dnahunter Posted June 12, 2013 ID:690088 Share Posted June 12, 2013 Hello MBAM keeps saying website block. website is:46.249.61.94 Type outgoing, Port=47000+. This keep going on every 3 mins . DDS (Ver_2012-11-20.01) - NTFS_AMD64Internet Explorer: 10.0.9200.16576 BrowserJavaVersion: 1.6.0_39Run by THMark at 21:01:33 on 2013-06-11Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8191.5609 [GMT -7:00].AV: Symantec Endpoint Protection *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: Symantec Endpoint Protection *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}FW: Symantec Endpoint Protection *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}.============== Running Processes ===============.C:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\nvvsvc.exeC:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exeC:\Windows\system32\svchost.exe -k RPCSSC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\svchost.exe -k GPSvcGroupC:\Program Files\NVIDIA Corporation\Display\nvxdsync.exeC:\Windows\system32\nvvsvc.exeC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Windows\system32\taskhost.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exeC:\ASUS.SYS\config\DVMExportService.exeC:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonationE:\ARRRGHHH!!\HiPatchService.exeC:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\NVIDIA Corporation\Display\nvtray.exeC:\Program Files\Microsoft Office\Office14\MSOSYNC.EXEC:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exeC:\Program Files (x86)\Steam 2\Steam.exeC:\Program Files (x86)\Pando Networks\Media Booster\PMB.exeC:\Program Files (x86)\DAEMON Tools Lite\DTLite.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exeC:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exeC:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exeC:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exeC:\Program Files (x86)\Common Files\Java\Java Update\jusched.exec:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXEC:\Program Files (x86)\iTunes\iTunesHelper.exeC:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exeC:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exeC:\Windows\SysWOW64\PnkBstrA.exeC:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exeC:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exeC:\Windows\system32\svchost.exe -k imgsvcC:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exeC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXEC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exeC:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exeC:\Windows\system32\SearchIndexer.exeC:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin64\Smc.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\System32\svchost.exe -k LocalServicePeerNetC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Windows\system32\SearchProtocolHost.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Windows\system32\sppsvc.exeC:\Windows\System32\svchost.exe -k secsvcsC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\system32\wbem\wmiprvse.exe\\?\C:\Windows\system32\wbem\WMIADAP.EXEC:\Windows\system32\SearchFilterHost.exeC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\system32\SearchProtocolHost.exeC:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exeC:\Windows\System32\cscript.exe.============== Pseudo HJT Report ===============.uStart Page = hxxp://www.google.com/mWinlogon: Userinit = userinit.exe,BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\IPS\IPSBHO.dllBHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLLBHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dllBHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dllBHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\THMark\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dllBHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLLBHO: WeCareReminder Class: {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dllBHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dllTB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dlluRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRunuRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /backgrounduRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"uRun: [steam] "C:\Program Files (x86)\Steam 2\Steam.exe" -silentuRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exeuRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorunuRun: [AdobeBridge] <no file>mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"mRun: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startupmRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"mRun: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exemRun: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbyloginmRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"uPolicies-Explorer: NoDriveTypeAutoRun = dword:145mPolicies-Explorer: NoActiveDesktop = dword:1mPolicies-Explorer: NoActiveDesktopChanges = dword:1mPolicies-System: ConsentPromptBehaviorAdmin = dword:0mPolicies-System: ConsentPromptBehaviorUser = dword:3mPolicies-System: EnableLUA = dword:0mPolicies-System: EnableUIADesktopToggle = dword:0mPolicies-System: PromptOnSecureDesktop = dword:0IE: Download all by FlashGet3 - C:\Users\THMark\AppData\Roaming\FlashGetBHO\GetAllUrl.htmIE: Download by FlashGet3 - C:\Users\THMark\AppData\Roaming\FlashGetBHO\GetUrl.htmIE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.htmlIE: Se&nd to OneNote - C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dllIE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dllIE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dllTrusted Zone: clonewarsadventures.comTrusted Zone: freerealms.comTrusted Zone: soe.comTrusted Zone: sony.comDPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cabDPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cabDPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} - hxxps://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.80.2.cabDPF: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_17-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cabDPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cabTCP: NameServer = 192.168.0.1TCP: Interfaces\{3FD03C73-2DA3-4BF2-BBC3-35FA76540AB3} : DHCPNameServer = 192.168.0.1TCP: Interfaces\{6270270B-9F29-4756-B371-C7BDBA678C86} : DHCPNameServer = 192.168.1.133Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLLHandler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dllNotify: SEP - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\WinLogoutNotifier.dllSSODL: WebCheck - <orphaned>SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLLx64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLLx64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllx64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dllx64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dllx64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLLx64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dllx64-Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServicesx64-Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrunx64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dllx64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dllx64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dllx64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLLx64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dllx64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>x64-SSODL: WebCheck - <orphaned>x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL.================= FIREFOX ===================.FF - ProfilePath - C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)FF - prefs.js: browser.startup.homepage - google.comFF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLLFF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLLFF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dllFF - plugin: C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dllFF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dllFF - plugin: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dllFF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dllFF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dllFF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dllFF - plugin: C:\Program Files (x86)\Nitro\Reader 3\npdf.dllFF - plugin: C:\Program Files (x86)\Nitro\Reader 3\npnitroie.dllFF - plugin: C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dllFF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dllFF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dllFF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dllFF - plugin: C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dllFF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dllFF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dllFF - plugin: C:\Windows\SysWOW64\npdeployJava1.dllFF - plugin: C:\Windows\SysWOW64\npmproxy.dllFF - plugin: G:\New folder\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll.---- FIREFOX POLICIES ----FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113933&tt=120812_bandext_3212_1FF - user.js: extensions.BabylonToolbar_i.babExt -FF - user.js: extensions.BabylonToolbar_i.srcExt - ssFF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://www.google.com/search?babsrc=TB_ggl&q=FF - user.js: extensions.BabylonToolbar.id - 1e666e7c00000000000002004c4f4f50FF - user.js: extensions.BabylonToolbar.instlDay - 15564FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.4.6FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.4.6FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.4.615:48:43FF - user.js: extensions.BabylonToolbar.prtnrId - babylonFF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbarFF - user.js: extensions.BabylonToolbar.aflt - babsstFF - user.js: extensions.BabylonToolbar_i.smplGrp - noneFF - user.js: extensions.BabylonToolbar.tlbrId - baseFF - user.js: extensions.BabylonToolbar.instlRef - sstFF - user.js: extensions.BabylonToolbar.dfltLng - enFF - user.js: extensions.BabylonToolbar.excTlbr - falseFF - user.js: extensions.BabylonToolbar.admin - false.============= SERVICES / DRIVERS ===============.R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\SEP\0C0103E8\009D.105\x64\SymDS64.sys [2011-7-16 451192]R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\SEP\0C0103E8\009D.105\x64\SymEFA64.sys [2011-8-27 931448]R1 BHDrvx64;BHDrvx64;C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\BASHDefs\20130521.011\BHDrvx64.sys [2013-5-28 1390680]R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2013-2-13 283200]R1 IDSVia64;IDSVia64;C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\IPSDefs\20130611.001\IDSviA64.sys [2013-6-11 513184]R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\SEP\0C0103E8\009D.105\x64\Ironx64.sys [2011-9-13 171128]R1 SYMNETS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\SEP\0C0103E8\009D.105\x64\symnets.sys [2011-9-8 386168]R2 BstHdDrv;BlueStacks Hypervisor;C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2012-7-10 75144]R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2012-7-10 385416]R2 DvmMDES;DeviceVM Meta Data Export Service;C:\ASUS.SYS\config\DVMExportService.exe [2009-10-16 319488]R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;E:\ARRRGHHH!!\HiPatchService.exe [2013-4-4 9216]R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-23 418376]R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-23 701512]R2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [2012-10-30 230416]R2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE --> c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE [?]R2 OracleXETNSListener;OracleXETNSListener;C:\oraclexe\app\oracle\product\11.2.0\server\bin\TNSLSNR.EXE [2011-8-27 512000]R2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-8-12 87040]R2 SepMasterService;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe [2011-9-20 137224]R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-5-14 3289208]R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-1-18 383264]R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-4-10 3560288]R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-15 138912]R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-7-24 25928]R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-4-27 83080]R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-4-27 184968]R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]S3 BstHdAndroidSvc;BlueStacks Android Service;C:\Program Files (x86)\BlueStacks\HD-Service.exe [2012-7-10 397704]S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11-2 33736]S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\System32\drivers\htcnprot.sys [2010-6-25 36928]S3 npggsvc;nProtect GameGuard Service;C:\Windows\System32\GameMon.des -service --> C:\Windows\System32\GameMon.des -service [?]S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-3-11 19456]S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-3-11 57856]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-3-11 30208]S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-7-25 1255736]S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE --> c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE [?].=============== Created Last 30 ================.2013-06-12 03:57:11 -------- d-----w- C:\Users\THMark\AppData\Local\{358D293F-3171-4A14-B3B9-D42F32B68222}2013-06-11 16:31:01 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BE81F950-7FAF-4341-A8D7-685562AEAE08}\mpengine.dll2013-06-10 03:43:14 -------- d-----w- C:\Users\THMark\AppData\Local\Warframe2013-06-09 03:39:35 -------- d-----w- C:\Users\THMark\AppData\Local\FreeOCR2013-06-09 03:35:03 -------- d-----w- C:\Users\THMark\AppData\Local\assembly2013-06-09 03:34:45 2680320 ----a-w- C:\Windows\SysWow64\ImageEnXLibrary.ocx2013-06-09 03:34:43 -------- d-----w- C:\FreeOCR2013-06-09 03:32:52 -------- d-----w- C:\Program Files (x86)\Temp2013-06-05 15:42:55 -------- d-----w- C:\Users\THMark\AppData\Local\{19AE5637-162C-43D7-AF94-C748693EB32F}2013-06-05 10:01:47 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll2013-06-05 01:20:51 262552 ----a-w- C:\Program Files (x86)\Mozilla Firefox\updated\browser\components\browsercomps.dll2013-06-03 03:04:52 -------- d-----w- C:\Users\THMark\AppData\Local\{9AD8D4DB-F944-4F62-9B43-2EC362AD5D4D}2013-05-17 18:21:04 -------- d-----w- C:\ProgramData\boost_interprocess2013-05-16 14:49:42 -------- d-----w- C:\Users\THMark\AppData\Local\{BA883505-911C-4F42-9431-2A3785952414}2013-05-15 22:59:18 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys2013-05-15 22:59:18 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys2013-05-15 22:59:18 144384 ----a-w- C:\Windows\System32\cdd.dll2013-05-15 22:59:06 1930752 ----a-w- C:\Windows\System32\authui.dll2013-05-15 22:59:05 70144 ----a-w- C:\Windows\System32\appinfo.dll2013-05-15 22:59:05 1796096 ----a-w- C:\Windows\SysWow64\authui.dll2013-05-15 22:59:05 111448 ----a-w- C:\Windows\System32\consent.exe2013-05-15 22:58:53 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll2013-05-15 22:58:53 3153920 ----a-w- C:\Windows\System32\win32k.sys2013-05-15 22:58:53 230400 ----a-w- C:\Windows\System32\wwansvc.dll2013-05-14 20:31:10 6128760 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll2013-05-14 20:31:10 6128760 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll.==================== Find3M ====================.2013-06-05 10:01:47 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll2013-05-14 19:07:11 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl2013-05-14 19:07:11 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe2013-05-02 09:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe2013-04-24 07:26:43 281120 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr2013-04-24 07:26:43 281120 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe2013-04-24 06:55:12 281120 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex02013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys2013-04-07 16:02:04 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe2013-04-04 21:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe.============= FINISH: 21:03:11.27 ===============.UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2012-11-20.01).Microsoft Windows 7 ProfessionalBoot Device: \Device\HarddiskVolume1Install Date: 7/24/2011 11:37:40 PMSystem Uptime: 6/11/2013 8:53:49 PM (1 hours ago).Motherboard: ASUSTeK Computer INC. | | M4A88TD-M/USB3Processor: AMD Phenom II X6 1090T Processor | AM3 | 3200/200mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 131 GiB total, 32.867 GiB free.D: is FIXED (NTFS) - 50 GiB total, 8.669 GiB free.E: is FIXED (NTFS) - 200 GiB total, 46.234 GiB free.G: is FIXED (NTFS) - 150 GiB total, 76.511 GiB free.H: is FIXED (NTFS) - 100 GiB total, 24.039 GiB free.I: is CDROM ()J: is CDROM (CDFS)Z: is FIXED (NTFS) - 600 GiB total, 254.088 GiB free..==== Disabled Device Manager Items =============.==== System Restore Points ===================.No restore point in system..==== Installed Programs ======================.Acronis Disk Director SuiteAdobe AIRAdobe Download AssistantAdobe Flash Player 11 ActiveXAdobe Flash Player 11 PluginAdobe Photoshop CS6Adobe Reader X (10.1.7)Adobe Shockwave Player 11.6AhnLab Online SecurityAmazon KindleApple Application SupportApple Mobile Device SupportApple Software UpdateArtMoney SE v7.37.2ASPCA Reminder by We-Care.com v4.0.19.1Audacity 2.0AVS Document Converter 2.0.1AVS Ringtone Maker version 1.6AVS Update Manager 1.0AVS4YOU Software Navigator 1.4black-ops.themepackBlueStacksBonjourChampions Online: Free For AllCheat Engine 6.1Core Temp version 0.99.8D3DX10DAEMON Tools LiteDefinition Update for Microsoft Office 2010 (KB982726) 64-Bit EditionExpress GateFIFA 12 © EA version 1FlashGet 3.7Galactic Magnate v1.2GameMaker 8.1Ghost Recon Online (NCSA-Live)Google Talk PluginGoogle Toolbar for Internet ExplorerGoogle Update HelperGuild Wars 2Happy Cloud ClientHeroes of NewerthHex Workshop v6.6Hi-Rez Studios Authenticate and Update ServiceHomefrontHTC BMP USB DriverHTC Driver InstallerHTC SyncHydraIRCiCloudInstaCodecsiTunesJ2SE Runtime Environment 5.0 Update 17Java Auto UpdaterJava 6 Update 39K-Lite Codec Pack 7.8.0 (Full)KabodLeague of LegendsMahjongWorld (uninstall only)Major League Baseball 2K12Malwarebytes Anti-Malware version 1.75.0.1300Microsoft .NET Framework 1.1Microsoft .NET Framework 4 Client ProfileMicrosoft .NET Framework 4 ExtendedMicrosoft .NET Framework 4 Multi-Targeting PackMicrosoft Application Error ReportingMicrosoft Expression Blend 3 SDKMicrosoft Expression Blend 4Microsoft Expression Blend SDK for .NET 4Microsoft Expression Blend SDK for Silverlight 4Microsoft Expression Design 4Microsoft Expression Encoder 4Microsoft Expression Encoder 4 Screen Capture CodecMicrosoft Expression Studio 4Microsoft Expression Web 4Microsoft Expression Web 4 Service Pack 2Microsoft Games for Windows - LIVE RedistributableMicrosoft Games for Windows MarketplaceMicrosoft Office 2010 Language Pack Service Pack 1 (SP1)Microsoft Office 2010 Service Pack 1 (SP1)Microsoft Office Access MUI (English) 2010Microsoft Office Access Setup Metadata MUI (English) 2010Microsoft Office Excel MUI (English) 2010Microsoft Office Groove MUI (English) 2010Microsoft Office InfoPath MUI (English) 2010Microsoft Office Office 32-bit Components 2010Microsoft Office OneNote MUI (English) 2010Microsoft Office Outlook MUI (English) 2010Microsoft Office PowerPoint MUI (English) 2010Microsoft Office Professional Plus 2010Microsoft Office Project MUI (English) 2010Microsoft Office Project Professional 2010Microsoft Office Proof (English) 2010Microsoft Office Proof (French) 2010Microsoft Office Proof (Spanish) 2010Microsoft Office Proofing (English) 2010Microsoft Office Publisher MUI (English) 2010Microsoft Office Shared 32-bit MUI (English) 2010Microsoft Office Shared MUI (English) 2010Microsoft Office Shared Setup Metadata MUI (English) 2010Microsoft Office Visio 2010Microsoft Office Visio MUI (English) 2010Microsoft Office Word MUI (English) 2010Microsoft Project 2010 Service Pack 1 (SP1)Microsoft Project Professional 2010Microsoft SilverlightMicrosoft Silverlight 3 SDKMicrosoft Silverlight 4 SDKMicrosoft Visio 2010 Service Pack 1 (SP1)Microsoft Visio Premium 2010Microsoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2005 Redistributable (x64)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219Microsoft Xbox 360 Accessories 1.2Microsoft_VC80_CRT_x86Microsoft_VC90_CRT_x86mIRCMozilla Firefox 20.0.1 (x86 en-US)Mozilla Maintenance ServiceMSVCRTMSXML 4.0 SP3 ParserMSXML 4.0 SP3 Parser (KB2721691)MSXML 4.0 SP3 Parser (KB2758694)MSXML 4.0 SP3 Parser (KB973685)NBA 2K12NBA 2K13Nexon Game ManagerNitro Reader 3NVIDIA 3D Vision Controller Driver 306.97NVIDIA 3D Vision Driver 311.06NVIDIA Control Panel 311.06NVIDIA Graphics Driver 311.06NVIDIA HD Audio Driver 1.3.18.0NVIDIA Install ApplicationNVIDIA PhysXNVIDIA PhysX System Software 9.12.0604NVIDIA Stereoscopic 3D DriverNVIDIA Update 1.11.3NVIDIA Update ComponentsOracle Database 11g Express EditionOriginPando Media BoosterPC Probe IIPCSX2 - Playstation 2 EmulatorPDF Settings CS6PeerBlock 1.1 (r518)Pirates of the Burning SeaPort Royale 3PrimoPDF -- brought to you by Nitro PDF SoftwarePunkBuster ServicesRagnarok Online2Realtek Ethernet Controller Driver For Windows 7Renesas Electronics USB 3.0 Host Controller DriverSaints Row. The Third 1.0Secure Download ManagerSecurity Update for Microsoft .NET Framework 4 Client Profile (KB2478663)Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)Security Update for Microsoft .NET Framework 4 Extended (KB2416472)Security Update for Microsoft .NET Framework 4 Extended (KB2487367)Security Update for Microsoft .NET Framework 4 Extended (KB2656351)Security Update for Microsoft .NET Framework 4 Extended (KB2736428)Security Update for Microsoft .NET Framework 4 Extended (KB2742595)Security Update for Microsoft Excel 2010 (KB2597126) 64-Bit EditionSecurity Update for Microsoft Expression Design 4 (KB2667730)Security Update for Microsoft Filter Pack 2.0 (KB2553501) 64-Bit EditionSecurity Update for Microsoft InfoPath 2010 (KB2687422) 64-Bit EditionSecurity Update for Microsoft InfoPath 2010 (KB2760406) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2553091)Security Update for Microsoft Office 2010 (KB2553096)Security Update for Microsoft Office 2010 (KB2553371) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2553447) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2589320) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2598243) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2687501) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2687510) 64-Bit EditionSecurity Update for Microsoft OneNote 2010 (KB2760600) 64-Bit EditionSecurity Update for Microsoft Publisher 2010 (KB2553147) 64-Bit EditionSecurity Update for Microsoft Visio 2010 (KB2810068) 64-Bit EditionSecurity Update for Microsoft Visio Viewer 2010 (KB2687505) 64-Bit EditionSecurity Update for Microsoft Word 2010 (KB2760410) 64-Bit EditionSins of a Solar Empire Rebellion © Stardock version 1Skype Click to CallSkype™ 5.10Spiral KnightsStar Wars: The Old RepublicSteamSymantec Endpoint ProtectionSystem Requirements Lab CYRITeamSpeak 3 ClientTeamViewer 8The Lord of the Rings OnlineTom Clancy's Ghost Recon Future SoldierTom Clancys Ghost Recon Future Soldier version 1.02Tribes AscendUbisoft Game LauncherUpdate for Microsoft .NET Framework 4 Client Profile (KB2468871)Update for Microsoft .NET Framework 4 Client Profile (KB2473228)Update for Microsoft .NET Framework 4 Client Profile (KB2533523)Update for Microsoft .NET Framework 4 Client Profile (KB2600217)Update for Microsoft .NET Framework 4 Extended (KB2468871)Update for Microsoft .NET Framework 4 Extended (KB2533523)Update for Microsoft .NET Framework 4 Extended (KB2600217)Update for Microsoft Office 2010 (KB2494150)Update for Microsoft Office 2010 (KB2553065)Update for Microsoft Office 2010 (KB2553092)Update for Microsoft Office 2010 (KB2553181) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2553267) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2553310) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2553378) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2566458)Update for Microsoft Office 2010 (KB2598242) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2687509) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2760631) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2767886) 64-Bit EditionUpdate for Microsoft OneNote 2010 (KB2553290) 64-Bit EditionUpdate for Microsoft Outlook 2010 (KB2597090) 64-Bit EditionUpdate for Microsoft Outlook 2010 (KB2687623) 64-Bit EditionUpdate for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit EditionUpdate for Microsoft PowerPoint 2010 (KB2598240) 64-Bit EditionUpdate for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit EditionVentrilo Client for Windows x64VLC media player 1.1.11WarframeWindows 7 Upgrade AdvisorWindows Live Communications PlatformWindows Live EssentialsWindows Live ID Sign-in AssistantWindows Live InstallerWindows Live Language SelectorWindows Live MessengerWindows Live Photo CommonWindows Live PIMT PlatformWindows Live SOXEWindows Live SOXE DefinitionsWindows Live UX PlatformWindows Live UX Platform Language PackWinRAR 4.01 (64-bit)World of Tanks v.0.6.3.11WPF Toolkit February 2010 (Version 3.5.50211.1)XChat 2 (remove only).==== Event Viewer Messages From Past Week ========.6/11/2013 8:59:48 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).6/11/2013 8:59:48 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.6/11/2013 5:59:07 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000000dc, 0x0000000000000002, 0x0000000000000001, 0xfffff800032aed35). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 061113-40716-01.6/11/2013 5:51:17 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Base Filtering Engine service, but this action failed with the following error: An instance of the service is already running.6/11/2013 5:50:45 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.6/11/2013 5:50:45 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the IKE and AuthIP IPsec Keying Modules service, but this action failed with the following error: An instance of the service is already running.6/11/2013 5:50:45 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error: An instance of the service is already running.6/11/2013 5:50:27 PM, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.6/11/2013 5:49:45 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.6/11/2013 5:49:27 PM, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:49:27 PM, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:49:27 PM, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:49:27 PM, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.6/11/2013 5:49:27 PM, Error: Service Control Manager [7031] - The HomeGroup Listener service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:49:17 PM, Error: Service Control Manager [7031] - The Windows Firewall service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:49:17 PM, Error: Service Control Manager [7031] - The Diagnostic Policy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:49:17 PM, Error: Service Control Manager [7031] - The Base Filtering Engine service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:51 PM, Error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:45 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 1 time(s).6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Offline Files service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Human Interface Device Access service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The HomeGroup Listener service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:48:11 PM, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:21:58 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Server service to connect.6/11/2013 5:21:58 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Secondary Logon service to connect.6/11/2013 5:21:58 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Multimedia Class Scheduler service to connect.6/11/2013 5:21:58 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the IKE and AuthIP IPsec Keying Modules service to connect.6/11/2013 5:21:58 PM, Error: Service Control Manager [7001] - The User Profile Service service depends on the Remote Procedure Call (RPC) service which failed to start because of the following error: The dependency service or group failed to start.6/11/2013 5:21:58 PM, Error: Service Control Manager [7001] - The Remote Procedure Call (RPC) service depends on the RPC Endpoint Mapper service which failed to start because of the following error: The service has not been started.6/11/2013 5:21:58 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Remote Procedure Call (RPC) service which failed to start because of the following error: The dependency service or group failed to start.6/11/2013 5:21:58 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:21:58 PM, Error: Service Control Manager [7000] - The Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:21:58 PM, Error: Service Control Manager [7000] - The Secondary Logon service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:21:58 PM, Error: Service Control Manager [7000] - The Multimedia Class Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:21:58 PM, Error: Service Control Manager [7000] - The IKE and AuthIP IPsec Keying Modules service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:21:57 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the System Event Notification Service service to connect.6/11/2013 5:21:57 PM, Error: Service Control Manager [7000] - The System Event Notification Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:21:53 PM, Error: Service Control Manager [7001] - The Group Policy Client service depends on the Remote Procedure Call (RPC) service which failed to start because of the following error: The dependency service or group failed to start.6/11/2013 5:21:49 PM, Error: Service Control Manager [7001] - The Function Discovery Resource Publication service depends on the Remote Procedure Call (RPC) service which failed to start because of the following error: The dependency service or group failed to start.6/11/2013 5:21:47 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the RPC Endpoint Mapper service, but this action failed with the following error: An instance of the service is already running.6/11/2013 5:20:57 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Themes service to connect.6/11/2013 5:20:57 PM, Error: Service Control Manager [7001] - The Windows Update service depends on the Remote Procedure Call (RPC) service which failed to start because of the following error: The dependency service or group failed to start.6/11/2013 5:20:57 PM, Error: Service Control Manager [7001] - The Task Scheduler service depends on the Remote Procedure Call (RPC) service which failed to start because of the following error: The dependency service or group failed to start.6/11/2013 5:20:57 PM, Error: Service Control Manager [7001] - The Background Intelligent Transfer Service service depends on the Remote Procedure Call (RPC) service which failed to start because of the following error: The dependency service or group failed to start.6/11/2013 5:20:57 PM, Error: Service Control Manager [7000] - The Themes service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:19:59 PM, Error: Service Control Manager [7001] - The Remote Procedure Call (RPC) service depends on the RPC Endpoint Mapper service which failed to start because of the following error: The service has returned a service-specific error code.6/11/2013 5:19:53 PM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:19:50 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the SSDP Discovery service to connect.6/11/2013 5:19:50 PM, Error: Service Control Manager [7001] - The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:19:50 PM, Error: Service Control Manager [7000] - The SSDP Discovery service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.6/11/2013 5:19:49 PM, Error: Service Control Manager [7031] - The UPnP Device Host service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.6/11/2013 5:19:49 PM, Error: Service Control Manager [7031] - The SSDP Discovery service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.6/11/2013 5:19:49 PM, Error: Service Control Manager [7031] - The Function Discovery Resource Publication service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:19:47 PM, Error: Service Control Manager [7031] - The RPC Endpoint Mapper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.6/11/2013 5:19:47 PM, Error: Service Control Manager [7031] - The Remote Procedure Call (RPC) service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.6/11/2013 5:01:53 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Peer Networking Identity Manager service, but this action failed with the following error: An instance of the service is already running.6/11/2013 5:01:53 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Peer Name Resolution Protocol service, but this action failed with the following error: An instance of the service is already running.6/11/2013 4:56:52 PM, Error: Service Control Manager [7031] - The Peer Networking Identity Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.6/11/2013 4:56:52 PM, Error: Service Control Manager [7031] - The Peer Networking Grouping service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.6/11/2013 4:56:52 PM, Error: Service Control Manager [7031] - The Peer Name Resolution Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service..==== End Of File =========================== Link to post Share on other sites More sharing options...
