
%WINDIR%\SWReg null query "HKEY_USERS\S-1-5-21-1043806178-727526901-2694514658-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8F0FB132-8310-1A66-EF0A-0BD8D873EC9A}" /s >> C:\exportnulls.txt
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Logfile of random's system information tool 1.09 (written by random/random) Run by Chris Reaper at 2011-10-31 19:44:49 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 94 GB (32%) free of 290 GB Total RAM: 4061 MB (40% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 7:45:24 PM, on 10/31/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CNRpc.exe C:\Program Files (x86)\Brownie\brpjp04a.exe C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe C:\Windows\AsScrPro.exe C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe C:\Program Files (x86)\iTunes\iTunes.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Chris Reaper\Desktop\RSIT.exe C:\Program Files (x86)\trend micro\Chris Reaper.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe Autorun O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Chris Reaper\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O8 - Extra context menu item: Se&nd to OneNote - res:///105 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: http://*.cinemanow.com O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing) O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe O23 - Service: Bradford Persistent Agent Service (BNPagent) - Bradford Networks - C:\Program Files (x86)\Bradford Networks\Persistent Agent\bndaemon.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe O23 - Service: CinemaNow Service - CinemaNow, Inc. - C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: FastBootAgent - ASUSTeK Computer Inc. - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: Lexar Secure II (LxrSII1s) - Lexar Media, Inc. - C:\Windows\system32\LxrSII1s.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: Nortel VPN Client (NvcSvcMgr) - Nortel Networks - C:\Program Files (x86)\Nortel\Nortel VPN Client\NvcSvcMgr.exe O23 - Service: Livescribe Pulse Smartpen Service (PenCommService) - Livescribe - C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~2\PHAROS~1\Core\CTskMstr.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 14065 bytes ======Scheduled tasks folder====== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job =========Mozilla firefox========= ProfilePath - C:\Users\Chris Reaper\AppData\Roaming\Mozilla\Firefox\Profiles\n5hn24af.default prefs.js - "browser.search.useDBForOrder" - true prefs.js - "browser.startup.homepage" - "http://www.google.com/" prefs.js - "extensions.enabledItems" - "{c2f863cd-0429-48c7-bb54-db756a951760}:5.96.10.6760, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6, {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.5.5, {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.9.5, [email protected]:1.2.3, {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.10, {258735dc-6743-4805-95fc-f95941fffdad}:1.3.6, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.01, {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, [email protected]:2.1.1, {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323, {3EC9C995-8072-4fc0-953E-4F30620D17F3}:2.0.0.4, {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9, {5e5ab302-7f65-44cd-8211-c1d4caaccea3}:3.3.3.2, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94, {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94, [email protected]:3.3.3.2, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17" prefs.js - "keyword.URL" - "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50-ff-aim-ab-en-us&query=" "{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video "{6904342A-8307-11DF-A508-4AE2DFD72085}"=C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 10.1 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=] "Description"=iTunes