Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Cannot remove SCORPION SAVER/ADPEAK
Message
<blockquote data-quote="hunzeker" data-source="post: 146685" data-attributes="member: 15154"><p>I guess I don't understand. What do you mean by "PM"? I thought I sent it again on 12/01.</p><p></p><p>I'll try again with this replay, but won't it just cut-off the bottom of the scan results like it has done twice before?</p><p></p><p>OTL logfile created on: 11/30/2013 1:48:24 PM - Run 3</p><p>OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Folders\Downloads\Programs</p><p>64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation</p><p>Internet Explorer (Version = 9.11.9600.16428)</p><p>Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy</p><p> </p><p>4.00 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 60.23% Memory free</p><p>8.00 Gb Paging File | 6.27 Gb Available in Paging File | 78.45% Paging File free</p><p>Paging file location(s): ?:\pagefile.sys [binary data]</p><p> </p><p>%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)</p><p>Drive C: | 372.51 Gb Total Space | 319.75 Gb Free Space | 85.84% Space Free | Partition Type: NTFS</p><p>Drive I: | 1.87 Gb Total Space | 1.37 Gb Free Space | 73.44% Space Free | Partition Type: NTFS</p><p>Drive J: | 298.09 Gb Total Space | 119.38 Gb Free Space | 40.05% Space Free | Partition Type: NTFS</p><p>Drive K: | 465.76 Gb Total Space | 277.05 Gb Free Space | 59.48% Space Free | Partition Type: NTFS</p><p> </p><p>Computer Name: WIN7 | User Name: Folders | Logged in as Administrator.</p><p>Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans</p><p>Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days</p><p> </p><p><span style="color: #E56717">========== Processes (SafeList) ==========</span></p><p> </p><p>PRC - C:\Users\Folders\Downloads\Programs\OTL_2.exe (OldTimer Tools)</p><p>PRC - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (IObit)</p><p>PRC - C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe (Google Inc.)</p><p>PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)</p><p>PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)</p><p>PRC - C:\Program Files (x86)\Norton Zone\Engine\1.0.15.13\NZ.exe (Symantec Corporation)</p><p>PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)</p><p>PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)</p><p>PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)</p><p>PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe (Plex, Inc.)</p><p>PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Python Software Foundation)</p><p>PRC - C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)</p><p>PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (IObit)</p><p>PRC - C:\Program Files\ScorpionSaver Services\AdpeakProxy.exe (Adpeak, Inc.)</p><p>PRC - C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)</p><p>PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)</p><p>PRC - C:\Program Files (x86)\WinTV\TVServer\CaptureGenPCI.exe (Hauppauge Computer Works)</p><p>PRC - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)</p><p>PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)</p><p>PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)</p><p> </p><p> </p><p><span style="color: #E56717">========== Modules (No Company Name) ==========</span></p><p> </p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\pysqlite2._sqlite.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32com.shell.shell.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_elementtree.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32api.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_socket.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_multiprocessing.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32ts.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._gdi_.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._misc_.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\windows._cacheinvalidation.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\pythoncom27.dll ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\PyWinTypes27.dll ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_ctypes.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._html2.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32profile.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32crypt.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._core_.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_ssl.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32security.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32pdh.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._windows_.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_hashlib.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._wizard.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32file.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32inet.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32process.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._controls_.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\unicodedata.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\pyexpat.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32event.pyd ()</p><p>MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\select.pyd ()</p><p>MOD - C:\Program Files\AVAST Software\Avast\libcef.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\SSL.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\rand.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\etree.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\objectify.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\crypto.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_socket.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ssl.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_hashlib.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\unicodedata.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ctypes.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\pyexpat.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\zlib1.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\select.pyd ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\WebKit.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\tag.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\zlib.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\swscale-0.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_core-vc80-3_0.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxml2.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxslt.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\libidn.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\libexslt.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\JavaScriptCore.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\cairo.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\CFLite.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\avutil-50.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\avcodec-52.dll ()</p><p>MOD - C:\Program Files (x86)\Plex\Plex Media Server\avformat-52.dll ()</p><p> </p><p> </p><p><span style="color: #E56717">========== Services (SafeList) ==========</span></p><p> </p><p>SRV:<strong>64bit:</strong> - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)</p><p>SRV:<strong>64bit:</strong> - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)</p><p>SRV:<strong>64bit:</strong> - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)</p><p>SRV:<strong>64bit:</strong> - (GenieTimelineService) -- C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe (Genie9)</p><p>SRV:<strong>64bit:</strong> - (SpyHunter 4 Service) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)</p><p>SRV:<strong>64bit:</strong> - (AdpeakProxy) -- C:\Program Files\ScorpionSaver Services\AdpeakProxy.exe (Adpeak, Inc.)