D-FRED-BROWN Posted June 12, 2013 ID:690089 Share Posted June 12, 2013 Hello dnahunter and welcome to Malwarebytes!I am D-FRED-BROWN and I will be helping you. Please print or save this topic. It will make it easier for you to follow the instructions and complete all of the necessary steps.----------Step 1----------------Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!Double-click on TDSSKiller.exe to run the tool for known TDSS variants.Vista/Windows 7 users right-click and select Run As Administrator.If TDSSKiller does not run, try renaming it.To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.Click the Start Scan button.Do not use the computer during the scanIf the scan completes with nothing found, click Close to exit.If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.Note: If Cure is not an option, Skip instead, do not choose Delete unless instructed.A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).Copy and paste the contents of that file in your next reply.----------Step 2----------------Please download Malwarebytes Anti-Rootkit from HEREUnzip the contents to a folder in a convenient location.Open the folder where the contents were unzipped and run mbar.exeFollow the instructions in the wizard to update and allow the program to scan your computer for threats.Click on the Cleanup button to remove any threats and reboot if prompted to do so.Wait while the system shuts down and the cleanup process is performed.Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.When done, please post the two logs produced they will be in the MBAR folder... mbar-log.txt and system-log.txt----------Step 3----------------Please download ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:http://www.bleepingc...to-use-combofix***IMPORTANT: save ComboFix to your Desktop**** Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Please go here to see a list of programs that should be disabled.**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall** Please include the C:\ComboFix.txt in your next reply for further review.NOTE: If you receive the message "illegal operation has been attempted on a registry key that has been marked for deletion", just reboot the computer.----------Step 4----------------Please download Security Check by screen317 from here or here.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.A Notepad document should open automatically called checkup.txt; please post the contents of that document.----------Step 5----------------In your next reply, please include the following:TDSSKiller's logfileMBAR mbar-log.txt and system-log.txtComboFix's report (C:\ComboFix.txt)Security Check checkup.txtAfter that, please let me know: How is your computer running now? Do you have any questions or concerns you'd like me to address? Don't hesitate to ask. -----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Note:Please make sure you are subscribed to this topic: Click on the "Follow This Topic" Button (at the top right of this page), make sure that the "Receive notification" box is checked and that it is set to "Instantly"-------> Your topic will be closed if you haven't replied within 3 days! <--------(If I don't respond within 24 hours, please send me a PM)-DFB Link to post Share on other sites More sharing options...
dnahunter Posted June 12, 2013 Author ID:690122 Share Posted June 12, 2013 Thanks that fix it.21:30:36.0115 2160 TDSS rootkit removing tool 2.8.18.0 Jun 10 2013 21:44:1921:30:36.0720 2160 ============================================================21:30:36.0720 2160 Current date / time: 2013/06/11 21:30:36.072021:30:36.0720 2160 SystemInfo:21:30:36.0720 2160 21:30:36.0720 2160 OS Version: 6.1.7601 ServicePack: 1.021:30:36.0720 2160 Product type: Workstation21:30:36.0720 2160 ComputerName: THMARK-PC21:30:36.0720 2160 UserName: THMark21:30:36.0720 2160 Windows directory: C:\Windows21:30:36.0720 2160 System windows directory: C:\Windows21:30:36.0720 2160 Running under WOW6421:30:36.0720 2160 Processor architecture: Intel x6421:30:36.0720 2160 Number of processors: 621:30:36.0720 2160 Page size: 0x100021:30:36.0720 2160 Boot type: Normal boot21:30:36.0720 2160 ============================================================21:30:38.0960 2160 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x0000004021:30:38.0970 2160 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x0000004021:30:38.0985 2160 ============================================================21:30:38.0985 2160 \Device\Harddisk0\DR0:21:30:38.0985 2160 MBR partitions:21:30:38.0985 2160 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2F110, BlocksNum 0x106D007E21:30:38.0985 2160 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x106FF800, BlocksNum 0x4B00000021:30:38.0985 2160 \Device\Harddisk1\DR1:21:30:38.0985 2160 MBR partitions:21:30:38.0985 2160 ============================================================21:30:39.0010 2160 C: <-> \Device\Harddisk0\DR0\Partition121:30:39.0050 2160 Z: <-> \Device\Harddisk0\DR0\Partition221:30:39.0050 2160 ============================================================21:30:39.0050 2160 Initialize success21:30:39.0050 2160 ============================================================21:30:57.0787 5792 ============================================================21:30:57.0787 5792 Scan started21:30:57.0787 5792 Mode: Manual;21:30:57.0787 5792 ============================================================21:30:58.0217 5792 ================ Scan system memory ========================21:30:58.0217 5792 System memory - ok21:30:58.0217 5792 ================ Scan services =============================21:30:58.0457 5792 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys21:30:58.0457 5792 1394ohci - ok21:30:58.0532 5792 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys21:30:58.0542 5792 ACPI - ok21:30:58.0562 5792 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys21:30:58.0562 5792 AcpiPmi - ok21:30:58.0657 5792 [ E2769E2699AF88CA3C57289A8A32ED19 ] AcronisOSSReinstallSvc C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe21:30:58.0697 5792 AcronisOSSReinstallSvc - ok21:30:58.0772 5792 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe21:30:58.0772 5792 AdobeARMservice - ok21:30:58.0887 5792 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe21:30:58.0892 5792 AdobeFlashPlayerUpdateSvc - ok21:30:58.0922 5792 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys21:30:58.0932 5792 adp94xx - ok21:30:58.0962 5792 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys21:30:58.0967 5792 adpahci - ok21:30:58.0987 5792 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys21:30:58.0987 5792 adpu320 - ok21:30:59.0017 5792 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll21:30:59.0017 5792 AeLookupSvc - ok21:30:59.0062 5792 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys21:30:59.0072 5792 AFD - ok21:30:59.0102 5792 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys21:30:59.0102 5792 agp440 - ok21:30:59.0127 5792 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe21:30:59.0127 5792 ALG - ok21:30:59.0147 5792 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys21:30:59.0147 5792 aliide - ok21:30:59.0227 5792 ALSysIO - ok21:30:59.0332 5792 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys21:30:59.0337 5792 amdide - ok21:30:59.0357 5792 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys21:30:59.0357 5792 AmdK8 - ok21:30:59.0382 5792 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys21:30:59.0382 5792 AmdPPM - ok21:30:59.0407 5792 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys21:30:59.0407 5792 amdsata - ok21:30:59.0422 5792 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys21:30:59.0427 5792 amdsbs - ok21:30:59.0457 5792 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys21:30:59.0457 5792 amdxata - ok21:30:59.0477 5792 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys21:30:59.0477 5792 AppID - ok21:30:59.0512 5792 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll21:30:59.0522 5792 AppIDSvc - ok21:30:59.0557 5792 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll21:30:59.0562 5792 Appinfo - ok21:30:59.0667 5792 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe21:30:59.0667 5792 Apple Mobile Device - ok21:30:59.0707 5792 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll21:30:59.0712 5792 AppMgmt - ok21:30:59.0737 5792 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys21:30:59.0737 5792 arc - ok21:30:59.0752 5792 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys21:30:59.0757 5792 arcsas - ok21:30:59.0862 5792 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe21:30:59.0862 5792 aspnet_state - ok21:30:59.0887 5792 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys21:30:59.0887 5792 AsyncMac - ok21:30:59.0897 5792 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys21:30:59.0897 5792 atapi - ok21:30:59.0952 5792 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll21:30:59.0962 5792 AudioEndpointBuilder - ok21:30:59.0982 5792 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll21:30:59.0992 5792 AudioSrv - ok21:31:00.0032 5792 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll21:31:00.0037 5792 AxInstSV - ok21:31:00.0057 5792 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys21:31:00.0062 5792 b06bdrv - ok21:31:00.0082 5792 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys21:31:00.0087 5792 b57nd60a - ok21:31:00.0102 5792 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll21:31:00.0107 5792 BDESVC - ok21:31:00.0117 5792 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys21:31:00.0117 5792 Beep - ok21:31:00.0152 5792 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll21:31:00.0167 5792 BFE - ok21:31:00.0337 5792 [ 7B56A40EAAACF1867FF178501D3EA185 ] BHDrvx64 C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\BASHDefs\20130521.011\BHDrvx64.sys21:31:00.0352 5792 BHDrvx64 - ok21:31:00.0402 5792 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll21:31:00.0412 5792 BITS - ok21:31:00.0442 5792 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys21:31:00.0442 5792 blbdrive - ok21:31:00.0507 5792 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe21:31:00.0512 5792 Bonjour Service - ok21:31:00.0542 5792 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys21:31:00.0542 5792 bowser - ok21:31:00.0567 5792 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys21:31:00.0567 5792 BrFiltLo - ok21:31:00.0587 5792 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys21:31:00.0587 5792 BrFiltUp - ok21:31:00.0627 5792 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll21:31:00.0627 5792 Browser - ok21:31:00.0652 5792 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys21:31:00.0657 5792 Brserid - ok21:31:00.0677 5792 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys21:31:00.0682 5792 BrSerWdm - ok21:31:00.0737 5792 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys21:31:00.0737 5792 BrUsbMdm - ok21:31:00.0757 5792 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys21:31:00.0757 5792 BrUsbSer - ok21:31:00.0842 5792 [ A510D4E029B977E285FB0116EDE86DBF ] BstHdAndroidSvc C:\Program Files (x86)\BlueStacks\HD-Service.exe21:31:00.0887 5792 BstHdAndroidSvc - ok21:31:00.0917 5792 [ 5E69B16FD15FD4FED0E5964FD6925141 ] BstHdDrv C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys21:31:00.0917 5792 BstHdDrv - ok21:31:00.0947 5792 [ 9F9C8178E839C8B81B9EAE352E5C7E9F ] BstHdLogRotatorSvc C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe21:31:00.0952 5792 BstHdLogRotatorSvc - ok21:31:00.0972 5792 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys21:31:00.0972 5792 BTHMODEM - ok21:31:01.0017 5792 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll21:31:01.0022 5792 bthserv - ok21:31:01.0032 5792 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys21:31:01.0032 5792 cdfs - ok21:31:01.0042 5792 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys21:31:01.0047 5792 cdrom - ok21:31:01.0067 5792 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll21:31:01.0072 5792 CertPropSvc - ok21:31:01.0092 5792 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys21:31:01.0092 5792 circlass - ok21:31:01.0117 5792 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys21:31:01.0127 5792 CLFS - ok21:31:01.0202 5792 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe21:31:01.0267 5792 clr_optimization_v2.0.50727_32 - ok21:31:01.0307 5792 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe21:31:01.0337 5792 clr_optimization_v2.0.50727_64 - ok21:31:01.0392 5792 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe21:31:01.0392 5792 clr_optimization_v4.0.30319_32 - ok21:31:01.0432 5792 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe21:31:01.0432 5792 clr_optimization_v4.0.30319_64 - ok21:31:01.0452 5792 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys21:31:01.0452 5792 CmBatt - ok21:31:01.0467 5792 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys21:31:01.0472 5792 cmdide - ok21:31:01.0517 5792 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys21:31:01.0527 5792 CNG - ok21:31:01.0547 5792 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys21:31:01.0547 5792 Compbatt - ok21:31:01.0567 5792 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys21:31:01.0567 5792 CompositeBus - ok21:31:01.0577 5792 COMSysApp - ok21:31:01.0597 5792 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys21:31:01.0597 5792 crcdisk - ok21:31:01.0642 5792 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll21:31:01.0647 5792 CryptSvc - ok21:31:01.0697 5792 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys21:31:01.0707 5792 CSC - ok21:31:01.0737 5792 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll21:31:01.0747 5792 CscService - ok21:31:01.0802 5792 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll21:31:01.0817 5792 DcomLaunch - ok21:31:01.0862 5792 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll21:31:01.0867 5792 defragsvc - ok21:31:01.0882 5792 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys21:31:01.0887 5792 DfsC - ok21:31:01.0907 5792 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll21:31:01.0912 5792 Dhcp - ok21:31:01.0927 5792 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys21:31:01.0927 5792 discache - ok21:31:01.0947 5792 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys21:31:01.0952 5792 Disk - ok21:31:01.0992 5792 [ 5DB085A8A6600BE6401F2B24EECB5415 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys21:31:01.0992 5792 dmvsc - ok21:31:02.0022 5792 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll21:31:02.0022 5792 Dnscache - ok21:31:02.0037 5792 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll21:31:02.0037 5792 dot3svc - ok21:31:02.0047 5792 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll21:31:02.0047 5792 DPS - ok21:31:02.0087 5792 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys21:31:02.0087 5792 drmkaud - ok21:31:02.0147 5792 [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys21:31:02.0152 5792 dtsoftbus01 - ok21:31:02.0222 5792 [ E5B95C75557120881076C45CD146D72C ] DvmMDES C:\ASUS.SYS\config\DVMExportService.exe21:31:02.0227 5792 DvmMDES - ok21:31:02.0282 5792 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys21:31:02.0297 5792 DXGKrnl - ok21:31:02.0332 5792 EagleX64 - ok21:31:02.0352 5792 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll21:31:02.0357 5792 EapHost - ok21:31:02.0452 5792 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys21:31:02.0517 5792 ebdrv - ok21:31:02.0592 5792 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys21:31:02.0597 5792 eeCtrl - ok21:31:02.0627 5792 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe21:31:02.0632 5792 EFS - ok21:31:02.0712 5792 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe21:31:02.0727 5792 ehRecvr - ok21:31:02.0737 5792 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe21:31:02.0742 5792 ehSched - ok21:31:02.0782 5792 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys21:31:02.0792 5792 elxstor - ok21:31:02.0837 5792 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys21:31:02.0842 5792 EraserUtilRebootDrv - ok21:31:02.0857 5792 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys21:31:02.0857 5792 ErrDev - ok21:31:02.0897 5792 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll21:31:02.0907 5792 EventSystem - ok21:31:02.0932 5792 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys21:31:02.0937 5792 exfat - ok21:31:02.0957 5792 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys21:31:02.0962 5792 fastfat - ok21:31:02.0992 5792 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe21:31:03.0007 5792 Fax - ok21:31:03.0032 5792 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys21:31:03.0032 5792 fdc - ok21:31:03.0047 5792 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll21:31:03.0052 5792 fdPHost - ok21:31:03.0052 5792 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll21:31:03.0052 5792 FDResPub - ok21:31:03.0062 5792 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys21:31:03.0067 5792 FileInfo - ok21:31:03.0072 5792 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys21:31:03.0072 5792 Filetrace - ok21:31:03.0087 5792 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys21:31:03.0087 5792 flpydisk - ok21:31:03.0102 5792 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys21:31:03.0102 5792 FltMgr - ok21:31:03.0167 5792 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll21:31:03.0187 5792 FontCache - ok21:31:03.0247 5792 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe21:31:03.0257 5792 FontCache3.0.0.0 - ok21:31:03.0277 5792 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys21:31:03.0277 5792 FsDepends - ok21:31:03.0327 5792 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys21:31:03.0327 5792 Fs_Rec - ok21:31:03.0377 5792 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys21:31:03.0382 5792 fvevol - ok21:31:03.0402 5792 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys21:31:03.0407 5792 gagp30kx - ok21:31:03.0462 5792 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys21:31:03.0462 5792 GEARAspiWDM - ok21:31:03.0497 5792 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll21:31:03.0512 5792 gpsvc - ok21:31:03.0612 5792 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe21:31:03.0612 5792 gupdate - ok21:31:03.0632 5792 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe21:31:03.0637 5792 gupdatem - ok21:31:03.0677 5792 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe21:31:03.0692 5792 gusvc - ok21:31:03.0717 5792 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys21:31:03.0717 5792 hcw85cir - ok21:31:03.0772 5792 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys21:31:03.0777 5792 HdAudAddService - ok21:31:03.0802 5792 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys21:31:03.0807 5792 HDAudBus - ok21:31:03.0822 5792 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys21:31:03.0822 5792 HidBatt - ok21:31:03.0842 5792 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys21:31:03.0842 5792 HidBth - ok21:31:03.0857 5792 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys21:31:03.0862 5792 HidIr - ok21:31:03.0887 5792 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll21:31:03.0887 5792 hidserv - ok21:31:03.0917 5792 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys21:31:03.0917 5792 HidUsb - ok21:31:03.0927 5792 HiPatchService - ok21:31:03.0972 5792 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll21:31:03.0972 5792 hkmsvc - ok21:31:03.0992 5792 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll21:31:03.0997 5792 HomeGroupListener - ok21:31:04.0032 5792 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll21:31:04.0037 5792 HomeGroupProvider - ok21:31:04.0057 5792 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys21:31:04.0057 5792 HpSAMD - ok21:31:04.0087 5792 [ F47CEC45FB85791D4AB237563AD0FA8F ] HTCAND64 C:\Windows\system32\Drivers\ANDROIDUSB.sys21:31:04.0087 5792 HTCAND64 - ok21:31:04.0112 5792 [ B8B1B284362E1D8135112573395D5DA5 ] htcnprot C:\Windows\system32\DRIVERS\htcnprot.sys21:31:04.0117 5792 htcnprot - ok21:31:04.0147 5792 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys21:31:04.0162 5792 HTTP - ok21:31:04.0172 5792 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys21:31:04.0172 5792 hwpolicy - ok21:31:04.0182 5792 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys21:31:04.0187 5792 i8042prt - ok21:31:04.0202 5792 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys21:31:04.0202 5792 iaStorV - ok21:31:04.0257 5792 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe21:31:04.0272 5792 idsvc - ok21:31:04.0352 5792 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\IPSDefs\20130611.001\IDSvia64.sys21:31:04.0362 5792 IDSVia64 - ok21:31:04.0377 5792 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys21:31:04.0377 5792 iirsp - ok21:31:04.0412 5792 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll21:31:04.0427 5792 IKEEXT - ok21:31:04.0447 5792 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys21:31:04.0447 5792 intelide - ok21:31:04.0462 5792 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\drivers\intelppm.sys21:31:04.0462 5792 intelppm - ok21:31:04.0482 5792 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll21:31:04.0487 5792 IPBusEnum - ok21:31:04.0497 5792 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys21:31:04.0502 5792 IpFilterDriver - ok21:31:04.0547 5792 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll21:31:04.0557 5792 iphlpsvc - ok21:31:04.0577 5792 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys21:31:04.0582 5792 IPMIDRV - ok21:31:04.0597 5792 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys21:31:04.0597 5792 IPNAT - ok21:31:04.0637 5792 [ 4EFFC8FF6D349E971E94B1C670C0C66A ] iPod Service C:\Program Files\iPod\bin\iPodService.exe21:31:04.0642 5792 iPod Service - ok21:31:04.0657 5792 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys21:31:04.0657 5792 IRENUM - ok21:31:04.0672 5792 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys21:31:04.0672 5792 isapnp - ok21:31:04.0687 5792 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys21:31:04.0692 5792 iScsiPrt - ok21:31:04.0707 5792 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys21:31:04.0707 5792 kbdclass - ok21:31:04.0722 5792 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys21:31:04.0722 5792 kbdhid - ok21:31:04.0737 5792 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe21:31:04.0737 5792 KeyIso - ok21:31:04.0762 5792 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys21:31:04.0767 5792 KSecDD - ok21:31:04.0802 5792 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys21:31:04.0802 5792 KSecPkg - ok21:31:04.0812 5792 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys21:31:04.0812 5792 ksthunk - ok21:31:04.0832 5792 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll21:31:04.0837 5792 KtmRm - ok21:31:04.0857 5792 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll21:31:04.0862 5792 LanmanServer - ok21:31:04.0893 5792 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll21:31:04.0893 5792 LanmanWorkstation - ok21:31:04.0918 5792 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys21:31:04.0918 5792 lltdio - ok21:31:04.0953 5792 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll21:31:04.0958 5792 lltdsvc - ok21:31:04.0968 5792 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll21:31:04.0968 5792 lmhosts - ok21:31:04.0978 5792 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys21:31:04.0983 5792 LSI_FC - ok21:31:04.0998 5792 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys21:31:04.0998 5792 LSI_SAS - ok21:31:05.0013 5792 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys21:31:05.0013 5792 LSI_SAS2 - ok21:31:05.0028 5792 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys21:31:05.0028 5792 LSI_SCSI - ok21:31:05.0048 5792 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys21:31:05.0048 5792 luafv - ok21:31:05.0103 5792 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys21:31:05.0103 5792 MBAMProtector - ok21:31:05.0158 5792 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe21:31:05.0163 5792 MBAMScheduler - ok21:31:05.0203 5792 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe21:31:05.0213 5792 MBAMService - ok21:31:05.0248 5792 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll21:31:05.0268 5792 Mcx2Svc - ok21:31:05.0273 5792 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys21:31:05.0278 5792 megasas - ok21:31:05.0298 5792 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys21:31:05.0298 5792 MegaSR - ok21:31:05.0348 5792 Microsoft SharePoint Workspace Audit Service - ok21:31:05.0373 5792 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll21:31:05.0378 5792 MMCSS - ok21:31:05.0393 5792 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys21:31:05.0393 5792 Modem - ok21:31:05.0418 5792 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys21:31:05.0418 5792 monitor - ok21:31:05.0433 5792 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys21:31:05.0438 5792 mouclass - ok21:31:05.0458 5792 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys21:31:05.0458 5792 mouhid - ok21:31:05.0468 5792 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys21:31:05.0468 5792 mountmgr - ok21:31:05.0493 5792 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe21:31:05.0503 5792 MozillaMaintenance - ok21:31:05.0513 5792 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys21:31:05.0518 5792 mpio - ok21:31:05.0533 5792 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys21:31:05.0533 5792 mpsdrv - ok21:31:05.0558 5792 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll21:31:05.0568 5792 MpsSvc - ok21:31:05.0578 5792 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys21:31:05.0578 5792 MRxDAV - ok21:31:05.0623 5792 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys21:31:05.0628 5792 mrxsmb - ok21:31:05.0663 5792 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys21:31:05.0668 5792 mrxsmb10 - ok21:31:05.0688 5792 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys21:31:05.0693 5792 mrxsmb20 - ok21:31:05.0713 5792 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys21:31:05.0713 5792 msahci - ok21:31:05.0733 5792 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys21:31:05.0733 5792 msdsm - ok21:31:05.0753 5792 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe21:31:05.0758 5792 MSDTC - ok21:31:05.0788 5792 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys21:31:05.0788 5792 Msfs - ok21:31:05.0803 5792 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys21:31:05.0803 5792 mshidkmdf - ok21:31:05.0833 5792 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys21:31:05.0833 5792 msisadrv - ok21:31:05.0853 5792 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll21:31:05.0853 5792 MSiSCSI - ok21:31:05.0858 5792 msiserver - ok21:31:05.0878 5792 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys21:31:05.0878 5792 MSKSSRV - ok21:31:05.0908 5792 [ 103B3BBE23AB774B009D182276EC6786 ] msloop C:\Windows\system32\DRIVERS\loop.sys21:31:05.0908 5792 msloop - ok21:31:05.0933 5792 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys21:31:05.0933 5792 MSPCLOCK - ok21:31:05.0938 5792 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys21:31:05.0943 5792 MSPQM - ok21:31:05.0958 5792 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys21:31:05.0963 5792 MsRPC - ok21:31:05.0968 5792 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys21:31:05.0973 5792 mssmbios - ok21:31:05.0978 5792 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys21:31:05.0983 5792 MSTEE - ok21:31:05.0993 5792 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys21:31:05.0993 5792 MTConfig - ok21:31:06.0033 5792 [ 19B006B181E3875FD254F7B67ACF1E7C ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys21:31:06.0033 5792 MTsensor - ok21:31:06.0053 5792 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys21:31:06.0053 5792 Mup - ok21:31:06.0093 5792 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll21:31:06.0098 5792 napagent - ok21:31:06.0113 5792 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys21:31:06.0118 5792 NativeWifiP - ok21:31:06.0213 5792 [ 56540E526B46E379A476FB5BC381B290 ] NAVENG C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\VirusDefs\20130611.018\ENG64.SYS21:31:06.0213 5792 NAVENG - ok21:31:06.0278 5792 [ 8A19D3991F9F14B885CDE8BC640F6B68 ] NAVEX15 C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\VirusDefs\20130611.018\EX64.SYS21:31:06.0308 5792 NAVEX15 - ok21:31:06.0368 5792 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys21:31:06.0383 5792 NDIS - ok21:31:06.0413 5792 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys21:31:06.0413 5792 NdisCap - ok21:31:06.0438 5792 