Detector Plug-in "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0] "Description"= "Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0] "Description"=DivX Plus Web Player "Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0] "Description"=DivX® Player Plugin for VOD Content "Path"=C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] "Description"=DivX VOD Helper Plug-in "Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin] "Description"=Google Earth in your browser "Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3] "Description"=Office Live Update v1.3 "Path"=C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5] "Description"=Office Live Update v1.5 "Path"=C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0] "Description"=BlackBerry Web Software Loading Helper Plug-In for Mozilla browsers "Path"=C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@wolfram.com/Mathematica] "Description"=Wolfram Mathematica Plug-in "Path"=C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.0.1802959\npmathplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll C:\Program Files (x86)\Mozilla Firefox\extensions\ {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} {972ce4c6-7e08-4474-a285-3208198ce6fd} {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} C:\Program Files (x86)\Mozilla Firefox\components\ binary.manifest browsercomps.dll npCouponPrinter.xpt nsIQTScriptablePlugin.xpt C:\Program Files (x86)\Mozilla Firefox\plugins\ np-mswmp.dll npCouponPrinter.dll npdeployJava1.dll npDivxPlayerPlugin.dll npMozCouponPrinter.dll nppdf32.dll npqtplugin.dll npqtplugin2.dll npqtplugin3.dll npqtplugin4.dll npqtplugin5.dll npqtplugin6.dll npqtplugin7.dll nsIDivxPlayerPlugin.xpt QuickTimePlugin.class WMP Firefox Plugin License.rtf WMP Firefox Plugin RelNotes.txt C:\Program Files (x86)\Mozilla Firefox\searchplugins\ amazondotcom.xml bing.xml eBay.xml google.xml wikipedia.xml yahoo.xml C:\Users\Chris Reaper\AppData\Roaming\Mozilla\Firefox\Profiles\n5hn24af.default\extensions\ [email protected] [email protected] {258735dc-6743-4805-95fc-f95941fffdad} {3EC9C995-8072-4fc0-953E-4F30620D17F3} {6AC85730-7D0F-4de0-B3FA-21142DD85326} {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} {ACAA314B-EEBA-48e4-AD47-84E31C44796C} {c45c406e-ab73-11d8-be73-000a95be3b12} {e4a8a97b-f2ed-450b-b12d-ee082ba24781} {F8A55C97-3DB6-4961-A81D-0DE0080E53CB} C:\Users\Chris Reaper\AppData\Roaming\Mozilla\Firefox\Profiles\n5hn24af.default\searchplugins\ aim-search.xml daemon-search.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}] DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-07 3118976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}] DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-07 3118976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}] Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2011-06-12 4221328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}] Bing Bar BHO - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll [2010-08-24 612616] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-09-22 42272] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {8dcb7100-df86-4384-8842-8fa844297b3f} - @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll [2010-08-24 612616] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920] "avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2011-10-11 258512] "BrStsWnd"=C:\Program Files (x86)\Brownie\BrstsW64.exe [2009-08-19 3695928] "APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240] "iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-10-09 421736] "Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608] "QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-09-05 35736] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe [2009-10-04 72248] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [2009-10-04 3054136] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" C:\Windows\SysWOW64\guard32.