</p><p>SRV - (LiveUpdateSvc) -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (IObit)</p><p>SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)</p><p>SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)</p><p>SRV - (NZ) -- C:\Program Files (x86)\Norton Zone\Engine\1.0.15.13\NZ.exe (Symantec Corporation)</p><p>SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)</p><p>SRV - (AdvancedSystemCareService7) -- C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (IObit)</p><p>SRV - (HauppaugeTVServer) -- C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)</p><p>SRV - (IMFservice) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)</p><p>SRV - (Hauppauge WinTV Extender) -- C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc)</p><p>SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)</p><p>SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)</p><p>SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)</p><p>SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)</p><p> </p><p> </p><p><span style="color: #E56717">========== Driver Services (SafeList) ==========</span></p><p> </p><p>DRV:<strong>64bit:</strong> - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)</p><p>DRV:<strong>64bit:</strong> - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)</p><p>DRV:<strong>64bit:</strong> - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)</p><p>DRV:<strong>64bit:</strong> - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys ()</p><p>DRV:<strong>64bit:</strong> - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)</p><p>DRV:<strong>64bit:</strong> - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)</p><p>DRV:<strong>64bit:</strong> - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys ()</p><p>DRV:<strong>64bit:</strong> - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)</p><p>DRV:<strong>64bit:</strong> - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)</p><p>DRV:<strong>64bit:</strong> - (IDMWFP) -- C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)</p><p>DRV:<strong>64bit:</strong> - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)</p><p>DRV:<strong>64bit:</strong> - (ccSet_NZ) -- C:\Windows\SysNative\drivers\NZx64\01000F0.00D\ccSetx64.sys (Symantec Corporation)</p><p>DRV:<strong>64bit:</strong> - (SmartDefragDriver) -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys ()</p><p>DRV:<strong>64bit:</strong> - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)</p><p>DRV:<strong>64bit:</strong> - (EsgScanner) -- C:\Windows\SysNative\drivers\EsgScanner.sys ()</p><p>DRV:<strong>64bit:</strong> - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)</p><p>DRV:<strong>64bit:</strong> - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)</p><p>DRV:<strong>64bit:</strong> - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)</p><p>DRV:<strong>64bit:</strong> - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()</p><p>DRV:<strong>64bit:</strong> - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)</p><p>DRV:<strong>64bit:</strong> - (hcw18bda) -- C:\Windows\SysNative\drivers\hcw18bda.sys (Hauppauge Computer Works, Inc)</p><p>DRV:<strong>64bit:</strong> - (NVNET) -- C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)</p><p>DRV:<strong>64bit:</strong> - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)</p><p>DRV:<strong>64bit:</strong> - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)</p><p>DRV:<strong>64bit:</strong> - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)</p><p>DRV:<strong>64bit:</strong> - (FETNDIS) -- C:\Windows\SysNative\drivers\fet6x64.sys (VIA Technologies, Inc. )</p><p>DRV:<strong>64bit:</strong> - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)</p><p>DRV:<strong>64bit:</strong> - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)</p><p>DRV:<strong>64bit:</strong> - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)</p><p>DRV:<strong>64bit:</strong> - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)</p><p>DRV:<strong>64bit:</strong> - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)</p><p>DRV - (UrlFilter) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys (IObit.com)</p><p>DRV - (RegFilter) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys (IObit.com)</p><p>DRV - (FileMonitor) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys (IObit)</p><p>DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)</p><p> </p><p> </p><p><span style="color: #E56717">========== Standard Registry (All) ==========</span></p><p> </p><p> </p><p><span style="color: #E56717">========== Internet Explorer ==========</span></p><p> </p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141</p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]</p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons</p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm</p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk</p><p>IE:<strong>64bit:</strong> - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141</p><p>IE:<strong>64bit:</strong> - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}</p><p>IE:<strong>64bit:</strong> - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk</p><p>IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141</p><p>IE - HKLM\..\SearchScopes,DefaultScope = </p><p>IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC</p><p> </p><p> </p><p>IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = </p><p>IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR</p><p>IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0</p><p> </p><p>IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = </p><p>IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR</p><p>IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0</p><p> </p><p>IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)</p><p>IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = </p><p> </p><p>IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)</p><p>IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = </p><p> </p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0</p><p> </p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)</p><p>IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003\..\SearchScopes,DefaultScope = </p><p> </p><p><span style="color: #E56717">========== FireFox ==========</span></p><p> </p><p>FF - prefs.js..browser.search.defaultengine: "Google"</p><p>FF - prefs.js..browser.search.defaultenginename: "Bing"</p><p>FF - prefs.js..browser.search.order.1: "Google"</p><p>FF - prefs.js..browser.search.selectedEngine: "Bing"</p><p>FF - prefs.js..browser.search.suggest.enabled: false</p><p>FF - prefs.js..browser.search.useDBForOrder: true</p><p>FF - prefs.js..browser.startup.homepage: "https://www.google.com/"</p><p>FF - prefs.js..extensions.enabledAddons: mozilla_cc%40internetdownloadmanager.com:7.3.64</p><p>FF - prefs.js..network.proxy.type: 0</p><p>FF - user.js - File not found</p><p> </p><p>FF:<strong>64bit:</strong> - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll File not found</p><p>FF:<strong>64bit:</strong> - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found</p><p>FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()</p><p>FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)</p><p>FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)</p><p>FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)</p><p>FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found</p><p>FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)</p><p>FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)</p><p>FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)</p><p>FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)</p><p> </p><p>FF - HKEY_CURRENT_USER\software\mozilla\Firefox\EXTENSIONS\\mozilla_cc@internetdownloadmanager.com: C:\Users\Folders\AppData\Roaming\IDM\idmmzcc5 [2013/11/25 23:33:11 | 000,000,000 | ---D | M]</p><p>FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Folders\AppData\Roaming\IDM\idmmzcc5 [2013/11/25 23:33:11 | 000,000,000 | ---D | M]</p><p> </p><p>[2013/11/11 20:12:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Folders\AppData\Roaming\Mozilla\Extensions</p><p>[2013/11/28 18:09:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Folders\AppData\Roaming\Mozilla\Firefox\Profiles\333rko86.default\extensions</p><p>[2013/11/21 20:32:24 | 000,007,911 | ---- | M] () -- C:\Users\Folders\AppData\Roaming\Mozilla\Firefox\Profiles\333rko86.default\searchplugins\Google.xml</p><p>[2013/11/12 18:51:42 | 000,000,905 | ---- | M] () -- C:\Users\Folders\AppData\Roaming\Mozilla\Firefox\Profiles\333rko86.default\searchplugins\yahoo_ff.xml</p><p>[2013/11/25 23:30:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions</p><p>[2013/11/25 23:33:11 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\FOLDERS\APPDATA\ROAMING\IDM\IDMMZCC5</p><p> </p><p><span style="color: #E56717">========== Chrome ==========</span></p><p> </p><p>CHR - default_search_provider: Google (Enabled)</p><p>CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite117" alt=":eek:" title="Eek! :eek:" loading="lazy" data-shortname=":eek:" />riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite117" alt=":eek:" title="Eek! :eek:" loading="lazy" data-shortname=":eek:" />mniboxStartMarginParameter}ie={inputEncoding}</p><p>CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite115" alt=":p" title="Stick out tongue :p" loading="lazy" data-shortname=":p" />ageClassification}sugkey={google:suggestAPIKeyParameter},</p><p>CHR - Extension: Google Drive = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\</p><p>CHR - Extension: avast! Online Security = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2005.45_1\</p><p>CHR - Extension: IDM Integration Module = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.18.7_1\</p><p>CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\</p><p>CHR - Extension: Google Wallet = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1\</p><p> </p><p>O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts</p><p>O2:<strong>64bit:</strong> - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)</p><p>O2:<strong>64bit:</strong> - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)</p><p>O2:<strong>64bit:</strong> - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)</p><p>O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)</p><p>O3:<strong>64bit:</strong> - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)</p><p>O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)</p><p>O4 - HKLM..