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys21:31:06.0438 5792 NdisTapi - ok21:31:06.0458 5792 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys21:31:06.0458 5792 Ndisuio - ok21:31:06.0483 5792 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys21:31:06.0513 5792 NdisWan - ok21:31:06.0533 5792 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys21:31:06.0538 5792 NDProxy - ok21:31:06.0548 5792 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys21:31:06.0553 5792 NetBIOS - ok21:31:06.0573 5792 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys21:31:06.0578 5792 NetBT - ok21:31:06.0593 5792 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe21:31:06.0593 5792 Netlogon - ok21:31:06.0638 5792 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll21:31:06.0648 5792 Netman - ok21:31:06.0678 5792 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe21:31:06.0683 5792 NetMsmqActivator - ok21:31:06.0693 5792 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe21:31:06.0698 5792 NetPipeActivator - ok21:31:06.0723 5792 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll21:31:06.0728 5792 netprofm - ok21:31:06.0733 5792 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe21:31:06.0738 5792 NetTcpActivator - ok21:31:06.0743 5792 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe21:31:06.0743 5792 NetTcpPortSharing - ok21:31:06.0758 5792 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys21:31:06.0763 5792 nfrd960 - ok21:31:06.0853 5792 [ DCD9287B04DE83CA22C8057C358243EA ] NitroReaderDriverReadSpool3 C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe21:31:06.0858 5792 NitroReaderDriverReadSpool3 - ok21:31:06.0878 5792 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll21:31:06.0878 5792 NlaSvc - ok21:31:06.0888 5792 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys21:31:06.0888 5792 Npfs - ok21:31:06.0903 5792 npggsvc - ok21:31:06.0913 5792 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll21:31:06.0918 5792 nsi - ok21:31:06.0928 5792 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys21:31:06.0928 5792 nsiproxy - ok21:31:07.0003 5792 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys21:31:07.0033 5792 Ntfs - ok21:31:07.0058 5792 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys21:31:07.0058 5792 Null - ok21:31:07.0083 5792 [ 285ACEC1B13A15BA520AAE06BACB9CFF ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys21:31:07.0083 5792 nusb3hub - ok21:31:07.0113 5792 [ F6D625FF7B56BB6EA063F0D3A5BBC996 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys21:31:07.0113 5792 nusb3xhc - ok21:31:07.0153 5792 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys21:31:07.0158 5792 NVHDA - ok21:31:07.0378 5792 [ FCBA1C22727939E7CFF9EB08FE9692AB ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys21:31:07.0418 5792 nvlddmkm - ok21:31:07.0438 5792 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys21:31:07.0438 5792 nvraid - ok21:31:07.0448 5792 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys21:31:07.0448 5792 nvstor - ok21:31:07.0478 5792 [ 10C232F6CFFD51D2332898AE7AE0FF23 ] nvsvc C:\Windows\system32\nvvsvc.exe21:31:07.0483 5792 nvsvc - ok21:31:07.0543 5792 [ 4789E020D2617046862D1790FC235FF6 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe21:31:07.0558 5792 nvUpdatusService - ok21:31:07.0578 5792 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys21:31:07.0583 5792 nv_agp - ok21:31:07.0598 5792 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys21:31:07.0603 5792 ohci1394 - ok21:31:07.0638 5792 OracleJobSchedulerXE - ok21:31:07.0643 5792 OracleMTSRecoveryService - ok21:31:07.0648 5792 OracleServiceXE - ok21:31:07.0653 5792 OracleXEClrAgent - ok21:31:07.0683 5792 [ 788D4CD078E3D55D92C4B986C739DA43 ] OracleXETNSListener C:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe21:31:07.0688 5792 OracleXETNSListener - ok21:31:07.0733 5792 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE21:31:07.0733 5792 ose64 - ok21:31:07.0858 5792 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE21:31:07.0883 5792 osppsvc - ok21:31:07.0923 5792 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll21:31:07.0928 5792 p2pimsvc - ok21:31:07.0968 5792 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll21:31:07.0978 5792 p2psvc - ok21:31:07.0993 5792 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys21:31:07.0998 5792 Parport - ok21:31:08.0018 5792 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys21:31:08.0018 5792 partmgr - ok21:31:08.0053 5792 [ 68139940B5AC84AFFB7EB1B713BE66E7 ] PassThru Service C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe21:31:08.0053 5792 PassThru Service - ok21:31:08.0073 5792 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll21:31:08.0078 5792 PcaSvc - ok21:31:08.0088 5792 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys21:31:08.0088 5792 pci - ok21:31:08.0098 5792 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys21:31:08.0098 5792 pciide - ok21:31:08.0118 5792 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys21:31:08.0118 5792 pcmcia - ok21:31:08.0133 5792 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys21:31:08.0133 5792 pcw - ok21:31:08.0143 5792 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys21:31:08.0153 5792 PEAUTH - ok21:31:08.0213 5792 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll21:31:08.0238 5792 PeerDistSvc - ok21:31:08.0328 5792 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe21:31:08.0328 5792 PerfHost - ok21:31:08.0368 5792 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll21:31:08.0393 5792 pla - ok21:31:08.0428 5792 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll21:31:08.0438 5792 PlugPlay - ok21:31:08.0473 5792 PnkBstrA - ok21:31:08.0488 5792 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll21:31:08.0493 5792 PNRPAutoReg - ok21:31:08.0518 5792 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll21:31:08.0528 5792 PNRPsvc - ok21:31:08.0573 5792 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll21:31:08.0583 5792 PolicyAgent - ok21:31:08.0633 5792 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll21:31:08.0638 5792 Power - ok21:31:08.0708 5792 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys21:31:08.0708 5792 PptpMiniport - ok21:31:08.0723 5792 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys21:31:08.0728 5792 Processor - ok21:31:08.0768 5792 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll21:31:08.0773 5792 ProfSvc - ok21:31:08.0788 5792 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe21:31:08.0793 5792 ProtectedStorage - ok21:31:08.0843 5792 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys21:31:08.0848 5792 Psched - ok21:31:08.0903 5792 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys21:31:08.0928 5792 ql2300 - ok21:31:08.0943 5792 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys21:31:08.0948 5792 ql40xx - ok21:31:08.0963 5792 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll21:31:08.0968 5792 QWAVE - ok21:31:08.0978 5792 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys21:31:08.0978 5792 QWAVEdrv - ok21:31:08.0988 5792 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys21:31:08.0988 5792 RasAcd - ok21:31:09.0003 5792 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys21:31:09.0003 5792 RasAgileVpn - ok21:31:09.0013 5792 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll21:31:09.0018 5792 RasAuto - ok21:31:09.0028 5792 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys21:31:09.0028 5792 Rasl2tp - ok21:31:09.0043 5792 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll21:31:09.0048 5792 RasMan - ok21:31:09.0063 5792 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys21:31:09.0063 5792 RasPppoe - ok21:31:09.0073 5792 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys21:31:09.0073 5792 RasSstp - ok21:31:09.0083 5792 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys21:31:09.0088 5792 rdbss - ok21:31:09.0103 5792 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys21:31:09.0103 5792 rdpbus - ok21:31:09.0108 5792 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys21:31:09.0108 5792 RDPCDD - ok21:31:09.0153 5792 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys21:31:09.0158 5792 RDPDR - ok21:31:09.0163 5792 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys21:31:09.0168 5792 RDPENCDD - ok21:31:09.0183 5792 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys21:31:09.0183 5792 RDPREFMP - ok21:31:09.0213 5792 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys21:31:09.0213 5792 RdpVideoMiniport - ok21:31:09.0243 5792 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys21:31:09.0248 5792 RDPWD - ok21:31:09.0308 5792 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys21:31:09.0313 5792 rdyboost - ok21:31:09.0348 5792 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll21:31:09.0353 5792 RemoteAccess - ok21:31:09.0393 5792 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll21:31:09.0398 5792 RemoteRegistry - ok21:31:09.0418 5792 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll21:31:09.0418 5792 RpcEptMapper - ok21:31:09.0438 5792 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe21:31:09.0438 5792 RpcLocator - ok21:31:09.0463 5792 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll21:31:09.0473 5792 RpcSs - ok21:31:09.0488 5792 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys21:31:09.0488 5792 rspndr - ok21:31:09.0523 5792 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys21:31:09.0528 5792 RTL8167 - ok21:31:09.0543 5792 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys21:31:09.0543 5792 s3cap - ok21:31:09.0553 5792 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe21:31:09.0558 5792 SamSs - ok21:31:09.0573 5792 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys21:31:09.0578 5792 sbp2port - ok21:31:09.0598 5792 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll21:31:09.0598 5792 SCardSvr - ok21:31:09.0613 5792 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys21:31:09.0613 5792 scfilter - ok21:31:09.0638 5792 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll21:31:09.0653 5792 Schedule - ok21:31:09.0683 5792 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll21:31:09.0688 5792 SCPolicySvc - ok21:31:09.0698 5792 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll21:31:09.0703 5792 SDRSVC - ok21:31:09.0718 5792 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys21:31:09.0718 5792 secdrv - ok21:31:09.0733 5792 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll21:31:09.0733 5792 seclogon - ok21:31:09.0743 5792 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll21:31:09.0743 5792 SENS - ok21:31:09.0753 5792 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll21:31:09.0758 5792 SensrSvc - ok21:31:09.0823 5792 [ 74885BDFF62E537F268EBF8E8CEC24BB ] SepMasterService C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe21:31:09.0823 5792 SepMasterService - ok21:31:09.0833 5792 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys21:31:09.0833 5792 Serenum - ok21:31:09.0838 5792 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys21:31:09.0838 5792 Serial - ok21:31:09.0853 5792 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys21:31:09.0853 5792 sermouse - ok21:31:09.0888 5792 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll21:31:09.0888 5792 SessionEnv - ok21:31:09.0903 5792 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys21:31:09.0903 5792 sffdisk - ok21:31:09.0918 5792 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys21:31:09.0918 5792 sffp_mmc - ok21:31:09.0928 5792 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys21:31:09.0928 5792 sffp_sd - ok21:31:09.0943 5792 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys21:31:09.0943 5792 sfloppy - ok21:31:09.0983 5792 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll21:31:09.0993 5792 SharedAccess - ok21:31:10.0013 5792 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll21:31:10.0018 5792 ShellHWDetection - ok21:31:10.0033 5792 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys21:31:10.0033 5792 SiSRaid2 - ok21:31:10.0048 5792 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys21:31:10.0048 5792 SiSRaid4 - ok21:31:10.0168 5792 [ EB17DF573B4423DF0B3B2EE3B268A6DE ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe21:31:10.0193 5792 Skype C2C Service - ok21:31:10.0238 5792 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe21:31:10.0243 5792 SkypeUpdate - ok21:31:10.0268 5792 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys21:31:10.0273 5792 Smb - ok21:31:10.0393 5792 [ B8EF6F1FAFBE89E24E152907605E7A25 ] SmcService C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin64\Smc.exe21:31:10.0403 5792 SmcService - ok21:31:10.0428 5792 [ 89733DCC3817455FBC3AB4A3C19EE765 ] SNAC C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin64\snac64.exe21:31:10.0433 5792 SNAC - ok21:31:10.0458 5792 [ B84440E7554FC85E900EEF0A7AABA228 ] snapman C:\Windows\system32\DRIVERS\snapman.sys21:31:10.0458 5792 snapman - ok21:31:10.0503 5792 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe21:31:10.0508 5792 SNMPTRAP - ok21:31:10.0518 5792 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys21:31:10.0518 5792 spldr - ok21:31:10.0563 5792 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe21:31:10.0573 5792 Spooler - ok21:31:10.0668 5792 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe21:31:10.0738 5792 sppsvc - ok21:31:10.0748 5792 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll21:31:10.0748 5792 sppuinotify - ok21:31:10.0778 5792 [ 48FD53FED3C81726001E438A2201E9FF ] SRTSP C:\Windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SRTSP64.SYS21:31:10.0783 5792 SRTSP - ok21:31:10.0803 5792 [ 63199A936D9BDEA578DFB8F5E9A40095 ] SRTSPX C:\Windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SRTSPX64.SYS21:31:10.0803 5792 SRTSPX - ok21:31:10.0823 5792 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys21:31:10.0828 5792 srv - ok21:31:10.0848 5792 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys21:31:10.0853 5792 srv2 - ok21:31:10.0868 5792 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys21:31:10.0868 5792 srvnet - ok21:31:10.0893 5792 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll21:31:10.0898 5792 SSDPSRV - ok21:31:10.0913 5792 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll21:31:10.0923 5792 SstpSvc - ok21:31:10.0973 5792 Steam Client Service - ok21:31:11.0038 5792 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe21:31:11.0043 5792 Stereo Service - ok21:31:11.0078 5792 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys21:31:11.0078 5792 stexstor - ok21:31:11.0113 5792 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll21:31:11.0123 5792 stisvc - ok21:31:11.0153 5792 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys21:31:11.0158 5792 storflt - ok21:31:11.0178 5792 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll21:31:11.0178 5792 StorSvc - ok21:31:11.0188 5792 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys21:31:11.0188 5792 storvsc - ok21:31:11.0203 5792 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys21:31:11.0203 5792 swenum - ok21:31:11.0268 5792 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe21:31:11.0278 5792 SwitchBoard - ok21:31:11.0313 5792 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll21:31:11.0328 5792 swprv - ok21:31:11.0378 5792 [ F017987B177F7BBC989318D59309D091 ] SymDS C:\Windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMDS64.SYS21:31:11.0388 5792 SymDS - ok21:31:11.0433 5792 [ E7F25D768EE0CDF69D8B752398C262BB ] SymEFA C:\Windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMEFA64.SYS21:31:11.0453 5792 SymEFA - ok21:31:11.0478 5792 [ 36B77F5C9E21F88A8C8EC67AD5415819 ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS21:31:11.0478 5792 SymEvent - ok21:31:11.0528 5792 [ 1611FA7A95A48387DF22757FA81B46A9 ] SymIRON C:\Windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\Ironx64.SYS21:31:11.0533 5792 SymIRON - ok21:31:11.0558 5792 [ D41557715C1C792D1391DB5AA81A00DF ] SYMNETS C:\Windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMNETS.SYS21:31:11.0563 5792 SYMNETS - ok21:31:11.0623 5792 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll21:31:11.0668 5792 SysMain - ok21:31:11.0693 5792 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll21:31:11.0698 5792 TabletInputService - ok21:31:11.0743 5792 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll21:31:11.0748 5792 TapiSrv - ok21:31:11.0768 5792 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll21:31:11.0768 5792 TBS - ok21:31:11.0838 5792 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys21:31:11.0898 5792 Tcpip - ok21:31:11.0988 5792 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys21:31:12.0018 5792 TCPIP6 - ok21:31:12.0058 5792 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys21:31:12.0058 5792 tcpipreg - ok21:31:12.0083 5792 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys21:31:12.0083 5792 TDPIPE - ok21:31:12.0113 5792 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys21:31:12.0118 5792 TDTCP - ok21:31:12.0133 5792 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys21:31:12.0133 5792 tdx - ok21:31:12.0293 5792 [ 6B1B2F8D62D606B200C2072564090104 ] TeamViewer8 C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe21:31:12.0318 5792 TeamViewer8 - ok21:31:12.0353 5792 [ 7DD4F26F73EFE8E0817E18D1D1B9B18A ] Teefer2 C:\Windows\system32\DRIVERS\Teefer.sys21:31:12.0358 5792 Teefer2 - ok21:31:12.0373 5792 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys21:31:12.0373 5792 TermDD - ok21:31:12.0403 5792 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll21:31:12.0408 5792 TermService - ok21:31:12.0423 5792 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll21:31:12.0428 5792 Themes - ok21:31:12.0458 5792 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll21:31:12.0458 5792 THREADORDER - ok21:31:12.0473 5792 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll21:31:12.0478 5792 TrkWks - ok21:31:12.0543 5792 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe21:31:12.0543 5792 TrustedInstaller - ok21:31:12.0563 5792 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys21:31:12.0563 5792 tssecsrv - ok21:31:12.0633 5792 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys21:31:12.0638 5792 TsUsbFlt - ok21:31:12.0658 5792 [ AD64450A4ABE076F5CB34CC08EEACB07 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys21:31:12.0663 5792 TsUsbGD - ok21:31:12.0688 5792 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys21:31:12.0693 5792 tunnel - ok21:31:12.0708 5792 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys21:31:12.0708 5792 uagp35 - ok21:31:12.0733 5792 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys21:31:12.0738 5792 udfs - ok21:31:12.0778 5792 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe21:31:12.0783 5792 UI0Detect - ok21:31:12.0803 5792 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys21:31:12.0808 5792 uliagpkx - ok21:31:12.0823 5792 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys21:31:12.0823 5792 umbus - ok21:31:12.0843 5792 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys21:31:12.0843 5792 UmPass - ok21:31:12.0883 5792 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll21:31:12.0888 5792 UmRdpService - ok21:31:12.0913 5792 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll21:31:12.0918 5792 upnphost - ok21:31:12.0958 5792 [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys21:31:12.0958 5792 USBAAPL64 - ok21:31:13.0008 5792 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys21:31:13.0013 5792 usbaudio - ok21:31:13.0033 5792 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys21:31:13.0038 5792 usbccgp - ok21:31:13.0058 5792 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys21:31:13.0058 5792 usbcir - ok21:31:13.0078 5792 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys21:31:13.0083 5792 usbehci - ok21:31:13.0098 5792 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys21:31:13.0103 5792 usbhub - ok21:31:13.0118 5792 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys21:31:13.0118 5792 usbohci - ok21:31:13.0128 5792 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys21:31:13.0128 5792 usbprint - ok21:31:13.0148 5792 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS21:31:13.0148 5792 USBSTOR - ok21:31:13.0163 5792 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys21:31:13.0163 5792 usbuhci - ok21:31:13.0178 5792 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll21:31:13.0178 5792 UxSms - ok21:31:13.0183 5792 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe21:31:13.0183 5792 VaultSvc - ok21:31:13.0193 5792 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys21:31:13.0193 5792 vdrvroot - ok21:31:13.0208 5792 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe21:31:13.0213 5792 vds - ok21:31:13.0223 5792 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys21:31:13.0223 5792 vga - ok21:31:13.0233 5792 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys21:31:13.0238 5792 VgaSave - ok21:31:13.0253 5792 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys21:31:13.0253 5792 vhdmp - ok21:31:13.0268 5792 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys21:31:13.0268 5792 viaide - ok21:31:13.0293 5792 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys21:31:13.0298 5792 vmbus - ok21:31:13.0313 5792 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys21:31:13.0313 5792 VMBusHID - ok21:31:13.0333 5792 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys21:31:13.0338 5792 volmgr - ok21:31:13.0363 5792 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys21:31:13.0368 5792 volmgrx - ok21:31:13.0393 5792 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys21:31:13.0398 5792 volsnap - ok21:31:13.0423 5792 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys21:31:13.0428 5792 vsmraid - ok21:31:13.0473 5792 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe21:31:13.0508 5792 VSS - ok21:31:13.0523 5792 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys21:31:13.0523 5792 vwifibus - ok21:31:13.0543 5792 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll21:31:13.0548 5792 W32Time - ok21:31:13.0563 5792 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys21:31:13.0563 5792 WacomPen - ok21:31:13.0628 5792 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys21:31:13.0633 5792 WANARP - ok21:31:13.0658 5792 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys21:31:13.0658 5792 Wanarpv6 - ok21:31:13.0713 5792 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe21:31:13.0733 5792 WatAdminSvc - ok21:31:13.0808 5792 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe21:31:13.0858 5792 wbengine - ok21:31:13.0873 5792 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll21:31:13.0878 5792 WbioSrvc - ok21:31:13.0908 5792 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll21:31:13.0913 5792 wcncsvc - ok21:31:13.0933 5792 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll21:31:13.0938 5792 WcsPlugInService - ok21:31:13.0953 5792 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys21:31:13.0953 5792 Wd - ok21:31:13.0998 5792 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys21:31:14.0008 5792 Wdf01000 - ok21:31:14.0018 5792 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll21:31:14.0023 5792 WdiServiceHost - ok21:31:14.0033 5792 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll21:31:14.0033 5792 WdiSystemHost - ok21:31:14.0068 5792 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll21:31:14.0068 5792 WebClient - ok21:31:14.0158 5792 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll21:31:14.0178 5792 Wecsvc - ok21:31:14.0268 5792 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll21:31:14.0273 5792 wercplsupport - ok21:31:14.0288 5792 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll21:31:14.0298 5792 WerSvc - ok21:31:14.0313 5792 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys21:31:14.0313 5792 WfpLwf - ok21:31:14.0333 5792 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys21:31:14.0333 5792 WIMMount - ok21:31:14.0348 5792 WinDefend - ok21:31:14.0373 5792 WinHttpAutoProxySvc - ok21:31:14.0433 5792 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll21:31:14.0433 5792 Winmgmt - ok21:31:14.0478 5792 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll21:31:14.0513 5792 WinRM - ok21:31:14.0558 5792 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys21:31:14.0558 5792 WinUsb - ok21:31:14.0613 5792 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll21:31:14.0633 5792 Wlansvc - ok21:31:14.0738 5792 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE21:31:14.0773 5792 wlidsvc - ok21:31:14.0793 5792 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys21:31:14.0798 5792 WmiAcpi - ok21:31:14.0808 5792 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe21:31:14.0813 5792 wmiApSrv - ok21:31:14.0818 5792 WMPNetworkSvc - ok21:31:14.0833 5792 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll21:31:14.0838 5792 WPCSvc - ok21:31:14.0853 5792 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll21:31:14.0858 5792 WPDBusEnum - ok21:31:14.0868 5792 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys21:31:14.0868 5792 ws2ifsl - ok21:31:14.0873 5792 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll21:31:14.0878 5792 wscsvc - ok21:31:14.0883 5792 WSearch - ok21:31:14.0968 5792 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll21:31:15.0023 5792 wuauserv - ok21:31:15.0058 5792 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys21:31:15.0063 5792 WudfPf - ok21:31:15.0078 5792 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys21:31:15.0083 5792 WUDFRd - ok21:31:15.0098 5792 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll21:31:15.0098 5792 wudfsvc - ok21:31:15.0133 5792 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll21:31:15.0133 5792 WwanSvc - ok21:31:15.0188 5792 X6va011 - ok21:31:15.0233 5792 [ 2C6BC21B2D5B58D8B1D638C1704CB494 ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys21:31:15.0238 5792 xusb21 - ok21:31:15.0263 5792 ================ Scan global ===============================21:31:15.0298 5792 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll21:31:15.0338 5792 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll21:31:15.0353 5792 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll21:31:15.0408 5792 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll21:31:15.0453 5792 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe21:31:15.0458 5792 [Global] - ok21:31:15.0458 5792 ================ Scan MBR ==================================21:31:15.0468 5792 [ C3C93F1CA51BBACBABEA804D2CC62CA1 ] \Device\Harddisk0\DR021:31:15.0468 5792 Suspicious mbr (Forged): \Device\Harddisk0\DR021:31:15.0513 5792 \Device\Harddisk0\DR0 ( Rootkit.Boot.Harbinger.a ) - infected21:31:15.0513 5792 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Harbinger.a (0)21:31:15.0518 5792 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR121:31:15.0733 5792 \Device\Harddisk1\DR1 - ok21:31:15.0733 5792 ================ Scan VBR ==================================21:31:15.0753 5792 [ 896CFF8FA85AF2A8898F077F182462D6 ] \Device\Harddisk0\DR0\Partition121:31:15.0753 5792 \Device\Harddisk0\DR0\Partition1 - ok21:31:15.0768 5792 [ 2F730CCFBC94C50B9CA726695B90CF51 ] \Device\Harddisk0\DR0\Partition221:31:15.0773 5792 \Device\Harddisk0\DR0\Partition2 - ok21:31:15.0773 5792 ============================================================21:31:15.0773 5792 Scan finished21:31:15.0773 5792 ============================================================21:31:15.0833 6236 Detected object count: 121:31:15.0833 6236 Actual detected object count: 121:32:00.0984 6236 \Device\Harddisk0\DR0\# - copied to quarantine21:32:00.0984 6236 \Device\Harddisk0\DR0 - copied to quarantine21:32:01.0034 6236 \Device\Harddisk0\DR0 ( Rootkit.Boot.Harbinger.a ) - will be cured on reboot21:32:01.0034 6236 \Device\Harddisk0\DR0 - ok21:32:01.0044 6236 \Device\Harddisk0\DR0 ( Rootkit.Boot.Harbinger.a ) - User select action: Cure21:32:11.0930 4536 Deinitialize successMalwarebytes Anti-Rootkit BETA 1.06.0.1003www.malwarebytes.orgDatabase version: v2013.06.12.01Windows 7 Service Pack 1 x64 NTFSInternet Explorer 10.0.9200.16576THMark :: THMARK-PC [administrator]6/11/2013 9:42:21 PMmbar-log-2013-06-11 (21-42-21).txtScan type: Quick scanScan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2PScan options disabled: Deep Anti-Rootkit Scan | PUPObjects scanned: 288152Time elapsed: 22 minute(s), 4 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 0(No malicious items detected)Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 0(No malicious items detected)Physical Sectors Detected: 0(No malicious items detected)(end) Link to post Share on other sites More sharing options...