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWow64\webcheck.dll [2011-04-10 203776] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2011-06-12 4221328] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=0 "ConsentPromptBehaviorUser"=3 "EnableLUA"=0 "EnableUIADesktopToggle"=0 "PromptOnSecureDesktop"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "AllowLegacyWebView"=1 "AllowUnhashedWebView"=1 "NoDrives"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm "vidc.cvid"=iccvid.dll "msacm.siren"=sirenacm.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "vidc.ffds"=ff_vfw.dll "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux2"=wdmaud.drv "vidc.DIVX"=DivX.dll "vidc.yv12"=DivX.dll "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "aux3"=wdmaud.drv "vidc.iv50"=ir50_32.dll "wave4"=wdmaud.drv "mixer4"=wdmaud.drv "midi4"=wdmaud.drv "wave5"=wdmaud.drv "mixer5"=wdmaud.drv "midi5"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .txt - open - ======List of files/folders created in the last 3 months====== 2011-10-31 19:44:49 ----D---- C:\rsit 2011-10-28 18:49:48 ----D---- C:\ProgramData\PreEmptive Solutions 2011-10-28 18:20:21 ----D---- C:\ProgramData\VS 2011-10-28 17:59:06 ----A---- C:\Windows\SysWOW64\shell32.dll 2011-10-28 13:53:30 ----D---- C:\Program Files (x86)\QuickTime 2011-10-25 20:00:12 ----A---- C:\exportnulls.txt 2011-10-19 09:43:05 ----SHD---- C:\$RECYCLE.BIN 2011-10-18 19:46:59 ----A---- C:\TDSSKiller.2.6.10.0_18.10.2011_19.46.59_log.txt 2011-10-16 20:04:16 ----A---- C:\ComboFix.txt 2011-10-16 19:37:33 ----A---- C:\Windows\zip.exe 2011-10-16 19:37:33 ----A---- C:\Windows\SWSC.exe 2011-10-16 19:37:33 ----A---- C:\Windows\SWREG.exe 2011-10-16 19:37:33 ----A---- C:\Windows\sed.exe 2011-10-16 19:37:33 ----A---- C:\Windows\PEV.exe 2011-10-16 19:37:33 ----A---- C:\Windows\NIRCMD.exe 2011-10-16 19:37:33 ----A---- C:\Windows\MBR.exe 2011-10-16 19:37:33 ----A---- C:\Windows\grep.exe 2011-10-16 19:37:24 ----D---- C:\Windows\ERDNT 2011-10-16 19:37:22 ----D---- C:\username123 2011-10-16 19:36:17 ----D---- C:\Qoobox 2011-10-14 08:56:35 ----A---- C:\Windows\SysWOW64\javaws.exe 2011-10-14 08:56:35 ----A---- C:\Windows\SysWOW64\javaw.exe 2011-10-14 08:56:35 ----A---- C:\Windows\SysWOW64\java.exe 2011-10-14 07:42:29 ----A---- C:\Windows\SysWOW64\mshtmled.dll 2011-10-14 07:42:28 ----A---- C:\Windows\SysWOW64\url.dll 2011-10-14 07:42:28 ----A---- C:\Windows\SysWOW64\iertutil.dll 2011-10-14 07:42:27 ----A---- C:\Windows\SysWOW64\urlmon.dll 2011-10-14 07:42:25 ----A---- C:\Windows\SysWOW64\wininet.dll 2011-10-14 07:42:24 ----A---- C:\Windows\SysWOW64\ieui.dll 2011-10-14 07:42:22 ----A---- C:\Windows\SysWOW64\jscript9.dll 2011-10-14 07:42:22 ----A---- C:\Windows\SysWOW64\jscript.dll 2011-10-14 07:42:21 ----A---- C:\Windows\SysWOW64\jsproxy.dll 2011-10-14 07:42:19 ----A---- C:\Windows\SysWOW64\mshtml.dll 2011-10-14 07:42:15 ----A---- C:\Windows\SysWOW64\ieframe.dll 2011-10-13 12:35:45 ----A---- C:\Windows\SysWOW64\psisdecd.dll 2011-10-13 12:35:35 ----A---- C:\Windows\SysWOW64\oleaut32.dll 2011-10-13 12:35:35 ----A---- C:\Windows\SysWOW64\oleacc.dll 2011-10-13 08:33:40 ----D---- C:\Program Files (x86)\iTunes 2011-10-13 08:30:05 ----D---- C:\Program Files (x86)\Bonjour 2011-10-11 12:54:43 ----A---- C:\Windows\BRVIDEO.INI 2011-10-11 12:54:43 ----A---- C:\Windows\brmx2001.ini 2011-10-11 12:54:42 -------- C:\Windows\SysWOW64\brlmw03a.ini 2011-10-11 12:54:42 -------- C:\Windows\SysWOW64\brlmw03a.dll 2011-10-11 12:54:40 ----D---- C:\Program Files (x86)\Brownie 2011-10-11 12:54:40 ----A---- C:\Windows\HL-2140.INI 2011-10-11 12:53:19 ----A---- C:\Windows\SysWOW64\BD2140.DAT 2011-10-11 12:53:19 ----A---- C:\Windows\BRWMARK.INI 2011-10-11 12:53:11 ----D---- C:\Program Files (x86)\Brother 2011-10-11 12:53:11 ----A---- C:\Windows\SysWOW64\BRRBTOOL.EXE 