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\8d25ed94-bb32-4930-87d7-4c74dc4f01ce.exe (AVAST Software)</p><p>O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)</p><p>O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)</p><p>O4 - HKLM..\Run: [Qwest Personal Digital Vault] "C:\Program Files (x86)\CenturyLink Personal Digital Vault\QwestPersonalDigitalVault.exe" /m File not found</p><p>O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)</p><p>O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)</p><p>O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [GoogleChromeAutoLaunch_4D58BC9D6CE41938B37776A7615543AA] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)</p><p>O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [GoogleDriveSync] c:\program files (x86)\google\drive\googledrivesync.exe (Google)</p><p>O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)</p><p>O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [Plex Media Server] C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)</p><p>O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)</p><p>O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found</p><p>O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found</p><p>O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = </p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = </p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13</p><p>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17</p><p>O7 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145</p><p>O7 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0</p><p>O7 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0</p><p>O8:<strong>64bit:</strong> - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()</p><p>O8:<strong>64bit:</strong> - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()</p><p>O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()</p><p>O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()</p><p>O10:<strong>64bit:</strong> - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000014 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)</p><p>O10:<strong>64bit:</strong> - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.)</p><p>O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)</p><p>O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)</p><p>O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)</p><p>O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)</p><p>O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)</p><p>O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.)</p><p>O13<strong>64bit:</strong> - gopher Prefix: missing</p><p>O13 - gopher Prefix: missing</p><p>O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.2.25</p><p>O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9174F4D4-A1F3-4903-AEC4-365046D8E2F9}: DhcpNameServer = 192.168.0.1 205.171.2.25</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)</p><p>O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)</p><p>O18:<strong>64bit:</strong> - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)</p><p>O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)</p><p>O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)</p><p>O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)</p><p>O20:<strong>64bit:</strong> - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)</p><p>O20:<strong>64bit:</strong> - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)</p><p>O20:<strong>64bit:</strong> - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)</p><p>O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)</p><p>O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)</p><p>O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)</p><p>O21:<strong>64bit:</strong> - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.</p><p>O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.</p><p>O29:<strong>64bit:</strong> - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)</p><p>O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)</p><p>O30:<strong>64bit:</strong> - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)</p><p>O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)</p><p>O30:<strong>64bit:</strong> - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)</p><p>O30:<strong>64bit:</strong> - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)</p><p>O30:<strong>64bit:</strong> - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)</p><p>O30:<strong>64bit:</strong> - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)</p><p>O30:<strong>64bit:</strong> - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)</p><p>O30:<strong>64bit:</strong> - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)</p><p>O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)</p><p>O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)</p><p>O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)</p><p>O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)</p><p>O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)</p><p>O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)</p><p>O31 - SafeBoot: AlternateShell - cmd.exe</p><p>O32 - HKLM CDRom: AutoRun - 1</p><p>O32 - AutoRun File - [2013/11/23 15:11:00 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]</p><p>O34 - HKLM BootExecute: (autocheck autochk *)</p><p>O35:<strong>64bit:</strong> - HKLM\..comfile [open] -- "%1" %*</p><p>O35:<strong>64bit:</strong> - HKLM\..exefile [open] -- "%1" %*</p><p>O35 - HKLM\..comfile [open] -- "%1" %*</p><p>O35 - HKLM\..exefile [open] -- "%1" %*</p><p>O37:<strong>64bit:</strong> - HKLM\...com [@ = comfile] -- "%1" %*</p><p>O37:<strong>64bit:</strong> - HKLM\...exe [@ = exefile] -- "%1" %*</p><p>O37 - HKLM\...com [@ = comfile] -- "%1" %*</p><p>O37 - HKLM\...exe [@ = exefile] -- "%1" %*</p><p>O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)</p><p>O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)</p><p>O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)</p><p> </p><p><span style="color: #E56717">========== Files/Folders - Created Within 30 Days ==========</span></p><p> </p><p>[2013/11/30 13:36:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Logs</p><p>[2013/11/30 13:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP</p><p>[2013/11/28 16:59:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab</p><p>[2013/11/28 14:36:40 | 000,000,000 | ---D | C] -- C:\Program Files\ScorpionSaver Services</p><p>[2013/11/28 12:11:21 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\IDM2</p><p>[2013/11/28 11:43:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Genie9</p><p>[2013/11/28 11:34:39 | 000,000,000 | ---D | C] -- C:\0f4b1c2beb7b6dabc8ddb5daad65d67a</p><p>[2013/11/28 10:18:12 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\autorun</p><p>[2013/11/27 20:18:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegHunter</p><p>[2013/11/27 20:10:07 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Systweak</p><p>[2013/11/27 20:10:06 | 000,019,392 | ---- | C] (Dll-Files.com) -- C:\Windows\SysNative\roboot64.exe</p><p>[2013/11/27 16:08:43 | 000,000,000 | ---D | C] -- C:\b1e34f6098ca96049f4c</p><p>[2013/11/27 16:06:54 | 000,000,000 | ---D | C] -- C:\4d3d87bbdec4022af663ac6a6c75</p><p>[2013/11/27 16:04:12 | 000,000,000 | ---D | C] -- C:\f287f11a16765c212c1b6c</p><p>[2013/11/27 16:01:31 | 000,000,000 | ---D | C] -- C:\e407f43d348aefaebea4b46177</p><p>[2013/11/27 16:00:45 | 000,000,000 | ---D | C] -- C:\5733db8184d72843ca1e49ed71b62fc1</p><p>[2013/11/27 15:59:42 | 000,000,000 | ---D | C] -- C:\31b674d54c6afb206866</p><p>[2013/11/27 13:29:55 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter</p><p>[2013/11/27 13:29:53 | 000,000,000 | ---D | C] -- C:\sh4ldr</p><p>[2013/11/26 20:55:06 | 000,000,000 | ---D | C] -- C:\Windows\Migration</p><p>[2013/11/26 20:55:04 | 000,000,000 | -HSD | C] -- C:\Config.Msi</p><p>[2013/11/26 20:53:44 | 000,000,000 | ---D | C] -- C:\7b324cffb58ae272b47de342</p><p>[2013/11/26 18:44:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)</p><p>[2013/11/26 16:37:17 | 000,047,064 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys</p><p>[2013/11/26 13:58:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinTV</p><p>[2013/11/26 13:58:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Hauppauge</p><p>[2013/11/26 13:48:29 | 000,000,000 | ---D | C] -- C:\Hauppauge</p><p>[2013/11/26 13:25:21 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess</p><p>[2013/11/25 23:28:31 | 000,000,000 | ---D | C] -- C:\_OTL</p><p>[2013/11/25 22:58:22 | 000,000,000 | ---D | C] -- C:\Windows\tasks\TaskDisabled</p><p>[2013/11/23 15:10:09 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group</p><p>[2013/11/23 15:09:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard</p><p>[2013/11/22 16:51:16 | 000,038,672 | ---- | C] (PCTV Systems S.