dnahunter Posted June 12, 2013 Author ID:690123 Share Posted June 12, 2013 ComboFix 13-06-08.02 - THMark 06/11/2013 22:35:19.1.6 - x64Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8191.5790 [GMT -7:00]Running from: c:\users\THMark\Desktop\ComboFix.exeAV: Symantec Endpoint Protection *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}FW: Symantec Endpoint Protection *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}SP: Symantec Endpoint Protection *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..C:\CFLogC:\install.exec:\users\THMark\AppData\Local\assembly\tmpc:\users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\{086787C8-800B-4D50-955A-4422894F9326}.xpsc:\users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1E7FD0E1-B88B-419D-82F0-0C321F6E2BA6}.xpsc:\users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\{C9B2F4EC-5B07-4A68-B8D3-940D0156BB46}.xpsc:\users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\{F994083F-F676-4768-AF1E-11802281FFB5}.xpsc:\users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\searchplugins\bing-zugo.xmlc:\users\THMark\Documents\~WRL0070.tmpc:\windows\security\Database\tmp.edb..((((((((((((((((((((((((( Files Created from 2013-05-12 to 2013-06-12 )))))))))))))))))))))))))))))))..2013-06-12 05:45 . 2013-06-12 05:45 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp2013-06-12 05:45 . 2013-06-12 05:45 -------- d-----w- c:\users\hedev\AppData\Local\temp2013-06-12 05:45 . 2013-06-12 05:45 -------- d-----w- c:\users\Default\AppData\Local\temp2013-06-12 04:47 . 2013-06-12 04:47 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE81F950-7FAF-4341-A8D7-685562AEAE08}\offreg.dll2013-06-12 04:42 . 2013-06-12 05:30 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)2013-06-12 04:32 . 2013-06-12 04:32 -------- d-----w- C:\TDSSKiller_Quarantine2013-06-11 16:31 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE81F950-7FAF-4341-A8D7-685562AEAE08}\mpengine.dll2013-06-10 03:43 . 2013-06-10 21:06 -------- d-----w- c:\users\THMark\AppData\Local\Warframe2013-06-09 03:39 . 2013-06-09 03:39 -------- d-----w- c:\users\THMark\AppData\Local\FreeOCR2013-06-09 03:35 . 2013-06-12 05:41 -------- d-----w- c:\users\THMark\AppData\Local\assembly2013-06-09 03:34 . 2007-03-10 16:11 2680320 ----a-w- c:\windows\SysWow64\ImageEnXLibrary.ocx2013-06-09 03:34 . 2013-06-09 15:26 -------- d-----w- C:\FreeOCR2013-06-09 03:32 . 2013-06-09 03:32 -------- d-----w- c:\program files (x86)\Temp2013-06-05 10:01 . 2013-06-05 10:01 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll2013-06-05 01:20 . 2013-06-05 01:20 262552 ----a-w- c:\program files (x86)\Mozilla Firefox\updated\browser\components\browsercomps.dll2013-05-27 04:02 . 2013-05-27 04:02 -------- d-----w- c:\users\THMark\AppData\Roaming\SystemRequirementsLab2013-05-20 21:00 . 2013-05-20 21:00 -------- d-----w- c:\users\THMark\AppData\Roaming\Nitro PDF2013-05-17 18:21 . 2013-06-09 22:34 -------- d-----w- c:\programdata\boost_interprocess2013-05-15 22:59 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys2013-05-15 22:59 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys2013-05-15 22:59 . 2011-02-03 11:25 144384 ----a-w- c:\windows\system32\cdd.dll2013-05-15 22:59 . 2013-02-27 05:52 14172672 ----a-w- c:\windows\system32\shell32.dll2013-05-15 22:59 . 2013-02-27 05:52 197120 ----a-w- c:\windows\system32\shdocvw.dll2013-05-15 22:59 . 2013-02-27 05:48 1930752 ----a-w- c:\windows\system32\authui.dll2013-05-15 22:59 . 2013-02-27 06:02 111448 ----a-w- c:\windows\system32\consent.exe2013-05-15 22:59 . 2013-02-27 05:47 70144 ----a-w- c:\windows\system32\appinfo.dll2013-05-15 22:59 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\SysWow64\authui.dll2013-05-15 22:58 . 2013-04-10 03:30 3153920 ----a-w- c:\windows\system32\win32k.sys2013-05-15 22:58 . 2013-03-19 05:53 48640 ----a-w- c:\windows\system32\wwanprotdim.dll2013-05-15 22:58 . 2013-03-19 05:53 230400 ----a-w- c:\windows\system32\wwansvc.dll2013-05-14 20:31 . 2013-05-14 20:31 6128760 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll2013-05-14 20:31 . 2013-05-14 20:31 6128760 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2013-06-03 03:04 . 2011-03-29 01:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll2013-05-16 10:05 . 2011-07-27 18:49 75016696 ----a-w- c:\windows\system32\MRT.exe2013-05-14 19:07 . 2012-05-10 16:47 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe2013-05-14 19:07 . 2011-07-24 20:41 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl2013-05-02 09:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe2013-04-24 07:26 . 2012-07-06 16:47 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr2013-04-24 07:26 . 2012-06-10 18:50 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.exe2013-04-24 06:55 . 2012-06-10 18:50 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.ex02013-04-13 05:49 . 2013-05-15 22:59 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll2013-04-13 05:49 . 2013-05-15 22:59 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll2013-04-13 05:49 . 2013-05-15 22:59 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll2013-04-13 05:49 . 2013-05-15 22:59 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll2013-04-13 04:45 . 2013-05-15 22:59 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll2013-04-13 04:45 . 2013-05-15 22:59 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll2013-04-12 14:45 . 2013-04-24 14:50 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys2013-04-07 16:02 . 2012-06-10 18:50 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe2013-04-04 21:50 . 2011-07-24 20:02 25928 ----a-w- c:\windows\system32\drivers\mbam.sys2013-03-19 06:04 . 2013-04-10 06:26 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe2013-03-19 05:46 . 2013-04-10 06:26 43520 ----a-w- c:\windows\system32\csrsrv.dll2013-03-19 05:04 . 2013-04-10 06:26 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe2013-03-19 05:04 . 2013-04-10 06:26 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe2013-03-19 04:47 . 2013-04-10 06:26 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll2013-03-19 03:06 . 2013-04-10 06:26 112640 ----a-w- c:\windows\system32\smss.exe..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shownREGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-18 911160]"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-28 39408]"Steam"="c:\program files (x86)\Steam 2\Steam.exe" [2013-06-06 1641896]"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2013-01-08 3093624]"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-01-08 3674320].[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-08-22 593920]"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-06-25 1073352]"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 0 (0x0)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableLUA"= 0 (0x0)"EnableUIADesktopToggle"= 0 (0x0)"PromptOnSecureDesktop"= 0 (0x0).[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]"LoadAppInit_DLLs"=1 (0x1).[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]"DisableMonitoring"=dword:00000001.R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]R3 ALSysIO;ALSysIO;c:\users\THMark\AppData\Local\Temp\ALSysIO64.sys;c:\users\THMark\AppData\Local\Temp\ALSysIO64.sys [x]R3 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]R4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE [x]S0 SymDS;Symantec Data Store;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMDS64.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\SYMDS64.SYS [x]S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMEFA64.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\SYMEFA64.SYS [x]S1 BHDrvx64;BHDrvx64;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\BASHDefs\20130521.011\BHDrvx64.sys;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\BASHDefs\20130521.011\BHDrvx64.sys [x]S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]S1 IDSVia64;IDSVia64;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\IPSDefs\20130611.001\IDSvia64.sys;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\IPSDefs\20130611.001\IDSvia64.sys [x]S1 SymIRON;Symantec Iron Driver;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\Ironx64.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\Ironx64.SYS [x]S1 SYMNETS;Symantec Network Security WFP Driver;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\SYMNETS.SYS [x]S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe;c:\asus.sys\config\DVMExportService.exe [x]S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;e:\arrrghhh!!\HiPatchService.exe;e:\arrrghhh!!\HiPatchService.exe [x]S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]S2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [x]S2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE [x]S2 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe;c:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [x]S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]S2 SepMasterService;Symantec Endpoint Protection;c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe;c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe [x]S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]..--- Other Services/Drivers In Memory ---.*NewlyCreated* - 59322389*Deregistered* - 59322389.Contents of the 'Scheduled Tasks' folder.2013-06-12 c:\windows\Tasks\Adobe Flash Player Updater.job- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 19:07].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 21:50].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 21:50].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000Core.job- c:\users\THMark\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 14:42].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000UA.job- c:\users\THMark\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 14:42]..--------- X64 Entries -----------..[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 825184]"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-01-24 477600].------- Supplementary Scan -------.uLocal Page = c:\windows\system32\blank.htmuStart Page = hxxp://www.google.com/mLocal Page = c:\windows\SysWOW64\blank.htmuInternet Settings,ProxyOverride = *.localIE: Download all by FlashGet3 - c:\users\THMark\AppData\Roaming\FlashGetBHO\GetAllUrl.htmIE: Download by FlashGet3 - c:\users\THMark\AppData\Roaming\FlashGetBHO\GetUrl.htmIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.htmlIE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105Trusted Zone: clonewarsadventures.comTrusted Zone: freerealms.comTrusted Zone: soe.comTrusted Zone: sony.comTCP: DhcpNameServer = 192.168.0.1FF - ProfilePath - c:\users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)FF - prefs.js: browser.startup.homepage - google.comFF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113933&tt=120812_bandext_3212_1FF - user.js: extensions.BabylonToolbar_i.babExt -FF - user.js: extensions.BabylonToolbar_i.srcExt - ssFF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://www.google.com/search?babsrc=TB_ggl&q=FF - user.js: extensions.BabylonToolbar.id - 1e666e7c00000000000002004c4f4f50FF - user.js: extensions.BabylonToolbar.instlDay - 15564FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.4.6FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.4.6FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.4.615:48FF - user.js: extensions.BabylonToolbar.prtnrId - babylonFF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbarFF - user.js: extensions.BabylonToolbar.aflt - babsstFF - user.js: extensions.BabylonToolbar_i.smplGrp - noneFF - user.js: extensions.BabylonToolbar.tlbrId - baseFF - user.js: extensions.BabylonToolbar.instlRef - sstFF - user.js: extensions.BabylonToolbar.dfltLng - enFF - user.js: extensions.BabylonToolbar.excTlbr - falseFF - user.js: extensions.BabylonToolbar.admin - false.- - - - ORPHANS REMOVED - - - -.Wow6432Node-HKCU-Run-AdobeBridge - (no file)Wow6432Node-HKCU-Run-FoodBuzzUpdate - c:\program files (x86)\FoodBuzz\Update\FoodBuzzUpdate.exeNotify-SEP - c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\WinLogoutNotifier.dllSafeBoot-59322389.sysHKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - startWebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exeAddRemove-black-ops_folder - c:\program files (x86)\windows-7-themes.com\black-ops\uninstall.exeAddRemove-FIFA 12 © EA_is1 - e:\fifa\game\FIFA 12\unins000.exeAddRemove-Galactic Magnate_is1 - e:\new folder\Galactic Magnate\uninst\unins000.exeAddRemove-Homefront_is1 - e:\hf\Homefront\Homefront\unins000.exeAddRemove-MahjongWorldClient - c:\program files (x86)\MahjongWorldClient\uninstall.exeAddRemove-Saints Row. The Third_is1 - e:\saints\Saints Row. The Third\uninstall\unins000.exeAddRemove-{6D87CAD9-9B94-4421-A439-B25F8DE14575} - c:\program files (x86)\InstallShield Installation Information\{6D87CAD9-9B94-4421-A439-B25F8DE14575}\setup.exeAddRemove-GameMaker81 - l:\game maker 8.1 lite\GameMaker 8.1\uninstall.exeAddRemove-lotro_highres_en - e:\happycloud\Cache\The Lord of the Rings Online\hcuninstaller.exeAddRemove-SOE-Pirates of the Burning Sea - e:\potbs\Uninstaller.exe...[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SepMasterService]"ImagePath"="\"c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe\" /s \"Symantec Endpoint Protection\" /m \"c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\sms.dll\" /prefetch:1"--.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SmcService]"ImagePath"="\"c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin64\Smc.exe\" /prefetch:1".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]"ImagePath"="c:\windows\system32\GameMon.des -service".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011".--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\e:\Battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]"qgif4.dll"=multi:"2011-10-10T16:42\00gif\00\00""qico4.dll"=multi:"2011-10-10T16:42\00ico\00\00""qjpeg4.dll"=multi:"2011-10-10T16:42\00jpeg\00jpg\00\00".[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:\e:\Battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]"qcncodecs4.dll"=multi:"2011-10-10T16:42\00GB18030\00GBK\00GB2312\00CP936\00MS936\00windows-936\00MIB: 114\00MIB: 113\00MIB: 2025\00\00""qkrcodecs4.dll"=multi:"2011-10-10T16:42\00EUC-KR\00cp949\00MIB: 38\00MIB: -949\00\00""qtwcodecs4.dll"=multi:"2011-10-10T16:42\00Big5\00Big5-HKSCS\00Big5-ETen\00CP950\00MIB: 2026\00MIB: 2101\00\00".[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\e:\battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]"qcncodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qjpcodecs4.dll"=multi:"40602\000\00Windows msvc release full-config\002011-10-10T16:42\00\00""qjpcodecsd4.dll"=multi:"40703\001\00Windows msvc debug full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qkrcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qtwcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00".[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\e:\battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]"Microsoft.VC80.CRT.manifest"=multi:"0\001\00unknown\002011-10-10T16:42\00\00""msvcr80.dll"=multi:"0\001\00unknown\002011-10-10T16:42\00\00""qgif4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qico4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qjpeg4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00".[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="IFlashBroker5".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]@="ShockwaveFlash.ShockwaveFlash.11".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="IFlashBroker5".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\CurrentVersion]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]@Denied: (Full) (Everyone).Completion time: 2013-06-11 22:59:39ComboFix-quarantined-files.txt 2013-06-12 05:59.Pre-Run: 35,085,447,168 bytes freePost-Run: 38,239,043,584 bytes free.- - End Of File - - 6EDA89A74C0FAAF11B8E7AED47054769A36C5E4F47E84449FF07ED3517B43A31 Results of screen317's Security Check version 0.99.64 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! Symantec Endpoint Protection WMI entry may not exist for antivirus; attempting automatic update.`````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware version 1.75.0.1300 Java 6 Update 39 Java version out of Date! Adobe Flash Player 11.7.700.202 Adobe Reader 10.1.7 Adobe Reader out of Date! Mozilla Firefox 20.0.1 Firefox out of Date! ````````Process Check: objlist.exe by Laurent```````` Norton ccSvcHst.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 1%````````````````````End of Log``````````````````````Thanks again. Link to post Share on other sites More sharing options...