2011-10-11 12:53:11 ----A---- C:\Windows\SysWOW64\BRLM03A.DLL 2011-10-11 12:53:11 -------- C:\Windows\SysWOW64\Pdrvinst.dll 2011-10-11 12:53:11 -------- C:\Windows\SysWOW64\BROSNMP.DLL 2011-10-11 12:52:48 ----A---- C:\Windows\Brownie.ini 2011-10-11 09:37:10 ----D---- C:\Users\Chris Reaper\AppData\Roaming\Avira 2011-10-11 09:35:12 ----D---- C:\ProgramData\Avira 2011-10-11 09:35:12 ----D---- C:\Program Files (x86)\Avira 2011-10-08 09:31:59 ----D---- C:\Program Files (x86)\Google 2011-10-08 09:06:13 ----AH---- C:\Windows\SysWOW64\mlfcache.dat 2011-10-03 17:54:37 ----D---- C:\Program Files (x86)\Trend Micro 2011-10-02 22:12:34 ----D---- C:\Users\Chris Reaper\AppData\Roaming\PrimoPDF 2011-10-02 22:10:43 ----D---- C:\Users\Chris Reaper\AppData\Roaming\OpenCandy 2011-10-02 22:10:41 ----D---- C:\Program Files (x86)\Nitro PDF 2011-09-28 14:35:24 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services 2011-09-28 14:28:05 ----D---- C:\Program Files (x86)\Microsoft ASP.NET 2011-09-28 14:27:54 ----D---- C:\Program Files (x86)\IIS 2011-09-28 14:17:14 ----D---- C:\Program Files (x86)\Common Files\Designer 2011-09-28 14:16:40 ----D---- C:\Windows\SysWOW64\1033 2011-09-28 14:15:00 ----D---- C:\Program Files (x86)\Microsoft F# 2011-09-28 14:15:00 ----D---- C:\Program Files (x86)\HTML Help Workshop 2011-09-28 14:14:59 ----D---- C:\Program Files (x86)\Common Files\Merge Modules 2011-09-28 14:06:43 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 9.0 2011-09-28 14:05:51 ----D---- C:\Program Files (x86)\Microsoft SDKs 2011-09-23 12:27:13 ----D---- C:\ProgramData\Nortel 2011-09-23 12:27:12 ----D---- C:\Program Files (x86)\Nortel 2011-09-23 12:26:43 ----A---- C:\Windows\SysWOW64\MadCHook.dll 2011-09-23 12:26:31 ----D---- C:\Program Files (x86)\PharosSystems 2011-09-23 12:25:55 ----D---- C:\Program Files (x86)\Pharos 2011-09-23 12:25:25 ----D---- C:\Temp 2011-09-22 13:54:54 ----D---- C:\Program Files (x86)\Application Verifier 2011-09-22 13:53:15 ----D---- C:\Windows\symbols 2011-09-22 13:53:10 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 10.0 2011-09-19 19:06:31 ----D---- C:\Program Files (x86)\ASUS Bluetooth Suite 2011-09-19 18:27:54 ----A---- C:\Windows\SysWOW64\LxrSII1s.exe 2011-09-19 18:27:52 ----A---- C:\Windows\SysWOW64\LxrSII1.dll 2011-09-07 13:57:53 ----D---- C:\Users\Chris Reaper\AppData\Roaming\Mathematica 2011-09-07 11:57:30 ----D---- C:\Program Files (x86)\Common Files\Wolfram Research 2011-09-07 11:57:30 ----D---- C:\Program Files (x86)\Common Files\ResearchSoft 2011-09-07 11:57:29 ----D---- C:\ProgramData\Mathematica 2011-09-07 11:48:51 ----A---- C:\Windows\SysWOW64\mlmodule32.dll 2011-09-07 11:48:51 ----A---- C:\Windows\SysWOW64\ml32i3.dll 2011-09-07 11:48:50 ----A---- C:\Windows\SysWOW64\ml32i2.dll 2011-09-07 11:48:50 ----A---- C:\Windows\SysWOW64\ml32i1.dll 2011-08-30 23:05:04 ----A---- C:\Windows\SysWOW64\jdns_sd.dll 2011-08-30 23:05:04 ----A---- C:\Windows\SysWOW64\dnssdX.dll 2011-08-30 23:05:04 ----A---- C:\Windows\SysWOW64\dns-sd.exe 2011-08-30 23:05:04 ----A---- C:\Windows\SysWOW64\dnssd.dll 2011-08-28 21:23:16 ----D---- C:\Program Files (x86)\Maple 15 2011-08-23 23:14:03 ----A---- C:\Windows\SysWOW64\tzres.dll 2011-08-23 11:47:04 ----D---- C:\Program Files (x86)\Microsoft SQL Server 2011-08-23 11:44:28 ----D---- C:\BcmSqlSetup 2011-08-23 11:02:17 ----D---- C:\Program Files (x86)\Microsoft Lync 2011-08-23 10:38:47 ----D---- C:\Windows\PCHEALTH 2011-08-23 10:36:35 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8 2011-08-23 10:35:15 ----D---- C:\Program Files (x86)\Microsoft Analysis Services 2011-08-23 10:33:31 ----RHD---- C:\MSOCache 2011-08-22 21:51:39 ----D---- C:\Users\Chris Reaper\AppData\Roaming\e-academy Inc 2011-08-21 13:07:51 ----D---- C:\Program Files (x86)\MSN Toolbar 2011-08-21 13:07:19 ----D---- C:\Users\Chris Reaper\AppData\Roaming\HpUpdate 2011-08-21 13:05:49 ----D---- C:\ProgramData\HP 