] () -- C:\Users\Malc\AppData\Roaming\UserTile.png

[2011/10/03 18:53:55 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\ctmmactl.dll

[2011/10/03 18:53:53 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CTBurst.dll

[2011/10/03 18:53:53 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll

[2011/10/03 18:53:51 | 000,037,888 | ---- | C] () -- C:\Windows\SysWow64\psconv.exe

[2011/10/03 18:53:51 | 000,010,240 | ---- | C] ( ) -- C:\Windows\SysWow64\killapps.exe

[2011/10/03 18:53:51 | 000,005,120 | ---- | C] () -- C:\Windows\SysWow64\enlocstr.exe

[2011/10/03 18:53:49 | 000,313,207 | ---- | C] () -- C:\Windows\SysWow64\ctstatic.dat

[2011/10/03 18:53:48 | 000,386,852 | ---- | C] () -- C:\Windows\SysWow64\ctdnlstr.dat

[2011/10/03 18:53:48 | 000,053,932 | ---- | C] () -- C:\Windows\SysWow64\ctdaught.dat

[2011/10/03 18:53:48 | 000,051,787 | ---- | C] () -- C:\Windows\SysWow64\ctdlang.dat

[2011/10/03 18:53:48 | 000,050,466 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini

[2011/10/03 18:53:48 | 000,000,307 | ---- | C] () -- C:\Windows\SysWow64\kill.ini

[2011/10/03 18:53:48 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini

[2011/09/12 23:06:18 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

"" = C:\Windows\SysNative\shell32.dll -- [2013/02/27 06:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

"" = %SystemRoot%\system32\shell32.dll -- [2013/02/27 05:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

"" = C:\Windows\sysWOW64\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Files - Unicode (All) ==========

[2011/05/09 20:51:34 | 000,000,008 | --S- | M] ()(C:\Users\Malc\AppData\Local\Z™?) -- C:\Users\Malc\AppData\Local\ℤ™☠

[2011/05/09 20:51:34 | 000,000,008 | --S- | C] ()(C:\Users\Malc\AppData\Local\Z™?) -- C:\Users\Malc\AppData\Local\ℤ™☠

========== Alternate Data Streams ==========

@Alternate Data Stream - 460 bytes -> C:\Users\Malc\Documents\Regulars Clive.ppp:SummaryInformation

@Alternate Data Stream - 460 bytes -> C:\Users\Malc\Documents\club tropicana.ppp:SummaryInformation

@Alternate Data Stream - 452 bytes -> C:\Users\Malc\Documents\Clive Poker.ppp:SummaryInformation

@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:CB0AACC9

< End of report >

Link to post
Share on other sites

We need to run an OTL Fix

  • Please reopen otlicon.png on your desktop.
  • Copy and Paste the following code into the customscanfix.png textbox.
    :OTL
    @Alternate Data Stream - 460 bytes -> C:\Users\Malc\Documents\Regulars Clive.ppp:SummaryInformation
    @Alternate Data Stream - 460 bytes -> C:\Users\Malc\Documents\club tropicana.ppp:SummaryInformation
    @Alternate Data Stream - 452 bytes -> C:\Users\Malc\Documents\Clive Poker.ppp:SummaryInformation
    @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:CB0AACC9
    [2011/05/09 20:51:34 | 000,000,008 | --S- | M] ()(C:\Users\Malc\AppData\Local\Z™?) -- C:\Users\Malc\AppData\Local\ℤ™☠
    [2011/05/09 20:51:34 | 000,000,008 | --S- | C] ()(C:\Users\Malc\AppData\Local\Z™?) -- C:\Users\Malc\AppData\Local\ℤ™☠
    [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2013/02/27 06:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2013/02/27 05:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = C:\Windows\sysWOW64\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]


    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]


  • Push runfix.png
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click the OK button.
  • A report will open. Copy and Paste that report in your next reply.

Link to post
Share on other sites

All processes killed

========== OTL ==========

Unable to delete ADS C:\Users\Malc\Documents\Regulars .

Unable to delete ADS C:\Users\Malc\Documents\club .

Unable to delete ADS C:\Users\Malc\Documents\Clive .

ADS C:\ProgramData\TEMP:CB0AACC9 deleted successfully.

File 11/05/09 20:51:34 | 000,000,008 | --S- | M] ()(C:\Users\Malc\AppData\Local\Z™?) not found.

File 11/05/09 20:51:34 | 000,000,008 | --S- | C] ()(C:\Users\Malc\AppData\Local\Z™?) not found.

C:\Windows\assembly\Desktop.ini moved successfully.

File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.

File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.

File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.

File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.

File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.

File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.

Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.

Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.

Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.

Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: Lauren

->Temp folder emptied: 0 bytes

User: Malc

->Temp folder emptied: 598514 bytes

->Temporary Internet Files folder emptied: 1235336 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Google Chrome cache emptied: 172480037 bytes

->Apple Safari cache emptied: 0 bytes

->Flash cache emptied: 826 bytes

User: Public

->Temp folder emptied: 0 bytes

User: Sarah

->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 15910787 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42303100 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 222.00 mb

[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Lauren

User: Malc

->Java cache emptied: 0 bytes

User: Public

User: Sarah

Total Java Files Cleaned = 0.00 mb

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Lauren

User: Malc

->Flash cache emptied: 0 bytes

User: Public

User: Sarah

Total Flash Files Cleaned = 0.00 mb

OTL by OldTimer - Version 3.2.69.0 log created on 06102013_083622

Files\Folders moved on Reboot...

C:\Users\Malc\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

C:\Users\Malc\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0003ed not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0003ee not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0003ef not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0003f0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0003f1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004b7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004b8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004b9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004ba not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004bb not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004bc not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004bd not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004be not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004bf not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004c9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004ca not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004cb not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004cc not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004cd not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004ce not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004cf not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004d9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0004da not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005a5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005a6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005a7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005a8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005a9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005aa not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ab not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ac not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ad not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ae not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005af not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005b9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005ba not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005bb not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005bc not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005bd not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005be not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005bf not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0005c8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000654 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000655 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000658 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000659 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00065d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000660 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000661 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000662 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000663 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000664 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000665 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000666 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000668 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000669 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066a not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066e not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00066f not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000670 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000671 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000672 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000673 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000674 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000675 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000676 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000677 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000678 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000679 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067a not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067e not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00067f not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000680 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000681 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000682 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000683 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000684 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000685 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000686 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000687 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000688 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000689 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068a not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068e not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00068f not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000690 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000691 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000692 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000693 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000695 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000696 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000697 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000699 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069a not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069e not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00069f not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006a9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006aa not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ab not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ac not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ad not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ae not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006af not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006b9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ba not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006bb not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006bc not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006be not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006bf not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006c9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ca not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cb not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cc not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cd not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ce not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006cf not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006d9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006da not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006db not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006dc not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006dd not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006de not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006df not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006e9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ea not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006eb not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ec not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ed not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ee not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ef not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f0 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f1 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f2 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f3 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f4 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f5 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f6 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f7 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f8 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006f9 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fa not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fb not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fc not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fd not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006fe not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0006ff not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000700 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000701 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000702 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000703 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000704 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000705 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000706 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000707 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000708 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000709 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070a not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070e not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00070f not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000710 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000711 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000713 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000714 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000715 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000716 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000717 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000718 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000719 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071a not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071e not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00071f not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000720 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000721 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000722 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000723 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000724 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000726 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000727 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000728 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000729 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072a not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072b not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072c not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072d not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072e not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00072f not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000730 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000731 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000732 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000733 not found!

File\Folder C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000734 not found!

C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Link to post
Share on other sites

Please download AdwCleaner by Xplode onto your desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.

Link to post
Share on other sites

# AdwCleaner v2.303 - Logfile created 06/10/2013 at 19:32:56

# Updated 08/06/2013 by Xplode

# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)

# User : Malc - MALC-PC

# Boot Mode : Normal

# Running from : C:\Users\Malc\Downloads\AdwCleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

File Found : C:\END

File Found : C:\Program Files (x86)\Mozilla FireFox\searchplugins\Search_Results.xml

File Found : C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\searchplugins\babylon1.xml

File Found : C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\searchplugins\zonealarm.xml

Folder Found : C:\Program Files (x86)\ExpressFiles

Folder Found : C:\Program Files (x86)\Mozilla Firefox\Extensions\ffxtlbr@babylon.com

Folder Found : C:\ProgramData\InstallMate

Folder Found : C:\ProgramData\Tarma Installer

Folder Found : C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Folder Found : C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Folder Found : C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Folder Found : C:\Users\Malc\AppData\Local\Ilivid Player

Folder Found : C:\Users\Malc\AppData\Local\PackageAware

Folder Found : C:\Users\Malc\AppData\Local\SwvUpdater

Folder Found : C:\Users\Malc\AppData\Local\Zoom_Downloader

Folder Found : C:\Users\Malc\AppData\LocalLow\Conduit

Folder Found : C:\Users\Malc\AppData\LocalLow\PriceGong

Folder Found : C:\Users\Malc\AppData\Roaming\CheckPoint\ZoneAlarm LTD Toolbar

Folder Found : C:\Users\Malc\AppData\Roaming\DriverCure

Folder Found : C:\Users\Malc\AppData\Roaming\DSite

Folder Found : C:\Users\Malc\AppData\Roaming\ExpressFiles

Folder Found : C:\Users\Malc\AppData\Roaming\SpeedMaxPc

Folder Found : C:\Windows\Installer\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0}

***** [Registry] *****

Key Found : HKCU\Software\APN PIP

Key Found : HKCU\Software\AppDataLow\Software\Conduit

Key Found : HKCU\Software\AppDataLow\Software\PriceGong

Key Found : HKCU\Software\AppDataLow\Software\SmartBar

Key Found : HKCU\Software\Conduit

Key Found : HKCU\Software\ExpressFiles

Key Found : HKCU\Software\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Key Found : HKCU\Software\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Key Found : HKCU\Software\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Key Found : HKCU\Software\InstallCore

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}

Key Found : HKCU\Software\PIP

Key Found : HKCU\Software\5355d6dee068e540

Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}

Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe

Key Found : HKLM\SOFTWARE\Classes\oneclick

Key Found : HKLM\SOFTWARE\Classes\oneclickmg

Key Found : HKLM\SOFTWARE\Classes\sim-packages

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}

Key Found : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}

Key Found : HKLM\Software\ExpressFiles

Key Found : HKLM\Software\Freeze.com

Key Found : HKLM\Software\Iminent

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32

Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi

Key Found : HKLM\Software\PIP

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}

Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk

Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco

Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}

Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}

Key Found : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}

Key Found : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{612AD33D-9824-4E87-8396-92374E91C4BB}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm LTD Toolbar

Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}]

Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]

***** [internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Registry is clean.

-\\ Mozilla Firefox v16.0.2 (en-GB)

File : C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\g6lzvssg.default-1358192917276\prefs.js

Found : user_pref("extensions.BabylonToolbar.admin", false);

Found : user_pref("extensions.BabylonToolbar.aflt", "babsst");

Found : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");

Found : user_pref("extensions.BabylonToolbar.autoRvrt", "false");

Found : user_pref("extensions.BabylonToolbar.dfltLng", "en");

Found : user_pref("extensions.BabylonToolbar.excTlbr", false);

Found : user_pref("extensions.BabylonToolbar.id", "8c87dd910000000000000025226f3af6");

Found : user_pref("extensions.BabylonToolbar.instlDay", "15724");

Found : user_pref("extensions.BabylonToolbar.instlRef", "sst");

Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");

Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");

Found : user_pref("extensions.BabylonToolbar.rvrt", "false");

Found : user_pref("extensions.BabylonToolbar.tlbrId", "base");

Found : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...]

Found : user_pref("extensions.BabylonToolbar.vrsn", "1.8.7.2");

Found : user_pref("extensions.BabylonToolbar.vrsni", "1.8.7.2");

Found : user_pref("extensions.BabylonToolbar_i.babExt", "");

Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109220&tt=0313_5");

Found : user_pref("extensions.BabylonToolbar_i.excTlbr", false);

Found : user_pref("extensions.BabylonToolbar_i.newTab", false);

Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");

Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");

Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.7.221:02:30");

Found : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1359199970541");

File : C:\Users\Malc\AppData\Roaming\Mozilla\Firefox\Profiles\wjfbbvx9.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v27.0.1453.110

File : C:\Users\Malc\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [9675 octets] - [10/06/2013 19:32:56]

########## EOF - C:\AdwCleaner[R1].txt - [9735 octets] ##########

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.