D-FRED-BROWN Posted June 12, 2013 ID:690126 Share Posted June 12, 2013 Please do the following:1. Close any open browsers.2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.3. Open notepad and copy/paste the text in the quotebox below into it:KILLALL::File::C:\Windows\System32\Drivers\59322389.sysDriver::Reboot::Save this as CFScript.txt, in the same location as ComboFix.exeRefering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I shall require in your next reply.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Please include the newly-created C:\ComboFix.txt in your next reply, and let me know how things are running now Link to post Share on other sites More sharing options...
dnahunter Posted June 12, 2013 Author ID:690138 Share Posted June 12, 2013 ComboFix 13-06-08.02 - THMark 06/12/2013 0:00.2.6 - x64Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8191.5583 [GMT -7:00]Running from: c:\users\THMark\Desktop\ComboFix.exeCommand switches used :: c:\users\THMark\Desktop\CFScript.txtAV: Symantec Endpoint Protection *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}FW: Symantec Endpoint Protection *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}SP: Symantec Endpoint Protection *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point.FILE ::"c:\windows\System32\Drivers\59322389.sys"..((((((((((((((((((((((((( Files Created from 2013-05-12 to 2013-06-12 )))))))))))))))))))))))))))))))..2013-06-12 07:03 . 2013-06-12 07:03 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp2013-06-12 07:03 . 2013-06-12 07:03 -------- d-----w- c:\users\hedev\AppData\Local\temp2013-06-12 07:03 . 2013-06-12 07:03 -------- d-----w- c:\users\Default\AppData\Local\temp2013-06-12 04:42 . 2013-06-12 05:30 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)2013-06-12 04:32 . 2013-06-12 04:32 -------- d-----w- C:\TDSSKiller_Quarantine2013-06-11 16:31 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BE81F950-7FAF-4341-A8D7-685562AEAE08}\mpengine.dll2013-06-10 03:43 . 2013-06-10 21:06 -------- d-----w- c:\users\THMark\AppData\Local\Warframe2013-06-09 03:39 . 2013-06-09 03:39 -------- d-----w- c:\users\THMark\AppData\Local\FreeOCR2013-06-09 03:35 . 2013-06-12 05:41 -------- d-----w- c:\users\THMark\AppData\Local\assembly2013-06-09 03:34 . 2007-03-10 16:11 2680320 ----a-w- c:\windows\SysWow64\ImageEnXLibrary.ocx2013-06-09 03:34 . 2013-06-09 15:26 -------- d-----w- C:\FreeOCR2013-06-09 03:32 . 2013-06-09 03:32 -------- d-----w- c:\program files (x86)\Temp2013-06-05 10:01 . 2013-06-05 10:01 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll2013-06-05 01:20 . 2013-06-05 01:20 262552 ----a-w- c:\program files (x86)\Mozilla Firefox\updated\browser\components\browsercomps.dll2013-05-27 04:02 . 2013-05-27 04:02 -------- d-----w- c:\users\THMark\AppData\Roaming\SystemRequirementsLab2013-05-20 21:00 . 2013-05-20 21:00 -------- d-----w- c:\users\THMark\AppData\Roaming\Nitro PDF2013-05-17 18:21 . 2013-06-09 22:34 -------- d-----w- c:\programdata\boost_interprocess2013-05-15 22:59 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys2013-05-15 22:59 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys2013-05-15 22:59 . 2011-02-03 11:25 144384 ----a-w- c:\windows\system32\cdd.dll2013-05-15 22:59 . 2013-02-27 05:52 14172672 ----a-w- c:\windows\system32\shell32.dll2013-05-15 22:59 . 2013-02-27 05:52 197120 ----a-w- c:\windows\system32\shdocvw.dll2013-05-15 22:59 . 2013-02-27 05:48 1930752 ----a-w- c:\windows\system32\authui.dll2013-05-15 22:59 . 2013-02-27 06:02 111448 ----a-w- c:\windows\system32\consent.exe2013-05-15 22:59 . 2013-02-27 05:47 70144 ----a-w- c:\windows\system32\appinfo.dll2013-05-15 22:59 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\SysWow64\authui.dll2013-05-15 22:58 . 2013-04-10 03:30 3153920 ----a-w- c:\windows\system32\win32k.sys2013-05-15 22:58 . 2013-03-19 05:53 48640 ----a-w- c:\windows\system32\wwanprotdim.dll2013-05-15 22:58 . 2013-03-19 05:53 230400 ----a-w- c:\windows\system32\wwansvc.dll2013-05-14 20:31 . 2013-05-14 20:31 6128760 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll2013-05-14 20:31 . 2013-05-14 20:31 6128760 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2013-06-03 03:04 . 2011-03-29 01:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll2013-05-16 10:05 . 2011-07-27 18:49 75016696 ----a-w- c:\windows\system32\MRT.exe2013-05-14 19:07 . 2012-05-10 16:47 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe2013-05-14 19:07 . 2011-07-24 20:41 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl2013-05-02 09:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe2013-04-24 07:26 . 2012-07-06 16:47 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr2013-04-24 07:26 . 2012-06-10 18:50 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.exe2013-04-24 06:55 . 2012-06-10 18:50 281120 ----a-w- c:\windows\SysWow64\PnkBstrB.ex02013-04-13 05:49 . 2013-05-15 22:59 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll2013-04-13 05:49 . 2013-05-15 22:59 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll2013-04-13 05:49 . 2013-05-15 22:59 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll2013-04-13 05:49 . 2013-05-15 22:59 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll2013-04-13 04:45 . 2013-05-15 22:59 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll2013-04-13 04:45 . 2013-05-15 22:59 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll2013-04-12 14:45 . 2013-04-24 14:50 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys2013-04-07 16:02 . 2012-06-10 18:50 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe2013-04-04 21:50 . 2011-07-24 20:02 25928 ----a-w- c:\windows\system32\drivers\mbam.sys2013-03-19 06:04 . 2013-04-10 06:26 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe2013-03-19 05:46 . 2013-04-10 06:26 43520 ----a-w- c:\windows\system32\csrsrv.dll2013-03-19 05:04 . 2013-04-10 06:26 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe2013-03-19 05:04 . 2013-04-10 06:26 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe2013-03-19 04:47 . 2013-04-10 06:26 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll2013-03-19 03:06 . 2013-04-10 06:26 112640 ----a-w- c:\windows\system32\smss.exe..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shownREGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-18 911160]"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-28 39408]"Steam"="c:\program files (x86)\Steam 2\Steam.exe" [2013-06-06 1641896]"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2013-01-08 3093624]"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-01-08 3674320].[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-08-22 593920]"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-06-25 1073352]"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 0 (0x0)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableLUA"= 0 (0x0)"EnableUIADesktopToggle"= 0 (0x0)"PromptOnSecureDesktop"= 0 (0x0).[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]"LoadAppInit_DLLs"=1 (0x1).[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]"DisableMonitoring"=dword:00000001.R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]R3 ALSysIO;ALSysIO;c:\users\THMark\AppData\Local\Temp\ALSysIO64.sys;c:\users\THMark\AppData\Local\Temp\ALSysIO64.sys [x]R3 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]R4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE [x]S0 SymDS;Symantec Data Store;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMDS64.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\SYMDS64.SYS [x]S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMEFA64.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\SYMEFA64.SYS [x]S1 BHDrvx64;BHDrvx64;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\BASHDefs\20130521.011\BHDrvx64.sys;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\BASHDefs\20130521.011\BHDrvx64.sys [x]S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]S1 IDSVia64;IDSVia64;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\IPSDefs\20130611.001\IDSvia64.sys;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\IPSDefs\20130611.001\IDSvia64.sys [x]S1 SymIRON;Symantec Iron Driver;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\Ironx64.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\Ironx64.SYS [x]S1 SYMNETS;Symantec Network Security WFP Driver;c:\windows\system32\Drivers\SEP\0C0103E8\009D.105\x64\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\SEP\0C0103E8\009D.105\x64\SYMNETS.SYS [x]S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe;c:\asus.sys\config\DVMExportService.exe [x]S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;e:\arrrghhh!!\HiPatchService.exe;e:\arrrghhh!!\HiPatchService.exe [x]S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]S2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe;c:\program files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [x]S2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE [x]S2 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe;c:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [x]S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]S2 SepMasterService;Symantec Endpoint Protection;c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe;c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe [x]S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]..--- Other Services/Drivers In Memory ---.*NewlyCreated* - WS2IFSL.Contents of the 'Scheduled Tasks' folder.2013-06-12 c:\windows\Tasks\Adobe Flash Player Updater.job- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 19:07].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 21:50].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-28 21:50].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000Core.job- c:\users\THMark\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 14:42].2013-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000UA.job- c:\users\THMark\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 14:42]..--------- X64 Entries -----------..[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 825184]"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-01-24 477600].------- Supplementary Scan -------.uLocal Page = c:\windows\system32\blank.htmuStart Page = hxxp://www.google.com/mLocal Page = c:\windows\SysWOW64\blank.htmuInternet Settings,ProxyOverride = *.localIE: Download all by FlashGet3 - c:\users\THMark\AppData\Roaming\FlashGetBHO\GetAllUrl.htmIE: Download by FlashGet3 - c:\users\THMark\AppData\Roaming\FlashGetBHO\GetUrl.htmIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.htmlIE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105Trusted Zone: clonewarsadventures.comTrusted Zone: freerealms.comTrusted Zone: soe.comTrusted Zone: sony.comTCP: DhcpNameServer = 192.168.0.1FF - ProfilePath - c:\users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)FF - prefs.js: browser.startup.homepage - google.comFF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113933&tt=120812_bandext_3212_1FF - user.js: extensions.BabylonToolbar_i.babExt -FF - user.js: extensions.BabylonToolbar_i.srcExt - ssFF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://www.google.com/search?babsrc=TB_ggl&q=FF - user.js: extensions.BabylonToolbar.id - 1e666e7c00000000000002004c4f4f50FF - user.js: extensions.BabylonToolbar.instlDay - 15564FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.4.6FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.4.6FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.4.615:48FF - user.js: extensions.BabylonToolbar.prtnrId - babylonFF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbarFF - user.js: extensions.BabylonToolbar.aflt - babsstFF - user.js: extensions.BabylonToolbar_i.smplGrp - noneFF - user.js: extensions.BabylonToolbar.tlbrId - baseFF - user.js: extensions.BabylonToolbar.instlRef - sstFF - user.js: extensions.BabylonToolbar.dfltLng - enFF - user.js: extensions.BabylonToolbar.excTlbr - falseFF - user.js: extensions.BabylonToolbar.admin - false.- - - - ORPHANS REMOVED - - - -.Notify-SEP - c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\WinLogoutNotifier.dllWebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exeAddRemove-black-ops_folder - c:\program files (x86)\windows-7-themes.com\black-ops\uninstall.exeAddRemove-FIFA 12 © EA_is1 - e:\fifa\game\FIFA 12\unins000.exeAddRemove-Galactic Magnate_is1 - e:\new folder\Galactic Magnate\uninst\unins000.exeAddRemove-Homefront_is1 - e:\hf\Homefront\Homefront\unins000.exeAddRemove-MahjongWorldClient - c:\program files (x86)\MahjongWorldClient\uninstall.exeAddRemove-Saints Row. The Third_is1 - e:\saints\Saints Row. The Third\uninstall\unins000.exeAddRemove-{6D87CAD9-9B94-4421-A439-B25F8DE14575} - c:\program files (x86)\InstallShield Installation Information\{6D87CAD9-9B94-4421-A439-B25F8DE14575}\setup.exe...[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SepMasterService]"ImagePath"="\"c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe\" /s \"Symantec Endpoint Protection\" /m \"c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\sms.dll\" /prefetch:1"--.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SmcService]"ImagePath"="\"c:\program files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin64\Smc.exe\" /prefetch:1".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]"ImagePath"="c:\windows\system32\GameMon.des -service".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011".--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\e:\Battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]"qgif4.dll"=multi:"2011-10-10T16:42\00gif\00\00""qico4.dll"=multi:"2011-10-10T16:42\00ico\00\00""qjpeg4.dll"=multi:"2011-10-10T16:42\00jpeg\00jpg\00\00".[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.7\com.trolltech.Qt.QTextCodecFactoryInterface:\e:\Battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]"qcncodecs4.dll"=multi:"2011-10-10T16:42\00GB18030\00GBK\00GB2312\00CP936\00MS936\00windows-936\00MIB: 114\00MIB: 113\00MIB: 2025\00\00""qkrcodecs4.dll"=multi:"2011-10-10T16:42\00EUC-KR\00cp949\00MIB: 38\00MIB: -949\00\00""qtwcodecs4.dll"=multi:"2011-10-10T16:42\00Big5\00Big5-HKSCS\00Big5-ETen\00CP950\00MIB: 2026\00MIB: 2101\00\00".[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\e:\battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\codecs]"qcncodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qjpcodecs4.dll"=multi:"40602\000\00Windows msvc release full-config\002011-10-10T16:42\00\00""qjpcodecsd4.dll"=multi:"40703\001\00Windows msvc debug full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qkrcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qtwcodecs4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00".[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.7.false\e:\battlefield 3\Bzmd\B*a*t*t*l*e*f*i*e*l*d* *3*"!\Core\imageformats]"Microsoft.VC80.CRT.manifest"=multi:"0\001\00unknown\002011-10-10T16:42\00\00""msvcr80.dll"=multi:"0\001\00unknown\002011-10-10T16:42\00\00""qgif4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qico4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00""qjpeg4.dll"=multi:"40703\000\00Windows msvc release full-config QT_NO_DRAGANDDROP\002011-10-10T16:42\00\00".[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="IFlashBroker5".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]@="ShockwaveFlash.ShockwaveFlash.11".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]@Denied: (A 2) (Everyone)@="IFlashBroker5".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\CurrentVersion]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]@Denied: (Full) (Everyone).------------------------ Other Running Processes ------------------------.c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exec:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exec:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXEc:\windows\SysWOW64\PnkBstrA.exec:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe.**************************************************************************.Completion time: 2013-06-12 00:28:13 - machine was rebootedComboFix-quarantined-files.txt 2013-06-12 07:28ComboFix2.txt 2013-06-12 05:59.Pre-Run: 38,313,099,264 bytes freePost-Run: 38,236,438,528 bytes free.- - End Of File - - 3BE556C1D5AE6463684D9A2243987461A36C5E4F47E84449FF07ED3517B43A31 Link to post Share on other sites More sharing options...
D-FRED-BROWN Posted June 12, 2013 ID:690202 Share Posted June 12, 2013 Looks a whole lot better. Please run the following scans to verify we haven't missed anything:----------Step 1----------------Please download AdwCleaner by Xplode onto your desktop.Double click on AdwCleaner.exe to run the tool.Click on Search.A logfile will automatically open after the scan has finished.Please post the contents of that logfile with your next reply.You can find the logfile at C:\AdwCleaner[R1].txt as well.----------Step 2----------------We need to create a New FULL OTL ReportPlease download OTL from here if you have not done so already:Main Mirror[*]Save it to your desktop.[*]Double click on the OTL icon on your desktop.[*]Click the "Scan All Users" checkbox.[*]Change the "Extra Registry" option to "SafeList"[*]Push the Run Scan button.[*]Two reports will open, copy and paste them in a reply here:OTL.txt <-- Will be openedExtra.txt <-- Will be minimized----------Step 3 (note: this scan may take a little time)----------------I'd like us to scan your machine with ESET OnlineScanHold down Control and click on the following link to open ESET OnlineScan in a new window.ESET OnlineScanClick the button.For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on to download the ESET Smart Installer. Save it to your desktop.Double click on the icon on your desktop.[*]Check [*]Click the button.[*]Accept any security warnings from your browser.[*]Check [*]Push the Start button.[*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.[*]When the scan completes, push [*]Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.[*]Push the button.[*]Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt----------Step 4----------------Please post the AdwCleaner logfile, the OTL.txt and Extras.txt, and the ESET online scan log in your next reply.Let me know how things go. Link to post Share on other sites More sharing options...
dnahunter Posted June 12, 2013 Author ID:690299 Share Posted June 12, 2013 # AdwCleaner v2.303 - Logfile created 06/12/2013 at 08:37:57# Updated 08/06/2013 by Xplode# Operating system : Windows 7 Professional Service Pack 1 (64 bits)# User : THMark - THMARK-PC# Boot Mode : Normal# Running from : C:\Users\THMark\Desktop\AdwCleaner.exe# Option [search]***** [services] *****Found : DvmMDES***** [Files / Folders] *****File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xmlFile Found : C:\user.jsFile Found : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\BrowserMngr_extensions.sqliteFile Found : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\browsermngr_prefs.jsFile Found : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\searchplugins\BabylonMngr.xmlFile Found : C:\Windows\SysWOW64\conduitEngine.tmpFolder Found : C:\Program Files (x86)\1ClickDownloadFolder Found : C:\ProgramData\BabylonFolder Found : C:\ProgramData\boost_interprocessFolder Found : C:\ProgramData\WeCareReminderFolder Found : C:\Users\THMark\AppData\Local\ConduitFolder Found : C:\Users\THMark\AppData\LocalLow\BabylonToolbarFolder Found : C:\Users\THMark\AppData\LocalLow\ConduitFolder Found : C:\Users\THMark\AppData\LocalLow\PriceGongFolder Found : C:\Users\THMark\AppData\Roaming\BabylonFolder Found : C:\Users\THMark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser ManagerFolder Found : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\extensions\wecarereminder@bryanFolder Found : C:\Users\THMark\AppData\Roaming\OpenCandy***** [Registry] *****Key Found : HKCU\Software\1ClickDownloadKey Found : HKCU\Software\AppDataLow\Software\PriceGongKey Found : HKCU\Software\DataMngr_ToolbarKey Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Found : HKCU\Software\wecarereminderKey Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}Key Found : HKLM\Software\BabylonKey Found : HKLM\Software\BrowserMngrKey Found : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}Key Found : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLLKey Found : HKLM\SOFTWARE\Classes\Conduit.EngineKey Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminderKey Found : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1Key Found : HKLM\SOFTWARE\Classes\Prod.capKey Found : HKLM\SOFTWARE\Classes\Toolbar.CT2790392Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}Key Found : HKLM\Software\ConduitKey Found : HKLM\Software\DataMngrKey Found : HKLM\Software\DeviceVMKey Found : HKLM\Software\Freeze.comKey Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCSKey Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99AD9D6D-A456-49EE-8360-F22EE7AA1272}Key Found : HKLM\SOFTWARE\Classes\Interface\{1C888195-0160-4883-91B7-294C0CE2F277}Key Found : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}Key Found : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}Key Found : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}Key Found : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}Key Found : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}Key Found : HKLM\SOFTWARE\Classes\Interface\{99ACA0F7-D864-45CB-8C40-FD42A077E7CA}Key Found : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}Key Found : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}Key Found : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}Key Found : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}Key Found : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}Key Found : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}Key Found : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}Key Found : HKLM\SOFTWARE\Classes\Interface\{E65F40C8-3CEB-47C2-9E01-BF73323DF4E7}Key Found : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}Key Found : HKLM\SOFTWARE\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}Key Found : HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}Key Found : HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [browserMngr Start Page]Value Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [browserMngrDefaultScope]***** [internet Browsers] *****-\\ Internet Explorer v10.0.9200.16576[HKCU\Software\Microsoft\Internet Explorer\Main - BrowserMngr Start Page] = hxxp://search.babylon.com/?affID=113933&tt=120812_bandext_3212_1&babsrc=HP_ss&mntrId=1e666e7c00000000000002004c4f4f50[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=113933&tt=120812_bandext_3212_1&babsrc=NT_ss&mntrId=1e666e7c00000000000002004c4f4f50-\\ Mozilla Firefox v20.0.1 (en-US)File : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\prefs.jsFound : user_pref("browser.search.defaultenginename", "Search the web (Babylon)");Found : user_pref("browser.search.order.1", "Search the web (Babylon)");Found : user_pref("browser.search.selectedEngine", "Search the web (Babylon)");Found : user_pref("extensions.BabylonToolbar.admin", false);Found : user_pref("extensions.BabylonToolbar.aflt", "babsst");Found : user_pref("extensions.BabylonToolbar.dfltLng", "en");Found : user_pref("extensions.BabylonToolbar.excTlbr", false);Found : user_pref("extensions.BabylonToolbar.id", "1e666e7c00000000000002004c4f4f50");Found : user_pref("extensions.BabylonToolbar.instlDay", "15564");Found : user_pref("extensions.BabylonToolbar.instlRef", "sst");Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");Found : user_pref("extensions.BabylonToolbar.tlbrId", "base");Found : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://www.google.com/search?babsrc=TB_ggl&q=");Found : user_pref("extensions.BabylonToolbar.vrsn", "1.6.4.6");Found : user_pref("extensions.BabylonToolbar.vrsni", "1.6.4.6");Found : user_pref("extensions.BabylonToolbar_i.babExt", "");Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=113933&tt=120812_bandext_3212_1");Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.4.615:48:43");-\\ Google Chrome v [unable to get version]File : C:\Users\THMark\AppData\Local\Google\Chrome\User Data\Default\Preferences[OK] File is clean.*************************AdwCleaner[R1].txt - [8834 octets] - [12/06/2013 08:37:57]########## EOF - C:\AdwCleaner[R1].txt - [8894 octets] ##########OTL Extras logfile created on: 6/12/2013 9:17:53 AM - Run 1OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\THMark\Desktop64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstationInternet Explorer (Version = 9.10.9200.16576)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy8.00 Gb Total Physical Memory | 5.32 Gb Available Physical Memory | 66.46% Memory free16.00 Gb Paging File | 12.58 Gb Available in Paging File | 78.66% Paging File freePaging file location(s): ?:\pagefile.sys [binary data]%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)Drive C: | 131.41 Gb Total Space | 35.40 Gb Free Space | 26.94% Space Free | Partition Type: NTFSDrive D: | 50.00 Gb Total Space | 8.67 Gb Free Space | 17.34% Space Free | Partition Type: NTFSDrive E: | 200.00 Gb Total Space | 48.69 Gb Free Space | 24.35% Space Free | Partition Type: NTFSDrive G: | 150.00 Gb Total Space | 76.51 Gb Free Space | 51.01% Space Free | Partition Type: NTFSDrive H: | 100.00 Gb Total Space | 24.04 Gb Free Space | 24.04% Space Free | Partition Type: NTFSDrive J: | 2.42 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFSDrive Z: | 600.00 Gb Total Space | 254.09 Gb Free Space | 42.35% Space Free | Partition Type: NTFSComputer Name: THMARK-PC | User Name: THMark | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All users | Include 64bit ScansCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days========== Extra Registry (SafeList) ==================== File Associations ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation).url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>].cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation).html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)========== Shell Spawning ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*exefile [open] -- "%1" %*helpfile [open] -- Reg Error: Key error.htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)InternetShortcut [open] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()Directory [bridge] -- G:\New folder\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [explore] -- Reg Error: Value error.Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]batfile [open] -- "%1" %*cmdfile [open] -- "%1" %*comfile [open] -- "%1" %*cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)exefile [open] -- "%1" %*helpfile [open] -- Reg Error: Key error.htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)piffile [open] -- "%1" %*regfile [merge] -- Reg Error: Key error.scrfile [config] -- "%1"scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %lscrfile [open] -- "%1" /Stxtfile [edit] -- Reg Error: Key error.Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()Directory [bridge] -- G:\New folder\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Folder [explore] -- Reg Error: Value error.Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.