2011-08-21 13:05:43 ----D---- C:\Program Files (x86)\HP 2011-08-12 22:54:28 ----D---- C:\Program Files (x86)\Microsoft Security Client 2011-08-10 16:23:06 ----A---- C:\Windows\SysWOW64\xmllite.dll 2011-08-10 16:23:03 ----A---- C:\Windows\SysWOW64\odbcjt32.dll 2011-08-10 16:23:03 ----A---- C:\Windows\SysWOW64\odbccr32.dll 2011-08-10 16:23:02 ----A---- C:\Windows\SysWOW64\odbctrac.dll 2011-08-10 16:23:02 ----A---- C:\Windows\SysWOW64\odbccu32.dll 2011-08-10 16:23:02 ----A---- C:\Windows\SysWOW64\odbccp32.dll 2011-08-10 16:22:27 ----A---- C:\Windows\SysWOW64\setup16.exe 2011-08-10 16:22:26 ----A---- C:\Windows\SysWOW64\wow32.dll 2011-08-10 16:22:26 ----A---- C:\Windows\SysWOW64\ntvdm64.dll 2011-08-10 16:22:26 ----A---- C:\Windows\SysWOW64\KernelBase.dll 2011-08-10 16:22:26 ----A---- C:\Windows\SysWOW64\kernel32.dll 2011-08-10 16:22:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2011-08-10 16:22:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2011-08-10 16:22:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2011-08-10 16:22:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2011-08-10 16:22:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2011-08-10 16:22:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2011-08-10 16:22:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2011-08-10 16:22:24 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2011-08-10 16:22:24 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2011-08-10 16:22:24 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2011-08-10 16:22:24 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2011-08-10 16:22:23 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2011-08-10 16:22:23 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2011-08-10 16:22:23 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2011-08-10 16:22:23 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2011-08-10 16:22:23 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2011-08-10 16:22:23 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2011-08-10 16:22:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2011-08-10 16:22:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2011-08-10 16:22:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2011-08-10 16:22:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2011-08-10 16:22:21 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2011-08-10 16:22:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2011-08-10 16:22:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2011-08-10 16:22:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2011-08-10 16:22:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2011-08-10 16:22:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2011-08-10 16:22:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2011-08-10 16:22:19 ----A---- C:\Windows\SysWOW64\instnm.exe 2011-08-10 16:22:18 ----A---- C:\Windows\SysWOW64\user.exe 2011-08-10 16:22:11 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe 2011-08-10 16:22:10 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe 2011-08-10 15:56:45 ----D---- C:\Program Files (x86)\LynxMessenger 2011-08-10 15:56:43 ----D---- C:\Windows\Lynx 2011-08-10 11:12:59 ----D---- C:\ProgramData\Bradford Networks 2011-08-10 11:12:56 ----D---- C:\Program Files (x86)\Bradford Networks 2011-08-06 23:38:58 ----D---- C:\Users\Chris Reaper\AppData\Roaming\ManyCam 2011-08-06 23:38:03 ----D---- C:\Program Files (x86)\ManyCam ======List of files/folders modified in the last 3 months====== 2011-10-31 19:45:05 ----D---- C:\Windows\Temp 2011-10-31 19:44:51 ----D---- C:\Windows\Prefetch 2011-10-31 08:52:09 ----SHD---- C:\System Volume Information 2011-10-31 07:52:59 ----D---- C:\Windows\System32 2011-10-31 07:50:24 ----D---- C:\Windows\SysWOW64\drivers 2011-10-30 23:57:40 ----D---- C:\Users\Chris Reaper\AppData\Roaming\Skype 2011-10-30 22:30:21 ----D---- C:\Windows\Microsoft.NET 2011-10-30 22:26:59 ----RSD---- C:\Windows\assembly 2011-10-30 21:14:25 ----SHD---- C:\Windows\Installer 2011-10-30 21:14:25 ----D---- C:\Config.Msi 2011-10-28 20:56:01 ----D---- C:\Windows\winsxs 2011-10-28 20:51:56 ----D---- C:\Windows\SysWOW64 2011-10-28 18:49:48 ----D---- C:\ProgramData 2011-10-28 18:35:22 ----D---- C:\Program Files (x86)\Common Files\microsoft shared 2011-10-28 13:53:30 ----D---- C:\Program Files (x86) 2011-10-27 12:53:20 ----D---- C:\Windows\inf 2011-10-27 08:48:53 ----RD---- C:\Users 2011-10-26 07:58:12 ----D---- C:\Windows 2011-10-24 20:54:21 ----RSD---- C:\Windows\Fonts 2011-10-24 09:25:39 ----D---- C:\Program Files (x86)\JDownloader 2011-10-20 13:41:29 ----D---- C:\Users\Chris Reaper\AppData\Roaming\Notepad++ 2011-10-20 13:41:01 ----D---- C:\Windows\debug 2011-10-20 13:40:25 ----D---- C:\Program Files (x86)\CCleaner 2011-10-16 19:57:48 ----A---- C:\Windows\system.ini 2011-10-16 19:49:30 ----D---- C:\Windows\AppPatch 2011-10-16 19:49:24 ----D---- C:\Program Files (x86)\Common Files 2011-10-15 00:12:36 ----RD---- C:\Program Files (x86)\Skype 2011-10-14 23:56:58 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-10-14 11:57:57 ----D---- C:\Users\Chris Reaper\AppData\Roaming\Download Manager 2011-10-14 08:58:30 ----D---- C:\Program Files (x86)\Microsoft Silverlight 2011-10-14 08:57:29 ----D---- C:\Program Files (x86)\Internet Explorer 2011-10-14 08:57:28 ----D---- C:\Windows\SysWOW64\migration 2011-10-14 08:57:27 ----D---- C:\Windows\ehome 2011-10-14 08:56:27 ----D---- C:\Program Files (x86)\Java 2011-10-13 08:33:41 ----RD---- C:\Program Files 2011-10-13 08:33:40 ----D---- C:\Program Files (x86)\Common Files\Apple 2011-10-11 12:53:08 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2011-10-11 12:52:29 ----D---- C:\Program Files (x86)\Mozilla Firefox 2011-10-08 09:32:05 ----D---- C:\Windows\Tasks 2011-10-07 13:47:10 ----A---- C:\Windows\SysWOW64\guard32.dll 2011-10-03 20:47:01 ----D---- C:\Users\Chris Reaper\AppData\Roaming\DAEMON Tools Lite 2011-10-03 20:46:32 ----D---- C:\Windows\Panther 2011-10-03 17:15:26 ----D---- C:\Windows\pss 2011-10-02 23:02:05 ----D---- C:\Program Files (x86)\Mozilla Thunderbird 2011-10-02 09:55:51 ----D---- C:\ProgramData\Microsoft Help 2011-09-28 14:35:24 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2011-09-28 14:27:07 ----SD---- C:\Users\Chris Reaper\AppData\Roaming\Microsoft 2011-09-28 14:27:07 ----SD---- C:\ProgramData\Microsoft 2011-09-28 14:03:31 ----D---- C:\Program Files (x86)\Britannica 10.0 2011-09-25 10:48:54 ----D---- C:\Windows\Minidump 2011-09-22 13:44:43 ----D---- C:\Program Files (x86)\MSBuild 2011-09-06 23:06:01 ----A---- C:\Windows\win.ini 2011-08-24 20:33:47 ----D---- C:\Windows\rescache 2011-08-24 07:44:26 ----D---- C:\Windows\SysWOW64\en-US 2011-08-23 10:40:54 ----D---- C:\Windows\ShellNew 2011-08-23 10:38:47 ----D---- C:\Program Files (x86)\Microsoft.NET 2011-08-23 07:38:53 ----D---- C:\Program Files (x86)\Microsoft Office 2011-08-23 07:38:50 ----D---- C:\Program Files (x86)\Microsoft Works 2011-08-21 13:07:56 ----D---- C:\Program Files (x86)\Bing Bar Installer 2011-08-21 13:05:43 ----D---- C:\Windows\twain_32 2011-08-21 00:07:04 ----D---- C:\ProgramData\Skype 2011-08-12 22:54:32 ----A---- C:\Windows\SysWOW64\PerfStringBackup.INI 2011-08-08 18:09:58 ----D---- C:\Windows\Logs 2011-08-02 00:14:53 ----D---- C:\Users\Chris Reaper\AppData\Roaming\Hoyle Puzzle and Board Games ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AsDsm;AsDsm; C:\Windows\SysWOW64\drivers\AsDsm.sys [] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [] R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [] R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [] R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [] R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [] R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [] R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [] R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [] R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [] R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [] R2 adfs;adfs; C:\Windows\SysWOW64\drivers\adfs.sys [] R2 ASMMAP64;ASMMAP64; \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904] R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [] R2 LxrSII1d;Secure II Driver; \??\C:\Windows\System32\Drivers\LxrSII1d.sys [] R2 nvcwfpco;nvcwfpco; C:\Windows\system32\DRIVERS\nvcwfpco.sys [] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [] R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [] R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [] R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [] R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x64.sys [] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver; C:\Windows\system32\DRIVERS\ManyCam_x64.sys [] R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [] R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [] R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [] R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [] R3 NT_NvcA;Nortel VPN Adapter; C:\Windows\system32\DRIVERS\ntnvca.sys [] R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [] R3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [] R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [] R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [] R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [] S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [] S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [] S3 AthDfu;Atheros Valkyrie USB BootROM; C:\Windows\System32\Drivers\AthDfu.sys [] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [] S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [] S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [] S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [] S3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [] S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [] S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [] S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [] S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [] S3 catchme;catchme; \??\C:\username123\catchme.sys [] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [] S3 ivusb;Initio Driver for USB Default Controller; C:\Windows\system32\DRIVERS\ivusb.sys [] S3 PulseUsb;Livescribe Smartpen USB Driver; C:\Windows\system32\DRIVERS\PulseUsb.sys [] S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [] S3 RimUsb;BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [] S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [] S3 StarOpen;StarOpen; C:\Windows\SysWOW64\drivers\StarOpen.sys [] S3 TIEHDUSB;TI Core USB Driver; C:\Windows\system32\DRIVERS\tiehdusb.sys [] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [] S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [] S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [] S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [] S4 mchInjDrv;mchInjDrv; \??\C:\Windows\TEMP\mc2D2B9.tmp [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [] R2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [2011-10-11 342480] R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-11 86224] R2 AntiVirService;Avira Realtime Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-10-11 110032] R2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-10-11 463824] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-09 55144] R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [2009-06-15 84536] R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208] R2 BNPagent;Bradford Persistent Agent Service; C:\Program Files (x86)\Bradford Networks\Persistent Agent\bndaemon.exe [2011-03-07 3079960] R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184] R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168] R2 CinemaNow Service;CinemaNow Service; C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2009-06-11 127352] R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2011-10-07 2663568] R2 FastBootAgent;FastBootAgent; C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-23 306232] R2 LxrSII1s;Lexar Secure II; C:\Windows\system32\LxrSII1s.exe [2009-12-30 65536] R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784] R2 NvcSvcMgr;Nortel VPN Client; C:\Program Files (x86)\Nortel\Nortel VPN Client\NvcSvcMgr.exe [2009-10-05 615704] R2 PenCommService;Livescribe Pulse Smartpen Service; C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe [2011-05-19 468992] R2 Pharos Systems ComTaskMaster;Pharos Systems ComTaskMaster; C:\PROGRA~2\PHAROS~1\Core\CTskMstr.exe [2008-05-16 290816] R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [2006-12-19 81920] R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512] R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-04-22 92592] R3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280] R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-10-09 934760] R3 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-06-16 73728] R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272] R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-08 136176] S3 Adobe LM Service;Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-12-08 72704] S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840] S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-08 136176] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536] S3 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040] S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752] S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] -----------------EOF-----------------
:file C:\Program Files (x86)\Brownie\BrstsW64.exe C:\Windows\system32\DRIVERS\L1E62x64.sys C:\Windows\system32\DRIVERS\MarvinBus64.sys C:\Windows\system32\DRIVERS\ATK64AMD.sys c:\windows\system32\PSRA069F.DLL c:\windows\SysWow64\MadCHook.dll
[Unregister Dlls] [Registry - Safe List] < FireFox Settings [Prefs.js] > -> C:\Users\Chris Reaper\AppData\Roaming\Mozilla\FireFox\Profiles\n5hn24af.default\prefs.js YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 YN -> extensions.enabledItems -> [email protected]:3.3.3.2 YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 YN -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 < FireFox Extensions [User Folders] > -> YY -> ~EmptyValue -> C:\Users\Chris Reaper\AppData\Roaming\Mozilla\Firefox\Profiles\n5hn24af.default\extensions\[email protected] < 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar YN -> "{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> Reg Error: Key error. [DAEMON Tools Toolbar] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar YN -> "Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ YN -> WebBrowser\\"{32099AAC-C132-4136-9E9A-4E364A424E17}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] < 64bit-Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ YN -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab [Reg Error: Key error.] [Files/Folders - Created Within 30 Days] NY -> 1 C:\Windows\*.tmp files -> C:\Windows\*.tmp [Files/Folders - Modified Within 30 Days] NY -> 1 C:\Windows\*.tmp files -> C:\Windows\*.tmp [Alternate Data Streams] NY -> @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:8CE646EE NY -> @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:0FF263E8
:OTL FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: [email protected]:3.3.3.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.) :Files ipconfig /flushdns /c :Commands [purity] [resethosts] [emptytemp] [EMPTYFLASH] [CREATERESTOREPOINT] [Reboot]
0 members, 1 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.