à r.l.) -- C:\Windows\SysWow64\pcleUtil.dll</p><p>[2013/11/22 16:51:00 | 000,831,554 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysWow64\hcwtvwnd.dll</p><p>[2013/11/22 16:51:00 | 000,323,640 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysWow64\hcwpnp32.dll</p><p>[2013/11/22 16:51:00 | 000,118,840 | ---- | C] (Hauppauge Computer Works, Inc.) -- C:\Windows\SysWow64\hcwi2c32.dll</p><p>[2013/11/22 16:51:00 | 000,036,921 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysWow64\hcwutl32.dll</p><p>[2013/11/22 16:48:57 | 000,912,896 | ---- | C] (Hauppauge Computer Works, Inc) -- C:\Windows\SysNative\drivers\hcw18bda.sys</p><p>[2013/11/22 16:48:57 | 000,139,264 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysNative\hcw18prop.ax</p><p>[2013/11/22 16:48:57 | 000,117,248 | ---- | C] (Hauppauge Computer Works, Inc.) -- C:\Windows\SysNative\hcw18CCv.ax</p><p>[2013/11/22 12:32:41 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro</p><p>[2013/11/22 10:51:12 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT</p><p>[2013/11/22 10:39:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner</p><p>[2013/11/21 20:55:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group</p><p>[2013/11/21 20:22:10 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Adobe</p><p>[2013/11/21 19:29:38 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\eCyber</p><p>[2013/11/21 14:10:52 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Real</p><p>[2013/11/21 14:08:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Real</p><p>[2013/11/20 18:07:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genie9</p><p>[2013/11/20 18:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\Genie9</p><p>[2013/11/20 17:58:48 | 000,000,000 | R--D | C] -- C:\Users\Folders\Desktop\Backup</p><p>[2013/11/20 17:58:47 | 000,000,000 | R--D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp</p><p>[2013/11/20 17:58:47 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup</p><p>[2013/11/20 17:57:45 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Genie9</p><p>[2013/11/19 19:02:59 | 000,000,000 | R--D | C] -- C:\Users\Folders\Google Drive</p><p>[2013/11/19 14:37:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftMaker Viewer</p><p>[2013/11/19 14:36:59 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoftMaker Viewer</p><p>[2013/11/19 14:36:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SoftMaker Viewer</p><p>[2013/11/18 19:25:06 | 000,032,600 | ---- | C] (IObit) -- C:\Windows\SysNative\SmartDefragBootTime.exe</p><p>[2013/11/17 17:02:28 | 000,000,000 | ---D | C] -- C:\Users\Folders\Rail Temp</p><p>[2013/11/17 14:51:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office</p><p>[2013/11/17 14:51:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache</p><p>[2013/11/17 14:36:20 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\DOGS</p><p>[2013/11/17 14:36:20 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\Documents</p><p>[2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\DISPUTES</p><p>[2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\Booknizer</p><p>[2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\APARTMENTS</p><p>[2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\AA QWEST</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\WAB</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\VERIZON</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\TAXES</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\RES REF</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\PROP TAX</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\PASSWORDS</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\OLD EMAILS</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\OLD APT</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\LICENSES</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\EMAILS</p><p>[2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\EMAIL ADDRESSES</p><p>[2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\SoftMaker</p><p>[2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\LICENSES PASSWORDS</p><p>[2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\BEND APT</p><p>[2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\AppData</p><p>[2013/11/16 15:23:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Media Preview</p><p>[2013/11/16 15:23:44 | 000,000,000 | ---D | C] -- C:\Program Files\Media Preview</p><p>[2013/11/16 15:23:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BabelSoft</p><p>[2013/11/16 13:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Research</p><p>[2013/11/16 13:04:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft ICE</p><p>[2013/11/16 12:59:40 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Foxit Software</p><p>[2013/11/16 12:59:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxit Software</p><p>[2013/11/15 21:01:58 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\PhotoScape</p><p>[2013/11/15 21:01:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape</p><p>[2013/11/15 21:01:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoScape</p><p>[2013/11/15 18:29:40 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\CrashDumps</p><p>[2013/11/15 13:29:34 | 000,000,000 | ---D | C] -- C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}</p><p>[2013/11/15 13:24:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller</p><p>[2013/11/15 13:21:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter</p><p>[2013/11/15 13:01:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox</p><p>[2013/11/15 09:52:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Zone</p><p>[2013/11/14 21:35:49 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Qwest</p><p>[2013/11/14 19:13:43 | 000,162,392 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NZx64\01000F0.00D\ccSetx64.sys</p><p>[2013/11/14 19:13:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NZx64\01000F0.00D</p><p>[2013/11/14 15:05:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0</p><p>[2013/11/14 13:23:04 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll</p><p>[2013/11/14 13:22:51 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll</p><p>[2013/11/13 18:49:24 | 000,439,296 | ---- | C] (Adpeak, Inc.) -- C:\Windows\SysNative\AdpeakProxy64.dll</p><p>[2013/11/13 18:49:21 | 000,338,944 | ---- | C] (Adpeak, Inc.) -- C:\Windows\SysWow64\AdpeakProxy.dll</p><p>[2013/11/13 18:11:18 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\vlc</p><p>[2013/11/13 18:10:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN</p><p>[2013/11/13 18:09:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN</p><p>[2013/11/13 18:01:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive</p><p>[2013/11/13 17:34:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth</p><p>[2013/11/13 17:26:08 | 001,005,928 | ---- | C] (The OpenSSL Project, http://www.openssl.org/) -- C:\Windows\SysWow64\libeay32.dll</p><p>[2013/11/13 17:26:08 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc70.dll</p><p>[2013/11/13 17:26:08 | 000,487,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp70.dll</p><p>[2013/11/13 17:26:07 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr70.dll</p><p>[2013/11/13 17:20:37 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\AVS4YOU</p><p>[2013/11/13 17:20:21 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU</p><p>[2013/11/13 17:19:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU</p><p>[2013/11/13 17:19:04 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU</p><p>[2013/11/13 17:18:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia</p><p>[2013/11/13 17:18:22 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GdiPlus.dll</p><p>[2013/11/13 17:18:21 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3a.dll</p><p>[2013/11/13 17:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU</p><p>[2013/11/13 17:08:41 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\IDM</p><p>[2013/11/13 17:08:41 | 000,000,000 | ---D | C] -- C:\ProgramData\IDM</p><p>[2013/11/13 17:08:41 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\DMCache</p><p>[2013/11/13 17:08:34 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager</p><p>[2013/11/13 17:08:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager</p><p>[2013/11/13 17:08:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Download Manager</p><p>[2013/11/13 16:52:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 2</p><p>[2013/11/13 16:18:30 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\OpenOffice</p><p>[2013/11/13 16:14:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CenturyLink Personal Digital Vault™</p><p>[2013/11/13 16:14:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CenturyLink Personal Digital Vault</p><p>[2013/11/13 14:37:06 | 000,000,000 | ---D | C] -- C:\Users\Folders\Norton Zone</p><p>[2013/11/13 14:36:03 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NZx64</p><p>[2013/11/13 14:36:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Zone</p><p>[2013/11/13 14:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton</p><p>[2013/11/13 14:35:52 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller</p><p>[2013/11/13 14:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller</p><p>[2013/11/13 14:33:36 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations</p><p>[2013/11/13 14:24:03 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Plex</p><p>[2013/11/13 14:23:53 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll</p><p>[2013/11/13 14:23:52 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll</p><p>[2013/11/13 14:23:02 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plex Media Center</p><p>[2013/11/13 13:40:46 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Apple Computer</p><p>[2013/11/13 13:40:40 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Plex Media Server</p><p>[2013/11/13 13:40:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server</p><p>[2013/11/13 13:39:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Plex</p><p>[2013/11/13 13:39:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache</p><p>[2013/11/13 12:40:20 | 000,000,000 | -HSD | C] -- C:\found.000</p><p>[2013/11/13 11:43:16 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE</p><p>[2013/11/13 11:39:57 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe</p><p>[2013/11/13 11:39:57 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll</p><p>[2013/11/13 11:39:53 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll</p><p>[2013/11/13 11:39:53 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl</p><p>[2013/11/13 11:39:53 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl</p><p>[2013/11/13 11:39:53 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll</p><p>[2013/11/13 11:39:53 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll</p><p>[2013/11/13 11:39:53 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll</p><p>[2013/11/13 11:39:53 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll</p><p>[2013/11/13 11:39:53 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll</p><p>[2013/11/13 11:39:53 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll</p><p>[2013/11/13 11:39:53 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll</p><p>[2013/11/13 11:39:53 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll</p><p>[2013/11/13 11:39:53 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll</p><p>[2013/11/13 11:39:53 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat</p><p>[2013/11/13 11:39:53 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat</p><p>[2013/11/13 11:39:53 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll</p><p>[2013/11/13 11:39:53 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll</p><p>[2013/11/13 11:39:53 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll</p><p>[2013/11/13 11:39:53 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll</p><p>[2013/11/13 11:39:53 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll</p><p>[2013/11/13 11:39:53 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll</p><p>[2013/11/13 11:39:53 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec</p><p>[2013/11/13 11:39:53 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec</p><p>[2013/11/13 11:39:53 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll</p><p>[2013/11/13 11:39:53 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll</p><p>[2013/11/13 11:39:53 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll</p><p>[2013/11/13 11:39:53 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll</p><p>[2013/11/13 11:39:53 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll</p><p>[2013/11/13 11:39:53 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe</p><p>[2013/11/13 11:39:53 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll</p><p>[2013/11/13 11:39:53 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe</p><p>[2013/11/13 11:39:53 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll</p><p>[2013/11/13 11:39:53 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe</p><p>[2013/11/13 11:39:53 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll</p><p>[2013/11/13 11:39:53 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe</p><p>[2013/11/13 11:39:53 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe</p><p>[2013/11/13 11:39:53 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe</p><p>[2013/11/13 11:39:53 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll</p><p>[2013/11/13 11:39:53 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll</p><p>[2013/11/13 11:39:53 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll</p><p>[2013/11/13 11:39:53 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll</p><p>[2013/11/13 11:39:53 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe</p><p>[2013/11/13 11:39:53 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe</p><p>[2013/11/13 11:39:53 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll</p><p>[2013/11/13 11:39:53 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll</p><p>[2013/11/13 11:39:53 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll</p><p>[2013/11/13 11:39:53 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe</p><p>[2013/11/13 11:39:53 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe</p><p>[2013/11/13 11:39:53 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll</p><p>[2013/11/13 11:39:53 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll</p><p>[2013/11/13 11:39:53 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll</p><p>[2013/11/13 11:39:53 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll</p><p>[2013/11/13 11:39:53 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll</p><p>[2013/11/13 11:39:53 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx</p><p>[2013/11/13 11:39:53 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe</p><p>[2013/11/13 11:39:53 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe</p><p>[2013/11/13 11:39:53 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\</p></blockquote><p></p>
[QUOTE="hunzeker, post: 146685, member: 15154"] I guess I don't understand. What do you mean by "PM"? I thought I sent it again on 12/01. I'll try again with this replay, but won't it just cut-off the bottom of the scan results like it has done twice before? OTL logfile created on: 11/30/2013 1:48:24 PM - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Folders\Downloads\Programs 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.16428) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 4.00 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 60.23% Memory free 8.00 Gb Paging File | 6.27 Gb Available in Paging File | 78.45% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 372.51 Gb Total Space | 319.75 Gb Free Space | 85.84% Space Free | Partition Type: NTFS Drive I: | 1.87 Gb Total Space | 1.37 Gb Free Space | 73.44% Space Free | Partition Type: NTFS Drive J: | 298.09 Gb Total Space | 119.38 Gb Free Space | 40.05% Space Free | Partition Type: NTFS Drive K: | 465.76 Gb Total Space | 277.05 Gb Free Space | 59.48% Space Free | Partition Type: NTFS Computer Name: WIN7 | User Name: Folders | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - C:\Users\Folders\Downloads\Programs\OTL_2.exe (OldTimer Tools) PRC - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (IObit) PRC - C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe (Google Inc.) PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) PRC - C:\Program Files (x86)\Norton Zone\Engine\1.0.15.13\NZ.exe (Symantec Corporation) PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.) PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.) PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe (Plex, Inc.) PRC - C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Python Software Foundation) PRC - C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.) PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (IObit) PRC - C:\Program Files\ScorpionSaver Services\AdpeakProxy.exe (Adpeak, Inc.) PRC - C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google) PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit) PRC - C:\Program Files (x86)\WinTV\TVServer\CaptureGenPCI.exe (Hauppauge Computer Works) PRC - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works) PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\pysqlite2._sqlite.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32com.shell.shell.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_elementtree.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32api.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_socket.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_multiprocessing.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32ts.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._gdi_.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._misc_.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\windows._cacheinvalidation.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\pythoncom27.dll () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\PyWinTypes27.dll () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_ctypes.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._html2.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32profile.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32crypt.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._core_.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_ssl.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32security.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32pdh.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._windows_.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\_hashlib.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._wizard.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32file.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32inet.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32process.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\wx._controls_.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\unicodedata.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\pyexpat.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\win32event.pyd () MOD - C:\Users\Folders\AppData\Local\Temp\_MEI30602\select.pyd () MOD - C:\Program Files\AVAST Software\Avast\libcef.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\SSL.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\rand.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\etree.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\objectify.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\crypto.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_socket.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ssl.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_hashlib.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\unicodedata.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ctypes.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\pyexpat.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\zlib1.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\DLLs\select.pyd () MOD - C:\Program Files (x86)\Plex\Plex Media Server\WebKit.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\tag.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\zlib.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\swscale-0.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_core-vc80-3_0.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxml2.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\libxslt.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\libidn.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\libexslt.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\JavaScriptCore.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\cairo.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\CFLite.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\avutil-50.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\avcodec-52.dll () MOD - C:\Program Files (x86)\Plex\Plex Media Server\avformat-52.dll () [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation) SRV:[b]64bit:[/b] - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:[b]64bit:[/b] - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) SRV:[b]64bit:[/b] - (GenieTimelineService) -- C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe (Genie9) SRV:[b]64bit:[/b] - (SpyHunter 4 Service) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.) SRV:[b]64bit:[/b] - (AdpeakProxy) -- C:\Program Files\ScorpionSaver Services\AdpeakProxy.exe (Adpeak, Inc.) SRV - (LiveUpdateSvc) -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (IObit) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (NZ) -- C:\Program Files (x86)\Norton Zone\Engine\1.0.15.13\NZ.exe (Symantec Corporation) SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) SRV - (AdvancedSystemCareService7) -- C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (IObit) SRV - (HauppaugeTVServer) -- C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works) SRV - (IMFservice) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit) SRV - (Hauppauge WinTV Extender) -- C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc) SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software) DRV:[b]64bit:[/b] - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software) DRV:[b]64bit:[/b] - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys () DRV:[b]64bit:[/b] - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software) DRV:[b]64bit:[/b] - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software) DRV:[b]64bit:[/b] - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys () DRV:[b]64bit:[/b] - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software) DRV:[b]64bit:[/b] - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software) DRV:[b]64bit:[/b] - (IDMWFP) -- C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.) DRV:[b]64bit:[/b] - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (ccSet_NZ) -- C:\Windows\SysNative\drivers\NZx64\01000F0.00D\ccSetx64.sys (Symantec Corporation) DRV:[b]64bit:[/b] - (SmartDefragDriver) -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys () DRV:[b]64bit:[/b] - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation) DRV:[b]64bit:[/b] - (EsgScanner) -- C:\Windows\SysNative\drivers\EsgScanner.sys () DRV:[b]64bit:[/b] - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:[b]64bit:[/b] - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:[b]64bit:[/b] - (esgiguard) -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys () DRV:[b]64bit:[/b] - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:[b]64bit:[/b] - (hcw18bda) -- C:\Windows\SysNative\drivers\hcw18bda.sys (Hauppauge Computer Works, Inc) DRV:[b]64bit:[/b] - (NVNET) -- C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation) DRV:[b]64bit:[/b] - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:[b]64bit:[/b] - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:[b]64bit:[/b] - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:[b]64bit:[/b] - (FETNDIS) -- C:\Windows\SysNative\drivers\fet6x64.sys (VIA Technologies, Inc. ) DRV:[b]64bit:[/b] - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation) DRV:[b]64bit:[/b] - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:[b]64bit:[/b] - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:[b]64bit:[/b] - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:[b]64bit:[/b] - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV - (UrlFilter) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys (IObit.com) DRV - (RegFilter) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys (IObit.com) DRV - (FileMonitor) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys (IObit) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) [color=#E56717]========== Standard Registry (All) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/ IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003\..\SearchScopes,DefaultScope = [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Bing" FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.selectedEngine: "Bing" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "https://www.google.com/" FF - prefs.js..extensions.enabledAddons: mozilla_cc%40internetdownloadmanager.com:7.3.64 FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKEY_CURRENT_USER\software\mozilla\Firefox\EXTENSIONS\\mozilla_cc@internetdownloadmanager.com: C:\Users\Folders\AppData\Roaming\IDM\idmmzcc5 [2013/11/25 23:33:11 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Folders\AppData\Roaming\IDM\idmmzcc5 [2013/11/25 23:33:11 | 000,000,000 | ---D | M] [2013/11/11 20:12:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Folders\AppData\Roaming\Mozilla\Extensions [2013/11/28 18:09:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Folders\AppData\Roaming\Mozilla\Firefox\Profiles\333rko86.default\extensions [2013/11/21 20:32:24 | 000,007,911 | ---- | M] () -- C:\Users\Folders\AppData\Roaming\Mozilla\Firefox\Profiles\333rko86.default\searchplugins\Google.xml [2013/11/12 18:51:42 | 000,000,905 | ---- | M] () -- C:\Users\Folders\AppData\Roaming\Mozilla\Firefox\Profiles\333rko86.default\searchplugins\yahoo_ff.xml [2013/11/25 23:30:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions [2013/11/25 23:33:11 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\FOLDERS\APPDATA\ROAMING\IDM\IDMMZCC5 [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}, CHR - Extension: Google Drive = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\ CHR - Extension: avast! Online Security = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2005.45_1\ CHR - Extension: IDM Integration Module = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.18.7_1\ CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\ CHR - Extension: Google Wallet = C:\Users\Folders\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1\ O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.) O2:[b]64bit:[/b] - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\8d25ed94-bb32-4930-87d7-4c74dc4f01ce.exe (AVAST Software) O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit) O4 - HKLM..\Run: [Qwest Personal Digital Vault] "C:\Program Files (x86)\CenturyLink Personal Digital Vault\QwestPersonalDigitalVault.exe" /m File not found O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [GoogleChromeAutoLaunch_4D58BC9D6CE41938B37776A7615543AA] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [GoogleDriveSync] c:\program files (x86)\google\drive\googledrivesync.exe (Google) O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.) O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001..\Run: [Plex Media Server] C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.) O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O7 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKU\S-1-5-21-3821494161-1811066229-1795245934-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0 O8:[b]64bit:[/b] - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm () O8:[b]64bit:[/b] - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm () O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm () O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm () O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000014 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Windows\SysNative\AdpeakProxy64.dll (Adpeak, Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SysWow64\AdpeakProxy.dll (Adpeak, Inc.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.2.25 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9174F4D4-A1F3-4903-AEC4-365046D8E2F9}: DhcpNameServer = 192.168.0.1 205.171.2.25 O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation) O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation) O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation) O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation) O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation) O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013/11/23 15:11:00 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013/11/30 13:36:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Logs [2013/11/30 13:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP [2013/11/28 16:59:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab [2013/11/28 14:36:40 | 000,000,000 | ---D | C] -- C:\Program Files\ScorpionSaver Services [2013/11/28 12:11:21 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\IDM2 [2013/11/28 11:43:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Genie9 [2013/11/28 11:34:39 | 000,000,000 | ---D | C] -- C:\0f4b1c2beb7b6dabc8ddb5daad65d67a [2013/11/28 10:18:12 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\autorun [2013/11/27 20:18:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegHunter [2013/11/27 20:10:07 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Systweak [2013/11/27 20:10:06 | 000,019,392 | ---- | C] (Dll-Files.com) -- C:\Windows\SysNative\roboot64.exe [2013/11/27 16:08:43 | 000,000,000 | ---D | C] -- C:\b1e34f6098ca96049f4c [2013/11/27 16:06:54 | 000,000,000 | ---D | C] -- C:\4d3d87bbdec4022af663ac6a6c75 [2013/11/27 16:04:12 | 000,000,000 | ---D | C] -- C:\f287f11a16765c212c1b6c [2013/11/27 16:01:31 | 000,000,000 | ---D | C] -- C:\e407f43d348aefaebea4b46177 [2013/11/27 16:00:45 | 000,000,000 | ---D | C] -- C:\5733db8184d72843ca1e49ed71b62fc1 [2013/11/27 15:59:42 | 000,000,000 | ---D | C] -- C:\31b674d54c6afb206866 [2013/11/27 13:29:55 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter [2013/11/27 13:29:53 | 000,000,000 | ---D | C] -- C:\sh4ldr [2013/11/26 20:55:06 | 000,000,000 | ---D | C] -- C:\Windows\Migration [2013/11/26 20:55:04 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2013/11/26 20:53:44 | 000,000,000 | ---D | C] -- C:\7b324cffb58ae272b47de342 [2013/11/26 18:44:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable) [2013/11/26 16:37:17 | 000,047,064 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys [2013/11/26 13:58:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinTV [2013/11/26 13:58:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Hauppauge [2013/11/26 13:48:29 | 000,000,000 | ---D | C] -- C:\Hauppauge [2013/11/26 13:25:21 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess [2013/11/25 23:28:31 | 000,000,000 | ---D | C] -- C:\_OTL [2013/11/25 22:58:22 | 000,000,000 | ---D | C] -- C:\Windows\tasks\TaskDisabled [2013/11/23 15:10:09 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013/11/23 15:09:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard [2013/11/22 16:51:16 | 000,038,672 | ---- | C] (PCTV Systems S.à r.l.) -- C:\Windows\SysWow64\pcleUtil.dll [2013/11/22 16:51:00 | 000,831,554 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysWow64\hcwtvwnd.dll [2013/11/22 16:51:00 | 000,323,640 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysWow64\hcwpnp32.dll [2013/11/22 16:51:00 | 000,118,840 | ---- | C] (Hauppauge Computer Works, Inc.) -- C:\Windows\SysWow64\hcwi2c32.dll [2013/11/22 16:51:00 | 000,036,921 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysWow64\hcwutl32.dll [2013/11/22 16:48:57 | 000,912,896 | ---- | C] (Hauppauge Computer Works, Inc) -- C:\Windows\SysNative\drivers\hcw18bda.sys [2013/11/22 16:48:57 | 000,139,264 | ---- | C] (Hauppauge Computer Works) -- C:\Windows\SysNative\hcw18prop.ax [2013/11/22 16:48:57 | 000,117,248 | ---- | C] (Hauppauge Computer Works, Inc.) -- C:\Windows\SysNative\hcw18CCv.ax [2013/11/22 12:32:41 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro [2013/11/22 10:51:12 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT [2013/11/22 10:39:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner [2013/11/21 20:55:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group [2013/11/21 20:22:10 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Adobe [2013/11/21 19:29:38 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\eCyber [2013/11/21 14:10:52 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Real [2013/11/21 14:08:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Real [2013/11/20 18:07:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genie9 [2013/11/20 18:06:49 | 000,000,000 | ---D | C] -- C:\Program Files\Genie9 [2013/11/20 17:58:48 | 000,000,000 | R--D | C] -- C:\Users\Folders\Desktop\Backup [2013/11/20 17:58:47 | 000,000,000 | R--D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp [2013/11/20 17:58:47 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [2013/11/20 17:57:45 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Genie9 [2013/11/19 19:02:59 | 000,000,000 | R--D | C] -- C:\Users\Folders\Google Drive [2013/11/19 14:37:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftMaker Viewer [2013/11/19 14:36:59 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoftMaker Viewer [2013/11/19 14:36:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SoftMaker Viewer [2013/11/18 19:25:06 | 000,032,600 | ---- | C] (IObit) -- C:\Windows\SysNative\SmartDefragBootTime.exe [2013/11/17 17:02:28 | 000,000,000 | ---D | C] -- C:\Users\Folders\Rail Temp [2013/11/17 14:51:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office [2013/11/17 14:51:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache [2013/11/17 14:36:20 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\DOGS [2013/11/17 14:36:20 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\Documents [2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\DISPUTES [2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\Booknizer [2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\APARTMENTS [2013/11/17 14:36:19 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\AA QWEST [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\WAB [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\VERIZON [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\TAXES [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\RES REF [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\PROP TAX [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\PASSWORDS [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\OLD EMAILS [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\OLD APT [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\LICENSES [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\EMAILS [2013/11/17 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\EMAIL ADDRESSES [2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\SoftMaker [2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\LICENSES PASSWORDS [2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\BEND APT [2013/11/17 14:32:43 | 000,000,000 | ---D | C] -- C:\Users\Folders\Documents\AppData [2013/11/16 15:23:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Media Preview [2013/11/16 15:23:44 | 000,000,000 | ---D | C] -- C:\Program Files\Media Preview [2013/11/16 15:23:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BabelSoft [2013/11/16 13:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Research [2013/11/16 13:04:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft ICE [2013/11/16 12:59:40 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Foxit Software [2013/11/16 12:59:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxit Software [2013/11/15 21:01:58 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\PhotoScape [2013/11/15 21:01:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape [2013/11/15 21:01:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoScape [2013/11/15 18:29:40 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\CrashDumps [2013/11/15 13:29:34 | 000,000,000 | ---D | C] -- C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A} [2013/11/15 13:24:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller [2013/11/15 13:21:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter [2013/11/15 13:01:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013/11/15 09:52:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Zone [2013/11/14 21:35:49 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Qwest [2013/11/14 19:13:43 | 000,162,392 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NZx64\01000F0.00D\ccSetx64.sys [2013/11/14 19:13:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NZx64\01000F0.00D [2013/11/14 15:05:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0 [2013/11/14 13:23:04 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll [2013/11/14 13:22:51 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll [2013/11/13 18:49:24 | 000,439,296 | ---- | C] (Adpeak, Inc.) -- C:\Windows\SysNative\AdpeakProxy64.dll [2013/11/13 18:49:21 | 000,338,944 | ---- | C] (Adpeak, Inc.) -- C:\Windows\SysWow64\AdpeakProxy.dll [2013/11/13 18:11:18 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\vlc [2013/11/13 18:10:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN [2013/11/13 18:09:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN [2013/11/13 18:01:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive [2013/11/13 17:34:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2013/11/13 17:26:08 | 001,005,928 | ---- | C] (The OpenSSL Project, http://www.openssl.org/) -- C:\Windows\SysWow64\libeay32.dll [2013/11/13 17:26:08 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc70.dll [2013/11/13 17:26:08 | 000,487,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp70.dll [2013/11/13 17:26:07 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr70.dll [2013/11/13 17:20:37 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\AVS4YOU [2013/11/13 17:20:21 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU [2013/11/13 17:19:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU [2013/11/13 17:19:04 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU [2013/11/13 17:18:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia [2013/11/13 17:18:22 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GdiPlus.dll [2013/11/13 17:18:21 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3a.dll [2013/11/13 17:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU [2013/11/13 17:08:41 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\IDM [2013/11/13 17:08:41 | 000,000,000 | ---D | C] -- C:\ProgramData\IDM [2013/11/13 17:08:41 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\DMCache [2013/11/13 17:08:34 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager [2013/11/13 17:08:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager [2013/11/13 17:08:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Download Manager [2013/11/13 16:52:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 2 [2013/11/13 16:18:30 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\OpenOffice [2013/11/13 16:14:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CenturyLink Personal Digital Vault™ [2013/11/13 16:14:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CenturyLink Personal Digital Vault [2013/11/13 14:37:06 | 000,000,000 | ---D | C] -- C:\Users\Folders\Norton Zone [2013/11/13 14:36:03 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NZx64 [2013/11/13 14:36:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Zone [2013/11/13 14:36:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton [2013/11/13 14:35:52 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller [2013/11/13 14:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller [2013/11/13 14:33:36 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations [2013/11/13 14:24:03 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Plex [2013/11/13 14:23:53 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_43.dll [2013/11/13 14:23:52 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_43.dll [2013/11/13 14:23:02 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plex Media Center [2013/11/13 13:40:46 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Apple Computer [2013/11/13 13:40:40 | 000,000,000 | ---D | C] -- C:\Users\Folders\AppData\Local\Plex Media Server [2013/11/13 13:40:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server [2013/11/13 13:39:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Plex [2013/11/13 13:39:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache [2013/11/13 12:40:20 | 000,000,000 | -HSD | C] -- C:\found.000 [2013/11/13 11:43:16 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE [2013/11/13 11:39:57 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe [2013/11/13 11:39:57 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll [2013/11/13 11:39:53 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013/11/13 11:39:53 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2013/11/13 11:39:53 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2013/11/13 11:39:53 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll [2013/11/13 11:39:53 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll [2013/11/13 11:39:53 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll [2013/11/13 11:39:53 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2013/11/13 11:39:53 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013/11/13 11:39:53 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll [2013/11/13 11:39:53 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2013/11/13 11:39:53 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll [2013/11/13 11:39:53 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013/11/13 11:39:53 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat [2013/11/13 11:39:53 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat [2013/11/13 11:39:53 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013/11/13 11:39:53 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013/11/13 11:39:53 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll [2013/11/13 11:39:53 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2013/11/13 11:39:53 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2013/11/13 11:39:53 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013/11/13 11:39:53 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec [2013/11/13 11:39:53 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec [2013/11/13 11:39:53 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2013/11/13 11:39:53 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll [2013/11/13 11:39:53 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2013/11/13 11:39:53 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll [2013/11/13 11:39:53 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2013/11/13 11:39:53 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2013/11/13 11:39:53 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2013/11/13 11:39:53 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe [2013/11/13 11:39:53 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2013/11/13 11:39:53 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe [2013/11/13 11:39:53 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll [2013/11/13 11:39:53 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe [2013/11/13 11:39:53 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe [2013/11/13 11:39:53 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2013/11/13 11:39:53 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll [2013/11/13 11:39:53 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll [2013/11/13 11:39:53 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll [2013/11/13 11:39:53 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll [2013/11/13 11:39:53 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2013/11/13 11:39:53 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe [2013/11/13 11:39:53 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll [2013/11/13 11:39:53 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll [2013/11/13 11:39:53 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll [2013/11/13 11:39:53 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe [2013/11/13 11:39:53 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe [2013/11/13 11:39:53 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll [2013/11/13 11:39:53 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2013/11/13 11:39:53 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll [2013/11/13 11:39:53 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll [2013/11/13 11:39:53 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll [2013/11/13 11:39:53 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx [2013/11/13 11:39:53 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe [2013/11/13 11:39:53 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe [2013/11/13 11:39:53 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ [/QUOTE]
Insert quotes…
Verification
Post reply
Top