========== Security Center Settings ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]"cval" = 1"FirewallDisableNotify" = 0"AntiVirusDisableNotify" = 0"UpdatesDisableNotify" = 064bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]"AntiVirusOverride" = 0"AntiSpywareOverride" = 0"FirewallOverride" = 064bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]"DisableMonitoring" = 1[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]========== System Restore Settings ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]"DisableSR" = 0========== Firewall Settings ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile][HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall][HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile][HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]"EnableFirewall" = 1"DisableNotifications" = 0[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]"EnableFirewall" = 1"DisableNotifications" = 0[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]"EnableFirewall" = 1"DisableNotifications" = 0========== Authorized Applications List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 -- (Trend Media Corporation Limited)"E:\IRC\xchat\xchat.exe" = E:\IRC\xchat\xchat.exe:*:Enabled:XChat IRC Client -- ()"E:\Combat Arms\CombatArms.exe" = E:\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"E:\Combat Arms\Engine.exe" = E:\Combat Arms\Engine.exe:*Enabled:Engine.exe"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 -- (Trend Media Corporation Limited)"E:\IRC\xchat\xchat.exe" = E:\IRC\xchat\xchat.exe:*:Enabled:XChat IRC Client -- ()"E:\Combat Arms\CombatArms.exe" = E:\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"E:\Combat Arms\Engine.exe" = E:\Combat Arms\Engine.exe:*Enabled:Engine.exe========== Vista Active Open Ports Exception List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]"{0001EE7E-A843-4B23-95BC-01D4691ED56F}" = lport=57776 | protocol=6 | dir=in | name=pando media booster |"{07F7D7ED-3DC1-410F-9695-99BFB4006CB4}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |"{0C2CD46A-DE4A-41E7-B861-11C4997167C8}" = lport=57776 | protocol=17 | dir=in | name=pando media booster |"{2076441E-6A89-4201-9126-0652411E3CD6}" = lport=58807 | protocol=17 | dir=in | name=pando media booster |"{30E0E368-4159-4755-BC0D-0816EA963735}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |"{331B520B-5425-4C19-A686-8720DE80B84C}" = lport=58807 | protocol=6 | dir=in | name=pando media booster |"{338A2290-9743-4F1C-BB35-4BA54BFBC791}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |"{3F436648-FB64-4CAC-8CBC-3DAF2481D2E3}" = lport=57974 | protocol=17 | dir=in | name=pando media booster |"{41C5A651-E0A5-4CEA-AA8F-6DDB7443F870}" = lport=58807 | protocol=17 | dir=in | name=pando media booster |"{4416F45F-43CE-480D-A9F9-AE08119F1E14}" = lport=57974 | protocol=17 | dir=in | name=pando media booster |"{4F8F3BDC-E285-4663-A9AB-B34465B45028}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |"{7E5932AB-5FE7-4504-A4F0-3182318E6BF6}" = rport=80 | protocol=6 | dir=out | app=e:\steamlibrary\steamapps\common\warframe\warframe.exe |"{7F18390A-DBA1-4141-9955-86341D93E3AB}" = lport=58807 | protocol=6 | dir=in | name=pando media booster |"{82F0CCCD-6145-48EB-9DBA-4B92CF76A272}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |"{9F4E72A8-C780-45A0-B89C-C7E8FCD9B411}" = lport=57776 | protocol=17 | dir=in | name=pando media booster |"{AB25C60B-6BAC-4D62-8122-0A9A3114323E}" = rport=80 | protocol=6 | dir=out | app=e:\steamlibrary\steamapps\common\warframe\warframe.x64.exe |"{CA2A3451-A58D-4EB3-A2A3-170C79D0C195}" = lport=57776 | protocol=6 | dir=in | name=pando media booster |"{CB27BA4E-786A-4BE4-9ECD-3EDA920DD89E}" = lport=57974 | protocol=6 | dir=in | name=pando media booster |"{E196F987-92F4-471A-A2A3-2427C4BEED54}" = lport=57974 | protocol=6 | dir=in | name=pando media booster |"{E389977F-EE95-4C27-B76D-8630444736C9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |"{EF4EDBEE-83E6-498A-A1C5-8D4266FCC7FC}" = rport=80 | protocol=6 | dir=out | app=e:\steamlibrary\steamapps\common\warframe\tools\launcher.exe |========== Vista Active Application Exception List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]"{0174BA0C-2C18-4251-8A23-9F350CFE28EE}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |"{088B98C1-024B-4D1B-822F-0A22CE89B460}" = protocol=6 | dir=in | app=e:\nfs hp\game\launcher.exe |"{0980B9FA-6C10-4B89-A1DC-138D831E6505}" = protocol=6 | dir=in | app=e:\swor\star wars-the old republic\launcher.exe |"{0C9E6DF8-F0DC-4628-84E2-5C21AAB85336}" = protocol=6 | dir=in | app=e:\happycloud\cache\the lord of the rings online\turbinelauncher.exe |"{0CF5F15A-FBD6-45FF-B9CB-94D2A439FBAE}" = protocol=17 | dir=in | app=e:\happycloud\cache\the lord of the rings online\turbinelauncher.exe |"{133AF6DD-08E4-4868-ABF4-EF20B2C3109A}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |"{13EED2DC-AE65-4491-A24B-0EB735BFDA48}" = protocol=17 | dir=in | app=e:\nba 2k13\nba2k13.exe |"{15C2B1B0-3002-4791-9028-81C46C09C03E}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.1000.157.105\bin64\snac64.exe |"{17F0BD5A-3D9B-4D7C-8709-9072D4E0C75E}" = protocol=6 | dir=in | app=e:\swor\star wars-the old republic\launcher.exe |"{19CBBBBE-F7B1-4166-B9DC-2383385DFB4D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |"{1BD577B2-CC03-41DA-B85C-C01094C6E35C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |"{1C3CD5B4-828E-4444-BA6E-F8A950FC5789}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |"{1CEAEB49-A72B-4FC8-9542-402EE969AAED}" = protocol=6 | dir=in | app=e:\happycloud\cache\the lord of the rings online\lotroclient.exe |"{1E4868F2-54E2-4528-9988-37AF2A4AEB1D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |"{21E27DA2-B6CD-429F-AD9A-D7D18A36EB89}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |"{220017C3-E95D-40D9-B009-4F73BCDBE51F}" = protocol=6 | dir=in | app=e:\lotr game\game.dat |"{2BD54203-93E4-46DA-9E8D-C487E46DAA88}" = protocol=17 | dir=in | app=c:\users\thmark\appdata\local\google\google talk plugin\googletalkplugin.exe |"{2FF73577-A236-4CF6-A31A-7754268D837D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |"{30AAA877-2388-489A-82E1-2DA7300FB6C0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space pirates and zombies\spazgame.exe |"{3248C6A0-E2A2-4BA5-BF33-E9B71F301877}" = protocol=17 | dir=in | app=e:\mlb\mlb2k12.exe |"{353A9748-A67E-4D0D-AFB3-05DCB2CC615E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\payday the heist\payday_win32_release.exe |"{371F3BCB-8D52-40A6-BAA7-A03723609E2B}" = protocol=17 | dir=in | app=c:\users\thmark\desktop\ts 3-take 2\teamspeak3-server_win64\ts3server_win64.exe |"{37B2707E-DA21-4978-91A9-2111FB22161E}" = protocol=17 | dir=in | app=e:\2k12\nba 2k12\game\nba2k12.exe |"{38654C2C-7813-49D7-95FC-FA669E4897E2}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |"{3894944F-17BB-460B-91C4-4CA30A6D52EF}" = protocol=17 | dir=out | app=e:\steamlibrary\steamapps\common\warframe\warframe.exe |"{38BC11BD-2396-473A-86C5-3BAB19CB1D71}" = protocol=17 | dir=in | app=e:\nfs hp\game\launcher.exe |"{3BC6D6F3-30C0-4E82-870A-3027EC7A623E}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.601.4699.105\bin64\smc.exe |"{3C66CB5F-232A-48CD-8C84-A16F8832AC82}" = protocol=17 | dir=in | app=e:\swor\star wars-the old republic\launcher.exe |"{3C8068EF-6998-4987-B9E8-2A98E5BCAA44}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |"{3DBA86F8-C444-411D-8587-9AFB2CCEFBB5}" = protocol=17 | dir=in | app=e:\gms\game folder\maplestory\arikums.exe |"{3FD6FDC5-7842-4348-8818-BD491A3C288C}" = protocol=17 | dir=in | app=c:\users\thmark\appdata\local\microsoft\windows\temporary internet files\content.ie5\5mkgb4q1\crossfire_downloader.exe |"{40009B37-AD71-4FC3-BBF3-901514AA434A}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |"{410AE3F3-0407-4C0A-B503-E90C34BC7CAA}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |"{417F82E1-C789-45A5-BAB2-4B1FC33A9B37}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |"{4198AC95-5E15-41F1-8A35-EC7D76689468}" = protocol=17 | dir=in | app=e:\swor\star wars-the old republic\launcher.exe |"{41E8F1CD-C729-46ED-99D4-A901BC14B607}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |"{42FB087E-28AF-45BC-A8BA-455B75CB2C0F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |"{45692369-2B5F-4C5F-B14E-E4272B0EEC23}" = protocol=6 | dir=in | app=c:\users\thmark\desktop\ts 3-take 2\teamspeak3-server_win64\ts3server_win64.exe |"{4A9BD504-D968-4F05-953B-642B8937EDB3}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |"{4ACE554B-032D-4B8F-9654-20A571275C63}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |"{4B966F0C-C4CA-482C-ABDF-CEC721D0998B}" = protocol=6 | dir=in | app=e:\mlb\mlb2k12.exe |"{4D1E1048-2C4B-46B2-87A5-9307CE7D1313}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |"{4E13F8CB-D680-42EA-82EF-E89756366BAF}" = protocol=17 | dir=in | app=e:\steamlibrary\steamapps\common\warframe\warframe.x64.exe |"{536FD900-4096-4BCA-B0B7-4F5BC0A9FF92}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |"{593A0F85-5C12-4F4E-AD6B-9468540E37AC}" = protocol=6 | dir=in | app=e:\combat arms\nmservice.exe |"{59F514A4-0EB1-45F6-8912-83DC9BEC74E3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |"{5E18A99B-14F4-4133-9B95-2099E51285F7}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |"{5F653422-F19B-4694-BD97-1615E9FEE677}" = protocol=6 | dir=in | app=e:\kabod\kabodonline\kabod.exe |"{622D002F-877D-4BBE-A5D7-5FB857C3C008}" = protocol=17 | dir=in | app=c:\users\thmark\appdata\local\teamspeak 3 client\ts3client_win64.exe |"{629CDB1A-0B28-4E2E-87B9-A08CF637D1D6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |"{66154135-BB13-42A8-B5BC-AB00150D56F0}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |"{676BB114-3784-4CA0-9D43-AA926436DE8B}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |"{6788E073-328F-42FA-B7CC-BC3D50EB1139}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |"{685F28D9-5F9F-4886-B3D1-470C6F4770EF}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.1000.157.105\bin64\smc.exe |"{6C5C0EB3-A3DD-4BFB-A119-41E261FCCB93}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.601.4699.105\bin64\smc.exe |"{6DA14136-2C1D-4EA1-9F19-FC7CD9E04412}" = protocol=17 | dir=in | app=e:\combat arms\nmservice.exe |"{70BD9AA4-17AB-4CF3-A320-DF0D3ACB0B54}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.1000.157.105\bin64\smc.exe |"{7775A67C-D999-4635-8D93-6DA9B00E0401}" = dir=in | app=e:\port royal 2\portroyale3.exe |"{7ACB86E3-4A49-428D-9582-D25DB472C6F7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nuclear dawn\nucleardawn.exe |"{7CD7DA27-16FF-4ADD-BD3C-4AE9D7049F8A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nuclear dawn\nucleardawn.exe |"{7D73FE77-9D37-46CE-8875-AD7FC15932E1}" = protocol=6 | dir=in | app=e:\diablo 3\diabloiii\diablo iii\diablo iii.exe |"{7D868D34-6DC8-46AF-8D3C-40789979669D}" = protocol=6 | dir=in | app=e:\2k12\nba 2k12\game\nba2k12.exe |"{7F335875-A254-4C6A-BAB1-34E09402B6B0}" = protocol=6 | dir=in | app=e:\nba 2k13\nba2k13.exe |"{7FD233EF-2C87-4F69-BDBF-72BBA07B08BC}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |"{81B67A25-9001-4FA5-8E93-4BDC7CBA8322}" = protocol=6 | dir=in | app=e:\gms\game folder\maplestory\arikums.exe |"{83898779-891B-4328-955D-5A729A4F8D54}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.601.4699.105\bin64\snac64.exe |"{85083A64-B265-4ECC-BA59-55EBD8A40780}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |"{924AE3F9-77DC-463C-A232-E84440A03524}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space pirates and zombies\spazgame.exe |"{94A0AEF5-0E67-425E-B033-7FB124589E30}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |"{994A21D4-FDBB-4373-B5D1-D66B14E51ECF}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |"{A16E68AE-6564-414A-A3AA-9DC84B490FA6}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |"{A1851A8D-B21F-4E50-AE4A-8B4CBE28E448}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |"{A45CD9BB-BDBE-4604-BB3B-7CE529CDBEA9}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |"{A581D9EF-EF63-4967-BBBE-6BA404A55F5A}" = protocol=6 | dir=in | app=c:\users\thmark\appdata\local\google\google talk plugin\googletalkplugin.exe |"{A60929F7-523E-409C-8DBB-26B21B200E4E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |"{A8E8F949-17B5-40F3-A6E8-4A98460AE01D}" = protocol=6 | dir=in | app=c:\users\thmark\appdata\local\microsoft\windows\temporary internet files\content.ie5\5mkgb4q1\crossfire_downloader.exe |"{AACBE903-0458-4D41-BACD-2F3DEBA0E7F4}" = protocol=17 | dir=in | app=e:\steamlibrary\steamapps\common\warframe\warframe.exe |"{AB58BE54-2493-416D-846D-049610537D2A}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |"{AB745E09-2DC3-413D-900A-AC20876D7E1A}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |"{B77AEB15-2C77-4C53-AB97-B888A23271D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |"{B7D3C501-7066-4E29-AFD9-7AD85FC039B6}" = protocol=17 | dir=in | app=e:\kabod\kabodonline\kabod.exe |"{B8AB576A-1944-478B-B4E7-BB854813913B}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |"{BCCA66DA-BBCA-4555-B916-8C1C591C05BB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |"{C3708A31-7BA3-4B83-9A71-103EFBEC29E9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |"{C824356C-5CC8-4FD9-B638-01AE3C51380C}" = protocol=6 | dir=in | app=e:\gms\game folder\maplestory\arikums.exe |"{CD5A02E1-5BEC-4137-B49B-27D2F39F0951}" = protocol=6 | dir=in | app=c:\program files (x86)\steam 2\steam.exe |"{CD9A0E6A-520B-491F-A7E9-D49D0A6407CC}" = protocol=6 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.1000.157.105\bin64\snac64.exe |"{CD9BA3A9-76FE-4F4B-AA2C-8B9AC3323ADC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |"{CFEEBE6A-FEC3-48B4-8595-DAA8E958E2F2}" = protocol=17 | dir=in | app=e:\diablo 3\diabloiii\diablo iii\diablo iii.exe |"{D1F32D48-D003-44F8-8224-F2F852B601D2}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |"{D4CF3913-E8B4-4DC8-961E-1DA535FE831F}" = protocol=17 | dir=in | app=e:\lotr game\game.dat |"{D5C79EF1-5B9C-4ECE-B182-966B71A2AF4D}" = protocol=17 | dir=out | app=e:\steamlibrary\steamapps\common\warframe\warframe.x64.exe |"{D7158D72-2C5C-4BB0-8F34-1DB0C07B3C46}" = protocol=17 | dir=in | app=c:\program files (x86)\symantec\symantec endpoint protection\12.1.601.4699.105\bin64\snac64.exe |"{D9EB7717-9333-4EAF-BF86-E7C497D30EE1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam 2\steam.exe |"{DAFE835F-78BD-4058-A12D-255672D5322C}" = protocol=6 | dir=in | app=c:\users\thmark\appdata\local\teamspeak 3 client\ts3client_win64.exe |"{DDD5FFE1-3D31-43B8-8EB3-A1B45425126B}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |"{E2956A64-4F91-41AD-A570-840DC49446A8}" = protocol=17 | dir=in | app=e:\gms\game folder\maplestory\arikums.exe |"{E6C1EFC0-2CD3-4669-A6E8-6537F9B2F344}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |"{E70498A7-E0EB-40DA-BD2E-AF4A416835B9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |"{EEF84F77-1329-448D-8F0C-6D30685420C9}" = protocol=17 | dir=in | app=e:\happycloud\cache\the lord of the rings online\lotroclient.exe |"{F5EA0828-14B3-4EEE-9165-378023E4A177}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |"{F8C779DF-0C1A-4707-B597-D580A8C01C6B}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |"{F9B13D74-8E6C-4D2A-871A-4B154C22BC12}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |"TCP Query User{72F3BD55-128A-4D47-94C7-7A28F55772A3}E:\wot\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=e:\wot\world_of_tanks\wotlauncher.exe |"TCP Query User{B2ACE4A2-5F29-4DE1-AEBA-1B19ED99B6C7}E:\wot\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=e:\wot\world_of_tanks\worldoftanks.exe |"TCP Query User{B3C7C84A-19A1-4CC7-AC6E-BF70A7029A76}E:\cod\call of duty - black ops\blackops.exe" = protocol=6 | dir=in | app=e:\cod\call of duty - black ops\blackops.exe |"UDP Query User{3A5B4002-DFE9-4939-AC4E-E001BA6121D3}E:\wot\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=e:\wot\world_of_tanks\wotlauncher.exe |"UDP Query User{9339E1C4-6B6C-4BE8-88C7-7ED8E4051EB5}E:\wot\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=e:\wot\world_of_tanks\worldoftanks.exe |"UDP Query User{A7B221BA-42BC-46D9-8B8D-94E2E8BDBB8F}E:\cod\call of duty - black ops\blackops.exe" = protocol=17 | dir=in | app=e:\cod\call of duty - black ops\blackops.exe |========== HKEY_LOCAL_MACHINE Uninstall List ==========64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)"{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp version 0.99.8"{19B62EDC-C108-4393-B3F1-8A813096CC8E}" = Symantec Endpoint Protection"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219"{2eeef4d9-e5f4-4fb8-b67f-fe3e9ebb2efb}.sdb" = Kabod"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support"{3C1F302A-CC25-488D-9C24-A76B95BC916F}" = Nitro Reader 3"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010"{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0409-1000-0000000FF1CE}_Office14.VISIOR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-040C-1000-0000000FF1CE}_Office14.VISIOR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUS_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.VISIOR_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUS_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PRJPROR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0043-0000-1000-0000000FF1CE}_Office14.VISIOR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUS_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0054-0409-1000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010"{90140000-0054-0409-1000-0000000FF1CE}_Office14.VISIOR_{7DC2B20B-31B9-4C7C-B8DC-8492A9A3095E}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-00B4-0409-1000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2010"{90140000-00B4-0409-1000-0000000FF1CE}_Office14.PRJPROR_{316A864B-0547-40CE-B136-B02B4D18BF09}" = Microsoft Project 2010 Service Pack 1 (SP1)"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)"{91140000-003B-0000-1000-0000000FF1CE}" = Microsoft Office Project Professional 2010"{91140000-003B-0000-1000-0000000FF1CE}_Office14.PRJPROR_{E6F88893-86F0-4CFB-B7E0-733575D1DEB4}" = Microsoft Project 2010 Service Pack 1 (SP1)"{91140000-0057-0000-1000-0000000FF1CE}" = Microsoft Office Visio 2010"{91140000-0057-0000-1000-0000000FF1CE}_Office14.VISIOR_{9081486B-B26D-42DB-8D31-81C525A9526A}" = Microsoft Visio 2010 Service Pack 1 (SP1)"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 311.06"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 311.06"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 311.06"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 306.97"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0604"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.18.0"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components"{BAF9E4D0-F3D1-4355-B973-1384CDF1941C}" = Hex Workshop v6.6"{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud"{D9C50188-12D5-4D3E-8F00-682346C2AA5F}" = Microsoft Xbox 360 Accessories 1.2"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended"Office14.PRJPROR" = Microsoft Project Professional 2010"Office14.PROPLUS" = Microsoft Office Professional Plus 2010"Office14.VISIOR" = Microsoft Visio Premium 2010"WinRAR archiver" = WinRAR 4.01 (64-bit)[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam"{04E9B02B-4F85-4B73-B865-27B9B8B35877}" = NBA 2K12"{05A7B662-80A3-4EB9-AE1D-89A62449431C}" = Oracle Database 11g Express Edition"{07EF3970-F8E5-4A27-A5A3-230484D35026}" = Microsoft Expression Encoder 4"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86"{08D605B4-DCD1-451F-ABD7-52E6BB868E4E}" = Microsoft Expression Design 4"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser"{1C997E1C-5CE9-4AF3-AAA9-DC65E6090827}" = Microsoft Expression Blend SDK for Silverlight 4"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks v.0.6.3.11"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK"{2300EE96-0A41-4FAB-BD03-989EC44577A0}" = Acronis Disk Director Suite"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer"{256E7DAC-9BE8-494E-8DE7-7857BF96B774}" = Microsoft Expression Blend 3 SDK"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java 6 Update 39"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver"{3248F0A8-6813-11D6-A77B-00B0D0150170}" = J2SE Runtime Environment 5.0 Update 17"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic"{3C6A9286-2A4B-43DF-A322-01ABFFDCD248}" = Ragnarok Online2"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF010}" = Tribes Ascend"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater"{4A5667B2-5D13-46C2-85B5-9D46A6096F61}" = Secure Download Manager"{4C6D5779-A766-45DF-9938-D6F595A66F2B}" = Microsoft Expression Blend 4"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace"{51268A7D-4E1A-371A-9849-496D48930952}" = Google Talk Plugin"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack"{5E21B617-F52E-BB10-92F9-C8AB2C799A8A}" = Adobe Download Assistant"{5EE6E987-1B79-4A93-832B-27472C7D1579}" = WPF Toolkit February 2010 (Version 3.5.50211.1)"{5F8D931D-B230-47F3-A9C0-0C8CA459A332}" = Microsoft Expression Web 4"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE"{68DED384-1F74-4AEE-8B8E-95AF15572FE3}" = Port Royale 3"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer"{6D87CAD9-9B94-4421-A439-B25F8DE14575}" = Tom Clancy's Ghost Recon Future Soldier"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable"{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6"{75D84EF7-0D8C-4e70-TCGRFS-7B42A5D4E0EB}_is1" = Tom Clancys Ghost Recon Future Soldier version 1.02"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update"{801B0DA3-A3FF-46CC-B97F-D76D510AF5AE}" = Microsoft Silverlight 4 SDK"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster"{987F1753-1F42-4DF2-A5EA-0CCB777F3EB0}" = ASPCA Reminder by We-Care.com v4.0.19.1"{99AD9D6D-A456-49EE-8360-F22EE7AA1272}" = Express Gate"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17"{9B3A1C97-A361-463E-8817-444F9F88CDFE}" = Microsoft Expression Blend SDK for .NET 4"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161"{A06FE62B-CEBC-4E94-AED8-92DCC33BC8EA}" = Microsoft Expression Studio 4"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)"{B119B96C-F724-4A9D-87FF-A505BD4C3772}" = BlueStacks"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call"{BF127B80-CFD5-4379-9752-E8AF1A5D0141}" = Microsoft Expression Encoder 4 Screen Capture Codec"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform"{D5B18B60-4FC3-42AD-A629-9CA10ACC06CD}" = HTC Sync"{D96B6543-A0C0-4351-AF96-73DEF1DD6820}" = NBA 2K13"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger"{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI"{E6C29DA3-ADD6-4941-903A-43965CBB0F7C}" = Major League Baseball 2K12"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219"{F5993FCC-DF5D-4879-B70D-AA1F379C5C6B}" = Microsoft Expression Web 4 Service Pack 2"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022"Adobe AIR" = Adobe AIR"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin"Adobe Shockwave Player" = Adobe Shockwave Player 11.6"AhnLab Online Security" = AhnLab Online Security"Amazon Kindle" = Amazon Kindle"ArtMoney SE_is1" = ArtMoney SE v7.37.2"Audacity_is1" = Audacity 2.0"AVS Document Converter_is1" = AVS Document Converter 2.0.1"AVS Ringtone Maker 1.6_is1" = AVS Ringtone Maker version 1.6"AVS Update Manager_is1" = AVS Update Manager 1.0"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4"black-ops_folder" = black-ops.themepack"Blend_4.0.20525.0" = Microsoft Expression Blend 4"Cheat Engine 6.1_is1" = Cheat Engine 6.1"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant"DAEMON Tools Lite" = DAEMON Tools Lite"Design_7.0.20516.0" = Microsoft Expression Design 4"Encoder_4.0.1639.0" = Microsoft Expression Encoder 4"ExpressionStudio_4.0.20525.0" = Microsoft Expression Studio 4"FIFA 12 © EA_is1" = FIFA 12 © EA version 1"FlashGet 3.7" = FlashGet 3.7"Galactic Magnate_is1" = Galactic Magnate v1.2"Guild Wars 2" = Guild Wars 2"Homefront_is1" = Homefront"hon" = Heroes of Newerth"HydraIRC" = HydraIRC"InstaCodecs_is1" = InstaCodecs"InstallShield_{05A7B662-80A3-4EB9-AE1D-89A62449431C}" = Oracle Database 11g Express Edition"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver"KLiteCodecPack_is1" = K-Lite Codec Pack 7.8.0 (Full)"MahjongWorldClient" = MahjongWorld (uninstall only)"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1"mIRC" = mIRC"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)"MozillaMaintenanceService" = Mozilla Maintenance Service"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver"Origin" = Origin"pcsx2-r5350" = PCSX2 - Playstation 2 Emulator"PrimoPDF" = PrimoPDF -- brought to you by Nitro PDF Software"PunkBusterSvc" = PunkBuster Services"Saints Row. The Third_is1" = Saints Row. The Third 1.0"Sins of a Solar Empire Rebellion © Stardock_is1" = Sins of a Solar Empire Rebellion © Stardock version 1"Steam App 230410" = Warframe"Steam App 9880" = Champions Online: Free For All"TeamViewer 8" = TeamViewer 8"VLC media player" = VLC media player 1.1.11"Web_4.0.1303.0" = Microsoft Expression Web 4"WinLiveSuite" = Windows Live Essentials"xchat" = XChat 2 (remove only)========== HKEY_USERS Uninstall List ==========[HKEY_USERS\S-1-5-21-4050476716-2494318647-2019036779-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]"fc418bf9b18f76aa" = Ghost Recon Online (NCSA-Live)"HappyCloud" = Happy Cloud Client"Spiral Knights" = Spiral Knights"TeamSpeak 3 Client" = TeamSpeak 3 Client========== Last 20 Event Log Errors ==========[ Application Events ]Error - 6/11/2013 8:50:30 PM | Computer Name = THMark-PC | Source = WinMgmt | ID = 10Description =Error - 6/11/2013 8:56:25 PM | Computer Name = THMark-PC | Source = WinMgmt | ID = 10Description =Error - 6/11/2013 9:00:20 PM | Computer Name = THMark-PC | Source = WinMgmt | ID = 10Description =Error - 6/11/2013 11:38:36 PM | Computer Name = THMark-PC | Source = Symantec AntiVirus | ID = 16711731Description = Security Risk Found!Suspicious.Cloud.2 in File: c:\users\thmark\appdata\local\temp\notepad.exe by: Defwatch scan. Action: Quarantine failed. Action Description: The file was left unchanged. Error - 6/11/2013 11:57:13 PM | Computer Name = THMark-PC | Source = WinMgmt | ID = 10Description =Error - 6/12/2013 12:35:01 AM | Computer Name = THMark-PC | Source = WinMgmt | ID = 10Description =Error - 6/12/2013 1:33:28 AM | Computer Name = THMark-PC | Source = System Restore | ID = 8193Description =Error - 6/12/2013 2:59:02 AM | Computer Name = THMark-PC | Source = System Restore | ID = 8193Description =Error - 6/12/2013 3:06:53 AM | Computer Name = THMark-PC | Source = WinMgmt | ID = 10Description =Error - 6/12/2013 3:52:43 AM | Computer Name = THMark-PC | Source = WinMgmt | ID = 10Description =Error - 6/12/2013 4:45:41 AM | Computer Name = THMark-PC | Source = System Restore | ID = 8193Description =[ Media Center Events ]Error - 8/30/2011 4:48:46 AM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 1:48:42 AM - Error connecting to the internet. 1:48:42 AM - Unable to contact server.. Error - 10/7/2011 4:49:05 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 1:49:05 PM - Error connecting to the internet. 1:49:05 PM - Unable to contact server.. Error - 10/7/2011 4:49:13 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 1:49:10 PM - Error connecting to the internet. 1:49:10 PM - Unable to contact server.. Error - 10/7/2011 5:49:20 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 2:49:20 PM - Error connecting to the internet. 2:49:20 PM - Unable to contact server.. Error - 10/7/2011 5:49:26 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 2:49:25 PM - Error connecting to the internet. 2:49:25 PM - Unable to contact server.. Error - 10/7/2011 6:53:40 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 3:53:40 PM - Error connecting to the internet. 3:53:40 PM - Unable to contact server.. Error - 10/7/2011 6:53:46 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 3:53:45 PM - Error connecting to the internet. 3:53:45 PM - Unable to contact server.. Error - 10/7/2011 7:53:53 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 4:53:53 PM - Error connecting to the internet. 4:53:53 PM - Unable to contact server.. Error - 10/7/2011 7:53:59 PM | Computer Name = THMark-PC | Source = MCUpdate | ID = 0Description = 4:53:58 PM - Error connecting to the internet. 4:53:58 PM - Unable to contact server.. [ System Events ]Error - 6/12/2013 1:41:00 AM | Computer Name = THMark-PC | Source = Application Popup | ID = 1060Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible versionof the driver.Error - 6/12/2013 1:45:41 AM | Computer Name = THMark-PC | Source = Service Control Manager | ID = 7030Description = The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.Error - 6/12/2013 2:59:53 AM | Computer Name = THMark-PC | Source = Application Popup | ID = 1060Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible versionof the driver.Error - 6/12/2013 2:59:53 AM | Computer Name = THMark-PC | Source = Application Popup | ID = 1060Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible versionof the driver.Error - 6/12/2013 3:01:41 AM | Computer Name = THMark-PC | Source = Service Control Manager | ID = 7030Description = The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.Error - 6/12/2013 3:03:33 AM | Computer Name = THMark-PC | Source = Service Control Manager | ID = 7030Description = The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.Error - 6/12/2013 3:09:28 AM | Computer Name = THMark-PC | Source = Service Control Manager | ID = 7038Description = The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: %%1330 To ensure that the service is configured properly, use the Services snap-in in MicrosoftManagement Console (MMC).Error - 6/12/2013 3:09:28 AM | Computer Name = THMark-PC | Source = Service Control Manager | ID = 7000Description = The NVIDIA Update Service Daemon service failed to start due to the following error: %%1069Error - 6/12/2013 3:55:32 AM | Computer Name = THMark-PC | Source = Service Control Manager | ID = 7038Description = The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: %%1330 To ensure that the service is configured properly, use the Services snap-in in MicrosoftManagement Console (MMC).Error - 6/12/2013 3:55:32 AM | Computer Name = THMark-PC | Source = Service Control Manager | ID = 7000Description = The NVIDIA Update Service Daemon service failed to start due to the following error: %%1069< End of report > Link to post Share on other sites More sharing options...
dnahunter Posted June 12, 2013 Author ID:690301 Share Posted June 12, 2013 OTL logfile created on: 6/12/2013 9:17:53 AM - Run 1OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\THMark\Desktop64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstationInternet Explorer (Version = 9.10.9200.16576)Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy8.00 Gb Total Physical Memory | 5.32 Gb Available Physical Memory | 66.46% Memory free16.00 Gb Paging File | 12.58 Gb Available in Paging File | 78.66% Paging File freePaging file location(s): ?:\pagefile.sys [binary data]%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)Drive C: | 131.41 Gb Total Space | 35.40 Gb Free Space | 26.94% Space Free | Partition Type: NTFSDrive D: | 50.00 Gb Total Space | 8.67 Gb Free Space | 17.34% Space Free | Partition Type: NTFSDrive E: | 200.00 Gb Total Space | 48.69 Gb Free Space | 24.35% Space Free | Partition Type: NTFSDrive G: | 150.00 Gb Total Space | 76.51 Gb Free Space | 51.01% Space Free | Partition Type: NTFSDrive H: | 100.00 Gb Total Space | 24.04 Gb Free Space | 24.04% Space Free | Partition Type: NTFSDrive J: | 2.42 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFSDrive Z: | 600.00 Gb Total Space | 254.09 Gb Free Space | 42.35% Space Free | Partition Type: NTFSComputer Name: THMARK-PC | User Name: THMark | Logged in as Administrator.Boot Mode: Normal | Scan Mode: All users | Include 64bit ScansCompany Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days========== Processes (SafeList) ==========PRC - [2013/06/12 09:16:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\THMark\Desktop\OTL.exePRC - [2013/05/14 13:26:12 | 003,289,208 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exePRC - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exePRC - [2013/04/07 09:02:04 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exePRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exePRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exePRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exePRC - [2013/03/06 08:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exePRC - [2013/01/24 15:26:10 | 000,812,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exePRC - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exePRC - [2013/01/08 01:41:08 | 003,674,320 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exePRC - [2012/07/10 14:18:10 | 000,385,416 | ---- | M] (BlueStack Systems, Inc.) -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exePRC - [2011/09/20 21:58:00 | 000,137,224 | ---- | M] (Symantec Corporation) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exePRC - [2011/08/27 10:00:20 | 000,512,000 | ---- | M] (Oracle Corporation) -- C:\oraclexe\app\oracle\product\11.2.0\server\bin\TNSLSNR.EXEPRC - [2011/08/27 09:58:50 | 115,773,440 | ---- | M] (Oracle Corporation) -- c:\oraclexe\app\oracle\product\11.2.0\server\bin\oracle.exePRC - [2011/08/22 10:01:00 | 000,593,920 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exePRC - [2011/08/12 17:13:26 | 000,087,040 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exePRC - [2010/04/27 10:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exePRC - [2009/10/16 10:42:48 | 000,319,488 | -H-- | M] (DeviceVM, Inc.) -- C:\ASUS.SYS\config\DVMExportService.exe========== Modules (No Company Name) ==========MOD - [2013/05/16 03:02:40 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\56765d6988c0fc573c31d3c6066fc704\System.Configuration.ni.dllMOD - [2013/01/15 17:53:39 | 000,014,768 | ---- | M] () -- C:\Program Files (x86)\Java\jre6\bin\jp2native.dllMOD - [2013/01/15 17:53:33 | 000,108,976 | ---- | M] () -- C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dllMOD - [2013/01/10 04:33:43 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dllMOD - [2013/01/10 04:33:11 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dllMOD - [2013/01/10 04:33:08 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dllMOD - [2013/01/10 04:33:04 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dllMOD - [2012/11/28 15:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dllMOD - [2012/11/28 15:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dllMOD - [2011/08/22 10:01:00 | 001,515,520 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dllMOD - [2011/08/22 10:01:00 | 000,593,920 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exeMOD - [2011/08/22 10:01:00 | 000,559,244 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.7.dllMOD - [2011/08/22 10:01:00 | 000,516,599 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dllMOD - [2011/08/22 10:01:00 | 000,389,120 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetect.dllMOD - [2011/08/22 10:01:00 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dllMOD - [2011/08/22 10:01:00 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dllMOD - [2011/08/22 10:01:00 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dllMOD - [2010/11/20 20:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll========== Services (SafeList) ==========SRV:64bit: - [2012/10/30 20:10:50 | 000,230,416 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe -- (NitroReaderDriverReadSpool3)SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)SRV:64bit: - [2009/07/13 18:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)SRV - [2013/06/12 06:07:08 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)SRV - [2013/05/14 13:26:12 | 003,289,208 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)SRV - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)SRV - [2013/04/23 05:48:24 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Auto | Running] -- E:\ARRRGHHH!!\HiPatchService.exe -- (HiPatchService)SRV - [2013/04/11 18:17:10 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)SRV - [2013/04/07 09:02:04 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)SRV - [2013/03/06 08:30:43 | 003,560,288 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)SRV - [2013/02/26 00:32:22 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)SRV - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)SRV - [2012/07/25 12:32:00 | 004,622,336 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)SRV - [2012/07/10 14:18:10 | 000,385,416 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)SRV - [2012/07/10 14:17:20 | 000,397,704 | ---- | M] (BlueStack Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)SRV - [2011/10/30 19:01:00 | 002,594,816 | ---- | M] (Symantec Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin64\Smc.exe -- (SmcService)SRV - [2011/10/30 18:41:00 | 000,324,016 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin64\snac64.exe -- (SNAC)SRV - [2011/09/20 21:58:00 | 000,137,224 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\ccSvcHst.exe -- (SepMasterService)SRV - [2011/08/27 10:01:00 | 000,012,800 | ---- | M] (Oracle Corporation) [On_Demand | Stopped] -- C:\oraclexe\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe -- (OracleXEClrAgent)SRV - [2011/08/27 10:00:20 | 000,512,000 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\oraclexe\app\oracle\product\11.2.0\server\bin\TNSLSNR.EXE -- (OracleXETNSListener)SRV - [2011/08/27 09:59:56 | 000,069,632 | ---- | M] (Oracle Corporation) [On_Demand | Stopped] -- C:\oraclexe\app\oracle\product\11.2.0\server\BIN\omtsreco.exe -- (OracleMTSRecoveryService)SRV - [2011/08/27 09:58:52 | 000,049,152 | ---- | M] () [Disabled | Stopped] -- c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe -- (OracleJobSchedulerXE)SRV - [2011/08/27 09:58:50 | 115,773,440 | ---- | M] (Oracle Corporation) [Auto | Running] -- c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE -- (OracleServiceXE)SRV - [2011/08/12 17:13:26 | 000,087,040 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)SRV - [2011/03/16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)SRV - [2009/10/16 10:42:48 | 000,319,488 | -H-- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\ASUS.SYS\config\DVMExportService.exe -- (DvmMDES)SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)SRV - [2007/02/22 19:53:16 | 002,217,416 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe -- (AcronisOSSReinstallSvc)========== Driver Services (SafeList) ==========DRV:64bit: - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)DRV:64bit: - [2013/02/13 16:58:55 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)DRV:64bit: - [2012/12/13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)DRV:64bit: - [2012/08/23 07:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)DRV:64bit: - [2012/08/23 07:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)DRV:64bit: - [2012/08/23 07:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)DRV:64bit: - [2012/08/21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)DRV:64bit: - [2012/07/03 08:25:16 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)DRV:64bit: - [2012/03/09 12:18:31 | 000,174,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)DRV:64bit: - [2011/09/27 17:45:00 | 000,678,008 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\SEP\0C0103E8\009D.105\x64\srtsp64.sys -- (SRTSP)DRV:64bit: - [2011/09/27 17:45:00 | 000,039,032 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SEP\0C0103E8\009D.105\x64\srtspx64.sys -- (SRTSPX)DRV:64bit: - [2011/09/13 17:46:00 | 000,171,128 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SEP\0C0103E8\009D.105\x64\Ironx64.sys -- (SymIRON)DRV:64bit: - [2011/09/08 18:24:00 | 000,386,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SEP\0C0103E8\009D.105\x64\symnets.sys -- (SYMNETS)DRV:64bit: - [2011/08/27 17:48:00 | 000,931,448 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\SEP\0C0103E8\009D.105\x64\SymEFA64.sys -- (SymEFA)DRV:64bit: - [2011/08/16 02:25:00 | 000,062,672 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Teefer.sys -- (Teefer2)DRV:64bit: - [2011/07/25 00:00:21 | 000,198,944 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)DRV:64bit: - [2011/07/16 17:48:00 | 000,451,192 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SEP\0C0103E8\009D.105\x64\SymDS64.sys -- (SymDS)DRV:64bit: - [2011/06/10 07:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)DRV:64bit: - [2011/03/10 23:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)DRV:64bit: - [2011/03/10 23:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)DRV:64bit: - [2010/11/20 20:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)DRV:64bit: - [2010/11/20 20:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)DRV:64bit: - [2010/06/25 16:08:10 | 000,036,928 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)DRV:64bit: - [2010/04/27 09:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)DRV:64bit: - [2010/04/27 09:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)DRV:64bit: - [2009/11/02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)DRV:64bit: - [2009/08/21 01:52:10 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)DRV:64bit: - [2009/07/15 20:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)DRV:64bit: - [2009/07/13 17:09:10 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\loop.sys -- (msloop)DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)DRV - [2013/05/28 16:38:21 | 002,098,776 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\VirusDefs\20130611.033\ex64.sys -- (NAVEX15)DRV - [2013/05/28 16:38:20 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\VirusDefs\20130611.033\eng64.sys -- (NAVENG)DRV - [2013/04/12 16:54:03 | 001,390,680 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\BASHDefs\20130521.011\BHDrvx64.sys -- (BHDrvx64)DRV - [2012/08/31 17:19:50 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Definitions\IPSDefs\20130611.001\IDSviA64.sys -- (IDSVia64)DRV - [2012/08/08 20:16:15 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)DRV - [2012/08/08 20:16:15 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)DRV - [2012/07/10 14:18:02 | 000,075,144 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)========== Standard Registry (SafeList) ==================== Internet Explorer ==========IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmIE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=113933&tt=120812_bandext_3212_1&babsrc=HP_ss&mntrId=1e666e7c00000000000002004c4f4f50IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-usIE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A3 EF B2 E7 2C 4A CC 01 [binary data]IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SRIE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=113933&tt=120812_bandext_3212_1&babsrc=SP_ss&mntrId=1e666e7c00000000000002004c4f4f50IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_enIE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local========== FireFox ==========FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"FF - prefs.js..browser.startup.homepage: "google.com"FF - prefs.js..extensions.enabledAddons: %7B59c81df5-4b7a-477b-912d-4e0fdf64e5f2%7D:0.9.90FF - prefs.js..extensions.enabledAddons: %7BBBDA0591-3099-440a-AA10-41764D9DB4DB%7D:11.3.0.9%20-%205FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not foundFF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: G:\New folder\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)FF - HKLM\Software\MozillaPlugins\@ahnlab.com/asp/npaosmgr.1: C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\conflict_221\npaosmgr.dll (AhnLab, Inc.)FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not foundFF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not foundFF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: G:\New folder\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\THMark\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\THMark\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\THMark\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\THMark\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\THMark\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)FF - HKCU\Software\MozillaPlugins\thehappycloud.com/HappyCloudPlugin: C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\IPSFFPlgn\ [2013/06/12 00:52:30 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/11 18:17:10 | 000,000,000 | ---D | M]FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins[2011/09/07 09:36:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\THMark\AppData\Roaming\Mozilla\Extensions[2013/06/08 20:34:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\extensions[2013/06/08 20:34:51 | 000,000,000 | ---D | M] ("FoodBuzz") -- C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\extensions\{2326C1C3-3E92-49da-A3FB-CB8AD8AD8F25}[2013/02/14 00:14:15 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}[2013/03/05 15:08:07 | 000,000,000 | ---D | M] (We-Care App) -- C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\extensions\wecarereminder@bryan[2012/08/12 15:48:46 | 000,002,227 | ---- | M] () -- C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\searchplugins\BabylonMngr.xml[2013/04/11 18:17:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions[2013/05/23 03:27:35 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}[2013/04/11 18:17:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}[2013/04/11 18:17:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}[2013/04/28 21:27:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions[2013/05/23 03:27:35 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}[2013/06/04 18:20:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\updated\extensions[2013/06/04 18:20:47 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\updated\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}[2013/06/04 18:20:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\updated\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}[2013/06/04 18:20:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\updated\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}[2013/06/04 18:20:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\updated\browser\extensions[2013/06/04 18:20:47 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\updated\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}[2013/06/04 18:20:51 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\updated\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}[2013/06/12 00:52:30 | 000,000,000 | ---D | M] (Symantec Intrusion Prevention) -- C:\PROGRAMDATA\SYMANTEC\SYMANTEC ENDPOINT PROTECTION\12.1.1000.157.105\DATA\IPSFFPLGN[2013/04/11 18:17:10 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll[2012/08/12 15:48:40 | 000,002,364 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml[2013/01/19 12:45:16 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml[2011/09/02 16:25:59 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old[2013/02/19 16:01:44 | 000,002,086 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml========== Chrome ==========O1 HOSTS File: ([2013/06/12 00:25:31 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hostsO1 - Hosts: 127.0.0.1 localhostO2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\IPS\IPSBHO.dll (Symantec Corporation)O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\THMark\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll (Trend Media Group)O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)O3:64bit: - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)O4:64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)O4 - HKLM..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)O4 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)O4 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()O4 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000..\Run: [steam] C:\Program Files (x86)\Steam 2\Steam.exe (Valve Corporation)O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO7 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO7 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145O7 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0O8:64bit: - Extra context menu item: Download all by FlashGet3 - C:\Users\THMark\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()O8:64bit: - Extra context menu item: Download by FlashGet3 - C:\Users\THMark\AppData\Roaming\FlashGetBHO\GetUrl.htm ()O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not foundO8 - Extra context menu item: Download all by FlashGet3 - C:\Users\THMark\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()O8 - Extra context menu item: Download by FlashGet3 - C:\Users\THMark\AppData\Roaming\FlashGetBHO\GetUrl.htm ()O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not foundO9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)O13 - gopher Prefix: missingO15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )O15 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)O15 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)O15 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..Trusted Domains: soe.com ([]* in Trusted sites)O15 - HKU\S-1-5-21-4050476716-2494318647-2019036779-1000\..Trusted Domains: sony.com ([]* in Trusted sites)O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39)O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.80.2.cab (Battlefield Play4Free Updater)O16 - DPF: {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_17-windows-i586.cab (Java Plug-in 1.5.0_17)O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39)O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab (Java Plug-in 1.6.0_39)O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab (SysInfo Class)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3FD03C73-2DA3-4BF2-BBC3-35FA76540AB3}: DhcpNameServer = 192.168.0.1O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6270270B-9F29-4756-B371-C7BDBA678C86}: DhcpNameServer = 192.168.1.133O18:64bit: - Protocol\Handler\livecall - No CLSID value foundO18:64bit: - Protocol\Handler\msnim - No CLSID value foundO18:64bit: - Protocol\Handler\skype4com - No CLSID value foundO18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)O18 - Protocol\Handler\ms-help - No CLSID value foundO18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)O20 - Winlogon\Notify\SEP: DllName - (C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Bin\WinLogoutNotifier.dll) - File not foundO21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.O32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2012/06/12 11:17:33 | 000,000,041 | R--- | M] () - J:\autorun.inf -- [ CDFS ]O34 - HKLM BootExecute: (autocheck autochk *)O35:64bit: - HKLM\..comfile [open] -- "%1" %*O35:64bit: - HKLM\..exefile [open] -- "%1" %*O35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*O37 - HKLM\...com [@ = ComFile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)========== Files/Folders - Created Within 30 Days ==========[2013/06/12 09:16:53 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\THMark\Desktop\OTL.exe[2013/06/12 00:28:15 | 000,000,000 | ---D | C] -- C:\Windows\temp[2013/06/12 00:25:37 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN[2013/06/11 23:56:23 | 005,078,680 | R--- | C] (Swearware) -- C:\Users\THMark\Desktop\ComboFix.exe[2013/06/11 22:33:23 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe[2013/06/11 22:33:23 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe[2013/06/11 22:33:23 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe[2013/06/11 22:33:02 | 000,000,000 | ---D | C] -- C:\Qoobox[2013/06/11 22:32:32 | 000,000,000 | ---D | C] -- C:\Windows\erdnt[2013/06/11 21:42:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)[2013/06/11 21:37:29 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\{FA7A3120-1FC0-4A0A-A0B9-F719C739369A}[2013/06/11 21:32:00 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine[2013/06/11 20:57:11 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\{358D293F-3171-4A14-B3B9-D42F32B68222}[2013/06/09 20:43:14 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\Warframe[2013/06/08 20:39:35 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\FreeOCR[2013/06/08 20:35:03 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\assembly[2013/06/08 20:34:45 | 002,680,320 | ---- | C] (HiComponents) -- C:\Windows\SysWow64\ImageEnXLibrary.ocx[2013/06/08 20:34:43 | 000,000,000 | ---D | C] -- C:\FreeOCR[2013/06/08 20:32:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Temp[2013/06/05 08:42:55 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\{19AE5637-162C-43D7-AF94-C748693EB32F}[2013/06/05 03:09:28 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll[2013/06/05 03:09:28 | 001,509,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl[2013/06/05 03:09:28 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl[2013/06/05 03:09:28 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat[2013/06/05 03:09:28 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat[2013/06/05 03:09:28 | 001,054,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe[2013/06/05 03:09:28 | 000,905,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll[2013/06/05 03:09:28 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll[2013/06/05 03:09:28 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll[2013/06/05 03:09:28 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll[2013/06/05 03:09:28 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll[2013/06/05 03:09:28 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll[2013/06/05 03:09:28 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll[2013/06/05 03:09:28 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll[2013/06/05 03:09:28 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll[2013/06/05 03:09:28 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll[2013/06/05 03:09:28 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec[2013/06/05 03:09:28 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll[2013/06/05 03:09:28 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec[2013/06/05 03:09:28 | 000,281,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll[2013/06/05 03:09:28 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll[2013/06/05 03:09:28 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll[2013/06/05 03:09:28 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll[2013/06/05 03:09:28 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll[2013/06/05 03:09:28 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll[2013/06/05 03:09:28 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll[2013/06/05 03:09:28 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe[2013/06/05 03:09:28 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe[2013/06/05 03:09:28 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll[2013/06/05 03:09:28 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe[2013/06/05 03:09:28 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll[2013/06/05 03:09:28 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe[2013/06/05 03:09:28 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe[2013/06/05 03:09:28 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe[2013/06/05 03:09:28 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll[2013/06/05 03:09:28 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll[2013/06/05 03:09:28 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll[2013/06/05 03:09:28 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll[2013/06/05 03:09:28 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll[2013/06/05 03:09:28 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll[2013/06/05 03:09:28 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll[2013/06/05 03:09:28 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll[2013/06/05 03:09:28 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll[2013/06/05 03:09:28 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe[2013/06/05 03:09:28 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe[2013/06/05 03:09:28 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll[2013/06/05 03:09:28 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll[2013/06/05 03:09:28 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll[2013/06/05 03:09:28 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx[2013/06/05 03:09:28 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe[2013/06/05 03:09:28 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe[2013/06/05 03:09:28 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll[2013/06/05 03:09:28 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll[2013/06/05 03:09:28 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll[2013/06/05 03:09:28 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx[2013/06/05 03:09:28 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll[2013/06/05 03:09:28 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll[2013/06/05 03:09:28 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe[2013/06/05 03:09:28 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll[2013/06/05 03:09:28 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll[2013/06/05 03:09:28 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll[2013/06/05 03:09:28 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll[2013/06/05 03:09:28 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll[2013/06/05 03:09:28 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll[2013/06/05 03:09:28 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll[2013/06/05 03:09:28 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe[2013/06/05 03:09:28 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe[2013/06/05 03:09:28 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe[2013/06/05 03:01:47 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll[2013/06/05 03:01:47 | 002,776,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll[2013/06/05 03:01:47 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll[2013/06/05 03:01:47 | 002,284,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll[2013/06/05 03:01:47 | 001,887,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll[2013/06/05 03:01:47 | 001,682,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll[2013/06/05 03:01:47 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll[2013/06/05 03:01:47 | 001,504,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll[2013/06/05 03:01:47 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll[2013/06/05 03:01:47 | 001,238,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll[2013/06/05 03:01:47 | 001,158,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll[2013/06/05 03:01:47 | 000,648,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll[2013/06/05 03:01:47 | 000,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll[2013/06/05 03:01:47 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll[2013/06/05 03:01:47 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll[2013/06/05 03:01:47 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll[2013/06/05 03:01:47 | 000,363,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll[2013/06/05 03:01:47 | 000,333,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll[2013/06/05 03:01:47 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll[2013/06/05 03:01:47 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll[2013/06/05 03:01:47 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll[2013/06/05 03:01:47 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll[2013/06/05 03:01:47 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll[2013/06/05 03:01:47 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll[2013/06/05 03:01:47 | 000,010,752 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll[2013/06/05 03:01:47 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll[2013/06/05 03:01:47 | 000,009,728 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll[2013/06/05 03:01:47 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll[2013/06/05 03:01:47 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll[2013/06/05 03:01:47 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll[2013/06/05 03:01:47 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll[2013/06/05 03:01:47 | 000,002,560 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll[2013/06/03 23:27:56 | 000,000,000 | ---D | C] -- C:\Users\THMark\Documents\Downloads[2013/06/02 20:04:52 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\{9AD8D4DB-F944-4F62-9B43-2EC362AD5D4D}[2013/05/31 09:10:43 | 000,000,000 | ---D | C] -- C:\Users\THMark\Documents\Mama[2013/05/26 21:02:17 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Roaming\SystemRequirementsLab[2013/05/20 14:00:04 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Roaming\Nitro PDF[2013/05/17 12:03:12 | 000,000,000 | ---D | C] -- C:\Users\THMark\Desktop\TS 3-Take 2[2013/05/17 11:21:04 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess[2013/05/16 07:49:42 | 000,000,000 | ---D | C] -- C:\Users\THMark\AppData\Local\{BA883505-911C-4F42-9431-2A3785952414}[2013/05/15 15:59:18 | 000,265,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys[2013/05/15 15:59:18 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll[2013/05/15 15:59:06 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll[2013/05/15 15:59:06 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll[2013/05/15 15:59:05 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll[2013/05/15 15:59:05 | 000,111,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe[2013/05/15 15:58:53 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wwanprotdim.dll[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ][1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]========== Files - Modified Within 30 Days ==========[2013/06/12 09:16:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\THMark\Desktop\OTL.exe[2013/06/12 09:07:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job[2013/06/12 08:47:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job[2013/06/12 08:37:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000UA.job[2013/06/12 07:47:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job[2013/06/12 06:07:08 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe[2013/06/12 06:07:08 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl[2013/06/12 01:01:49 | 000,000,177 | -H-- | M] () -- C:\dvmexp.idx[2013/06/12 01:00:35 | 000,020,528 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0[2013/06/12 01:00:35 | 000,020,528 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0[2013/06/12 00:56:12 | 000,800,970 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI[2013/06/12 00:56:12 | 000,674,652 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat[2013/06/12 00:56:12 | 000,127,418 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat[2013/06/12 00:50:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat[2013/06/12 00:50:34 | 2146,734,079 | -HS- | M] () -- C:\hiberfil.sys[2013/06/12 00:25:31 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts[2013/06/11 23:56:36 | 005,078,680 | R--- | M] (Swearware) -- C:\Users\THMark\Desktop\ComboFix.exe[2013/06/11 18:37:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000Core.job[2013/06/11 17:58:55 | 671,780,163 | ---- | M] () -- C:\Windows\MEMORY.DMP[2013/06/05 03:09:28 | 003,958,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll[2013/06/05 03:09:28 | 001,509,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl[2013/06/05 03:09:28 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl[2013/06/05 03:09:28 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat[2013/06/05 03:09:28 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat[2013/06/05 03:09:28 | 001,054,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe[2013/06/05 03:09:28 | 000,905,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll[2013/06/05 03:09:28 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll[2013/06/05 03:09:28 | 000,762,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll[2013/06/05 03:09:28 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll[2013/06/05 03:09:28 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll[2013/06/05 03:09:28 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll[2013/06/05 03:09:28 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll[2013/06/05 03:09:28 | 000,599,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll[2013/06/05 03:09:28 | 000,526,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll[2013/06/05 03:09:28 | 000,452,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll[2013/06/05 03:09:28 | 000,441,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec[2013/06/05 03:09:28 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll[2013/06/05 03:09:28 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec[2013/06/05 03:09:28 | 000,281,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll[2013/06/05 03:09:28 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll[2013/06/05 03:09:28 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll[2013/06/05 03:09:28 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll[2013/06/05 03:09:28 | 000,216,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll[2013/06/05 03:09:28 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll[2013/06/05 03:09:28 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll[2013/06/05 03:09:28 | 000,173,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe[2013/06/05 03:09:28 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe[2013/06/05 03:09:28 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll[2013/06/05 03:09:28 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe[2013/06/05 03:09:28 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll[2013/06/05 03:09:28 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe[2013/06/05 03:09:28 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe[2013/06/05 03:09:28 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe[2013/06/05 03:09:28 | 000,136,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll[2013/06/05 03:09:28 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll[2013/06/05 03:09:28 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll[2013/06/05 03:09:28 | 000,125,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll[2013/06/05 03:09:28 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll[2013/06/05 03:09:28 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll[2013/06/05 03:09:28 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll[2013/06/05 03:09:28 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll[2013/06/05 03:09:28 | 000,097,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll[2013/06/05 03:09:28 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe[2013/06/05 03:09:28 | 000,089,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe[2013/06/05 03:09:28 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll[2013/06/05 03:09:28 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll[2013/06/05 03:09:28 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll[2013/06/05 03:09:28 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx[2013/06/05 03:09:28 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe[2013/06/05 03:09:28 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe[2013/06/05 03:09:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll[2013/06/05 03:09:28 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll[2013/06/05 03:09:28 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll[2013/06/05 03:09:28 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx[2013/06/05 03:09:28 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll[2013/06/05 03:09:28 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll[2013/06/05 03:09:28 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe[2013/06/05 03:09:28 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll[2013/06/05 03:09:28 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll[2013/06/05 03:09:28 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll[2013/06/05 03:09:28 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll[2013/06/05 03:09:28 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll[2013/06/05 03:09:28 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll[2013/06/05 03:09:28 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf[2013/06/05 03:09:28 | 000,025,185 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf[2013/06/05 03:09:28 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll[2013/06/05 03:09:28 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe[2013/06/05 03:09:28 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe[2013/06/05 03:09:28 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe[2013/06/05 03:01:47 | 003,928,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll[2013/06/05 03:01:47 | 002,776,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll[2013/06/05 03:01:47 | 002,565,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll[2013/06/05 03:01:47 | 002,284,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll[2013/06/05 03:01:47 | 001,887,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll[2013/06/05 03:01:47 | 001,682,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll[2013/06/05 03:01:47 | 001,643,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll[2013/06/05 03:01:47 | 001,504,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll[2013/06/05 03:01:47 | 001,424,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll[2013/06/05 03:01:47 | 001,238,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll[2013/06/05 03:01:47 | 001,158,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll[2013/06/05 03:01:47 | 000,648,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll[2013/06/05 03:01:47 | 000,522,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll[2013/06/05 03:01:47 | 000,465,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll[2013/06/05 03:01:47 | 000,417,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll[2013/06/05 03:01:47 | 000,364,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll[2013/06/05 03:01:47 | 000,363,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll[2013/06/05 03:01:47 | 000,333,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll[2013/06/05 03:01:47 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll[2013/06/05 03:01:47 | 000,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll[2013/06/05 03:01:47 | 000,221,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll[2013/06/05 03:01:47 | 000,194,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll[2013/06/05 03:01:47 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll[2013/06/05 03:01:47 | 000,010,752 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll[2013/06/05 03:01:47 | 000,010,752 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll[2013/06/05 03:01:47 | 000,009,728 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll[2013/06/05 03:01:47 | 000,009,728 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll[2013/06/05 03:01:47 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll[2013/06/05 03:01:47 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll[2013/06/05 03:01:47 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll[2013/06/05 03:01:47 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll[2013/06/05 03:01:47 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll[2013/06/05 03:01:47 | 000,002,560 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll[2013/06/05 03:01:47 | 000,002,560 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll[2013/05/20 14:00:27 | 000,034,799 | ---- | M] () -- C:\Users\THMark\Documents\PSYCHOLOGY%20100%20EXAM%203%20STUDY%20GUIDE.pdf0.pdf[2013/05/17 23:21:40 | 000,055,915 | ---- | M] () -- C:\Users\THMark\Documents\Retainer Milan---1.pdf[2013/05/16 03:26:07 | 005,039,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ][1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]========== Files Created - No Company Name ==========[2013/06/11 22:33:23 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe[2013/06/11 22:33:23 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe[2013/06/11 22:33:23 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe[2013/06/11 22:33:23 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe[2013/06/11 22:33:23 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe[2013/06/11 18:32:22 | 000,000,912 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000UA.job[2013/06/11 18:32:22 | 000,000,860 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4050476716-2494318647-2019036779-1000Core.job[2013/06/11 17:58:55 | 671,780,163 | ---- | C] () -- C:\Windows\MEMORY.DMP[2013/06/05 03:09:28 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf[2013/06/05 03:09:28 | 000,025,185 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf[2013/05/20 14:00:26 | 000,034,799 | ---- | C] () -- C:\Users\THMark\Documents\PSYCHOLOGY%20100%20EXAM%203%20STUDY%20GUIDE.pdf0.pdf[2013/05/17 23:21:40 | 000,055,915 | ---- | C] () -- C:\Users\THMark\Documents\Retainer Milan---1.pdf[2013/01/27 11:54:11 | 000,071,885 | ---- | C] () -- C:\Users\THMark\final_bstSnapshot_47597.jpg[2013/01/27 11:54:10 | 000,066,541 | ---- | C] () -- C:\Users\THMark\final_bstSnapshot_37789.jpg[2013/01/10 01:33:06 | 000,000,094 | ---- | C] () -- C:\Users\THMark\AppData\Local\fusioncache.dat[2012/09/07 23:45:35 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe[2012/06/10 11:50:27 | 000,281,120 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe[2012/06/10 11:50:21 | 002,250,024 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe[2012/06/10 11:50:21 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe[2012/02/02 11:24:20 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini[2012/01/17 01:15:40 | 000,003,584 | ---- | C] () -- C:\Users\THMark\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2011/12/30 14:37:37 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat[2011/10/27 23:18:39 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll[2011/10/27 23:18:39 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini[2011/10/27 23:18:38 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll[2011/10/27 23:18:38 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll[2011/10/27 23:18:38 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll[2011/09/28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat[2011/09/06 10:03:54 | 000,007,605 | ---- | C] () -- C:\Users\THMark\AppData\Local\resmon.resmoncfg[2011/07/29 13:02:11 | 000,000,468 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat[2011/07/27 19:04:08 | 000,001,770 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat[2011/07/27 17:51:35 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI[2011/07/27 12:33:30 | 000,000,028 | ---- | C] () -- C:\Windows\MyActiveX.INI[2011/07/26 20:19:01 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat[2011/07/25 00:13:38 | 000,794,694 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI[2011/07/24 14:24:59 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI[2011/07/24 14:24:59 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD2040.DAT[2011/07/24 11:05:18 | 000,024,576 | R--- | C] () -- C:\Windows\SysWow64\AsIO.dll[2011/07/24 11:05:18 | 000,013,440 | R--- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys[2011/07/24 11:05:15 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys[2011/07/24 11:05:15 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys[2011/07/24 11:00:12 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini[2011/07/24 11:00:06 | 000,035,593 | ---- | C] () -- C:\Windows\Ascd_tmp.ini========== ZeroAccess Check ==========[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32][HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32][HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64"" = C:\Windows\SysNative\shell32.dll -- [2013/02/26 22:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]"" = %SystemRoot%\system32\shell32.dll -- [2013/02/26 21:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Both[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]< End of report > The ESET didn't record any logs after running. too much time consuming to run again Link to post Share on other sites More sharing options...
D-FRED-BROWN Posted June 12, 2013 ID:690305 Share Posted June 12, 2013 ----------Step 1----------------We need to run an OTL FixPlease reopen on your desktop.Copy and Paste the following code into the textbox.:OTL[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32][HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32][HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64"" = C:\Windows\SysNative\shell32.dll -- [2013/02/26 22:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]"" = %SystemRoot%\system32\shell32.dll -- [2013/02/26 21:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Apartment[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Free[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)"ThreadingModel" = Both[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32][1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ][1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]:Commands[purity][emptytemp][emptyjava][emptyflash][Reboot]Push OTL may ask to reboot the machine. Please do so if asked.Click the OK button.A report will open. Copy and Paste that report in your next reply.----------Step 2----------------Instructions for DELETE:Close all open programs and internet browsers.Double click on adwcleaner.exe to run the tool.Click on Delete.Confirm each time with Ok.You will be prompted to restart your computer. A text file will open after the restart.Please post the contents of that logfile with your next reply.You can find the logfile at C:\AdwCleaner[s1].txt as well.Afterwards, please reboot the computer.----------Step 3----------------Please post the OTL and AdwCleaner reports in your next reply. How are things running now? Link to post Share on other sites More sharing options...
dnahunter Posted June 13, 2013 Author ID:690683 Share Posted June 13, 2013 All processes killed========== OTL ==========C:\Windows\assembly\Desktop.ini moved successfully.File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.C:\Windows\SysWow64\ConduitEngine.tmp deleted successfully.C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP\WiseCustomCalla.dll deleted successfully.C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP folder deleted successfully.========== COMMANDS ==========[EMPTYTEMP]User: All UsersUser: Default->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 67 bytes->Flash cache emptied: 56468 bytesUser: Default User->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes->Flash cache emptied: 0 bytesUser: hedev->Temp folder emptied: 0 bytesUser: Public->Temp folder emptied: 0 bytesUser: THMark->Temp folder emptied: 172182 bytes->Temporary Internet Files folder emptied: 138927269 bytes->Java cache emptied: 43748477 bytes->FireFox cache emptied: 106986107 bytes->Flash cache emptied: 56979 bytesUser: UpdatusUser->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytes%systemdrive% .tmp files removed: 0 bytes%systemroot% .tmp files removed: 0 bytes%systemroot%\System32 .tmp files removed: 0 bytes%systemroot%\System32 (64bit) .tmp files removed: 0 bytes%systemroot%\System32\drivers .tmp files removed: 0 bytesWindows Temp folder emptied: 271574 bytes%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 55807975 bytesRecycleBin emptied: 0 bytesTotal Files Cleaned = 330.00 mb[EMPTYJAVA]User: All UsersUser: DefaultUser: Default UserUser: hedevUser: PublicUser: THMark->Java cache emptied: 0 bytesUser: UpdatusUserTotal Java Files Cleaned = 0.00 mb[EMPTYFLASH]User: All UsersUser: Default->Flash cache emptied: 0 bytesUser: Default User->Flash cache emptied: 0 bytesUser: hedevUser: PublicUser: THMark->Flash cache emptied: 0 bytesUser: UpdatusUserTotal Flash Files Cleaned = 0.00 mbOTL by OldTimer - Version 3.2.69.0 log created on 06132013_083826Files\Folders moved on Reboot...C:\Users\THMark\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.C:\Users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\7A7E08C8-3FF5-45F2-873D-A84D669DC82F.dat moved successfully.C:\Users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S73A5G2S\index[1].htm moved successfully.C:\Users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HLXO2HC7\fastbutton[1].htm moved successfully.C:\Users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7DLPTDE\EFpQQyG9GqCrobXxL-KRMWzklk6MJbhg7BmBP42CjCQ[1].eot moved successfully.C:\Users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D7DLPTDE\s-BiyweUPV0v-yRb-cjciFQlYEbsez9cZjKsNMjLOwM[1].eot moved successfully.C:\Users\THMark\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.PendingFileRenameOperations files...Registry entries deleted on Reboot...# AdwCleaner v2.303 - Logfile created 06/13/2013 at 08:49:44# Updated 08/06/2013 by Xplode# Operating system : Windows 7 Professional Service Pack 1 (64 bits)# User : THMark - THMARK-PC# Boot Mode : Normal# Running from : C:\Users\THMark\Desktop\AdwCleaner.exe# Option [Delete]***** [services] *****Stopped & Deleted : DvmMDES***** [Files / Folders] *****File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xmlFile Deleted : C:\user.jsFile Deleted : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\BrowserMngr_extensions.sqliteFile Deleted : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\browsermngr_prefs.jsFile Deleted : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\searchplugins\BabylonMngr.xmlFolder Deleted : C:\Program Files (x86)\1ClickDownloadFolder Deleted : C:\ProgramData\BabylonFolder Deleted : C:\ProgramData\boost_interprocessFolder Deleted : C:\ProgramData\WeCareReminderFolder Deleted : C:\Users\THMark\AppData\Local\ConduitFolder Deleted : C:\Users\THMark\AppData\LocalLow\BabylonToolbarFolder Deleted : C:\Users\THMark\AppData\LocalLow\ConduitFolder Deleted : C:\Users\THMark\AppData\LocalLow\PriceGongFolder Deleted : C:\Users\THMark\AppData\Roaming\BabylonFolder Deleted : C:\Users\THMark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser ManagerFolder Deleted : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\extensions\wecarereminder@bryanFolder Deleted : C:\Users\THMark\AppData\Roaming\OpenCandy***** [Registry] *****Key Deleted : HKCU\Software\1ClickDownloadKey Deleted : HKCU\Software\AppDataLow\Software\PriceGongKey Deleted : HKCU\Software\DataMngr_ToolbarKey Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Deleted : HKCU\Software\wecarereminderKey Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}Key Deleted : HKLM\Software\BabylonKey Deleted : HKLM\Software\BrowserMngrKey Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLLKey Deleted : HKLM\SOFTWARE\Classes\Conduit.EngineKey Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminderKey Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1Key Deleted : HKLM\SOFTWARE\Classes\Prod.capKey Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2790392Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}Key Deleted : HKLM\Software\ConduitKey Deleted : HKLM\Software\DataMngrKey Deleted : HKLM\Software\DeviceVMKey Deleted : HKLM\Software\Freeze.comKey Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCSKey Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99AD9D6D-A456-49EE-8360-F22EE7AA1272}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1C888195-0160-4883-91B7-294C0CE2F277}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{99ACA0F7-D864-45CB-8C40-FD42A077E7CA}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E65F40C8-3CEB-47C2-9E01-BF73323DF4E7}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [browserMngr Start Page]Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [browserMngrDefaultScope]***** [internet Browsers] *****-\\ Internet Explorer v10.0.9200.16611Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=113933&tt=120812_bandext_3212_1&babsrc=NT_ss&mntrId=1e666e7c00000000000002004c4f4f50 --> hxxp://www.google.com-\\ Mozilla Firefox v20.0.1 (en-US)File : C:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\prefs.jsC:\Users\THMark\AppData\Roaming\Mozilla\Firefox\Profiles\0qllv7u0.default\user.js ... Deleted !Deleted : user_pref("browser.search.defaultenginename", "Search the web (Babylon)");Deleted : user_pref("browser.search.order.1", "Search the web (Babylon)");Deleted : user_pref("browser.search.selectedEngine", "Search the web (Babylon)");Deleted : user_pref("extensions.BabylonToolbar.admin", false);Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);Deleted : user_pref("extensions.BabylonToolbar.id", "1e666e7c00000000000002004c4f4f50");Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15564");Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://www.google.com/search?babsrc=TB_ggl&q=");Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.6.4.6");Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.6.4.6");Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=113933&tt=120812_bandext_3212_1");Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.4.615:48:43");-\\ Google Chrome v [unable to get version]File : C:\Users\THMark\AppData\Local\Google\Chrome\User Data\Default\Preferences[OK] File is clean.*************************AdwCleaner[s1].txt - [8506 octets] - [13/06/2013 08:49:44]########## EOF - C:\AdwCleaner[s1].txt - [8566 octets] ########## everything is working fine now. Thank You. Link to post Share on other sites More sharing options...
D-FRED-BROWN Posted June 13, 2013 ID:690773 Share Posted June 13, 2013 Judging by your last few logs, I'd say your system is clean. Before we move on, please take the time to install the following updates. Program updates are a critical part of your computer's safety net, as outdated applications leave you vulnerable to malware.---------I see you have User Accounts Control (UAC) disabled.This is an important security feature which helps prevent malware and other unwanted software from being installed on your computer.I strongly suggest you keep it enabled. See this link for instructions on how to enable it: http://windows.microsoft.com/en-US/windows-vista/Turn-User-Account-Control-on-or-off---------Firefox is out of date. Using an outdated version of a web browser leaves you extremely vulnerable to malware!Please visit Mozilla site and update it to the latest version.---------Your version of Adobe Reader is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Adobe components and update:Download the latest version of Adobe Reader and save it to your desktop.Uncheck the "Free McAfee Security plan Plus" option or any other Toolbar you are offeredClick the download button at the bottom.If you use Internet Explorer and do not wish to install the ActiveX element, simply click on the click here to download link on the next page.Remove all older version of Adobe Reader: Go to Add/remove and uninstall all versions of Adobe Reader, Acrobat Reader and Adobe Acrobat.If you are unsure of how to use Add or Remove Programs, the please see this tutorial:How To Remove An Installed Program From Your ComputerThen from your desktop double-click on Adobe Reader to install the newest version.If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.When the "Adobe Setup - Welcome" window opens, click the Install > button.If offered to install a Toolbar, just uncheck the box before continuing unless you want it.---------Upgrade Java : (64 bits)Download the latest version of Java SE Runtime Environment (JRE) JRE 7 Update 3 .Under the JAVA Platform Standard Edition, click the "Download JRE" button to the right.Check the box that says: "Accept License Agreement.".Click on the link to download Windows Offline Installation 64 bit ( jre-7u3-windows-x64.exe) and save it to your desktop. Do NOT use the Sun Download Manager..Close any programs you may have running - especially your web browser.Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.Check any item with Java Runtime Environment (JRE or J2SE) in the name.Click the Remove or Change/Remove button.Repeat as many times as necessary to remove each Java version.Reboot your computer once all Java components are removed.Then from your desktop double-click on the download to install the newest version.(Vista or Win 7 users, right click on the jre-7u3-windows-x64.exe and select "Run as an Administrator.")---------Please let me know how the updates went, as failed updates may be dule to malware. Link to post Share on other sites More sharing options...
D-FRED-BROWN Posted June 19, 2013 ID:693217 Share Posted June 19, 2013 Are you still with me? Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted June 25, 2013 Root Admin ID:695397 Share Posted June 25, 2013 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts