Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows has detected your computers performance is slow


  • This topic is locked This topic is locked
38 replies to this topic

#1 bkdesign

bkdesign

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 25 July 2013 - 03:27 PM

Hi,

 

I had a virus a few weeks back which you guys helped me remove.  I am not sure the virus is completely gone.  I keep getting this pop-up "Windows has detected your computers performance is slow" every 5 minutes or so, and I did a scan with Mircrosoft Mr. Fixit which mentioned that there are other people logged into my computer.  From what I can tell I am the only one logged into my computer.  Also Outlook 2003 keeps crashing and restarting.  I have changed the compatibility for Outlook to Windows XP (service pack 2).  I am not sure if this has anything to do with the problem.

 

Thanks for your help!

bkdesign



BC AdBot (Login to Remove)

 


#2 bkdesign

bkdesign
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 30 July 2013 - 12:45 AM

I am still having issues with my system.  Below is the hijackthis log

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:44:14 PM, on 7/29/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Program Files (x86)\Adobe\Adobe InDesign CS5\InDesign.exe
C:\Program Files (x86)\Extensis\Extensis Suitcase 11\Suitcase.exe
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\Illustrator.exe
C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Brad\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
O2 - BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\AlienRespawn\Components\Scheduler\Launcher.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Brad\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
O4 - Global Startup: Intuit Data Protect.lnk = C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6287/mcfscan.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: intu-help-qb5 - {867FCB77-9823-4CD6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Alienware Fusion Service (AlienFusionService) - Alienware - C:\Program Files\Alienware\Command Center\AlienFusionService.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Product - 2010/11/01 13:10:16 (CLKMSVC10_9EC60124) - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Anti-Malware Core (mfecore) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QBIDPService (QBVSS) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\AlienRespawn\sftservice.EXE
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files (x86)\Smith Micro\StuffIt\ArcNameService.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13508 bytes



#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,631 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:39 PM

Posted 30 July 2013 - 03:30 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/502232 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#4 bkdesign

bkdesign
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 30 July 2013 - 03:50 PM

1. My computer has been running slower then usual and I am not sure if it's because I had a virus a few weeks back.  I do keep getting a pop-up message that "Windows has detected your computers performance is slow" and my mouse stalls sometimes.  I have also been having issues with Microsoft Outlook 2003, stalling and closing/restarting.

 

2. DDS Log (see below)

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16635
Run by Brad at 13:48:10 on 2013-07-30
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.4087.1193 [GMT -7:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
C:\Program Files (x86)\AlienRespawn\sftservice.EXE
C:\Program Files (x86)\Smith Micro\StuffIt\ArcNameService.exe
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\PROGRA~1\McAfee\MSC\McAPExe.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
C:\Program Files\Alienware\Command Center\ThermalController.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Program Files\McAfee\MAT\McPvTray.exe
C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe
C:\Program Files (x86)\Adobe\Adobe InDesign CS5\InDesign.exe
C:\Program Files (x86)\Extensis\Extensis Suitcase 11\Suitcase.exe
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_94_ActiveX.exe
C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\AcroTray.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\MsSpellCheckingFacility.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - <orphaned>
BHO: Virtual Storage Mount Notification: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Google Update] "C:\Users\Brad\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRunOnce: [Launcher] C:\Program Files (x86)\AlienRespawn\Components\Scheduler\Launcher.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\GOOGLE~1.LNK - C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INTUIT~1.LNK - C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6287/mcfscan.cab
TCP: NameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{6F89BDAB-DA49-4D6C-AEEE-44102ADDD1CF} : DHCPNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
STS: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
x64-BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - <orphaned>
x64-BHO: Virtual Storage Mount Notification: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll
x64-BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
x64-BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
x64-TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [Command Center Controllers] "C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe"
x64-DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - <orphaned>
x64-Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - <orphaned>
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
x64-SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll
x64-STS: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - plugin: c:\PROGRA~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll
FF - plugin: C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Users\Brad\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - ExtSQL: !HIDDEN! 2013-03-15 17:00; smartwebprinting@hp.com; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2012-12-26 772944]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2012-12-26 342416]
R1 cbfs3;cbfs3;C:\Windows\System32\drivers\cbfs3.sys [2012-5-3 321424]
R1 MOBKFilter;MOBKFilter;C:\Windows\System32\drivers\MOBK.sys [2013-5-1 66040]
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2012-6-18 14704]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-11-1 203264]
R2 HomeNetSvc;McAfee Home Network;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-5-1 221296]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-1 13336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [2013-6-13 120592]
R2 McMPFSvc;McAfee Personal Firewall;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-5-1 221296]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-5-1 221296]
R2 mcpltsvc;McAfee Platform Services;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-5-1 221296]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-5-1 221296]
R2 McPvDrv;McPvDrv Driver;C:\Windows\System32\drivers\McPvDrv.sys [2013-5-14 74560]
R2 mfecore;McAfee Anti-Malware Core;C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [2013-5-1 1017016]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2013-5-1 218760]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\System32\mfevtps.exe [2013-5-1 182752]
R2 QBVSS;QBIDPService;C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [2012-12-6 1248256]
R2 RtNdPt60;Realtek NDIS Protocol Driver;C:\Windows\System32\drivers\RtNdPt60.sys [2010-11-1 27136]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\SftService.exe [2010-11-1 689472]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2010-11-1 116240]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2012-12-26 70112]
R3 CompFilter64;UVCCompositeFilter;C:\Windows\System32\drivers\lvbflt64.sys [2012-1-18 25632]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2013-1-3 79240]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2013-1-3 15752]
R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2012-1-18 351136]
R3 LVUVC64;Logitech HD Pro Webcam C910(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-1-18 4865568]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2012-12-26 309968]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2012-12-26 516608]
R3 mfencbdc;McAfee Inc. mfencbdc;C:\Windows\System32\drivers\mfencbdc.sys [2013-2-18 337120]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-11-1 239616]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2010/11/01 13:10:16;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-4-26 232944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-21 162408]
S3 BthMtpEnum;Bluetooth MTP Device Enumerator;C:\Windows\System32\drivers\BthMtpEnum.sys [2009-7-13 64512]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2012-9-19 102368]
S3 HipShieldK;McAfee Inc. HipShieldK;C:\Windows\System32\drivers\HipShieldK.sys [2013-5-1 197264]
S3 mfencrk;McAfee Inc. mfencrk;C:\Windows\System32\drivers\mfencrk.sys [2013-2-18 95856]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-26 19456]
S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);C:\Windows\System32\drivers\RtTeam60.sys [2010-11-1 43008]
S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);C:\Windows\System32\drivers\RtVlan60.sys [2010-11-1 24064]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2);C:\Windows\System32\drivers\RtTeam60.sys [2010-11-1 43008]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-26 57856]
S3 VIA_USB_ETS;VIA Telecom USB ETS Driver;C:\Windows\System32\drivers\VIA_USB_ETS.sys [2012-10-2 21760]
S3 ViaUsbModemDriver;VIA Telecom USB MODEM Driver;C:\Windows\System32\drivers\VIA_USB_MODEM.sys [2012-10-2 28160]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-10-26 1255736]
S4 MOBKbackup;McAfee Online Backup;C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe [2010-4-13 231224]
S4 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-5-10 3574624]
.
=============== File Associations ===============
.
ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\dreamweaver.exe", "%1"
.
=============== Created Last 30 ================
.
2013-07-30 16:12:11 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{90FB525F-6A64-4D3D-8E97-B878B66EA886}\mpengine.dll
2013-07-16 06:24:47 24416 ----a-r- C:\Windows\System32\AdobePDFUI.dll
2013-07-16 06:20:14 106088 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2013-07-10 00:26:02 -------- d-sh--w- C:\$RECYCLE.BIN
2013-07-09 20:37:53 -------- d-----w- C:\Windows\System32\MRT
2013-07-09 20:14:39 -------- d-----w- C:\4b7ba50c5139b70223506ca3
2013-07-09 20:13:00 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-07-09 20:00:48 571904 ----a-w- C:\Program Files\Windows Defender\MpClient.dll
2013-07-09 19:59:19 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-07-09 19:59:18 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-09 17:23:29 -------- d--h--w- C:\Windows\AxInstSV
2013-07-08 18:34:44 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-07-08 18:34:32 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-06 02:05:17 -------- d-----w- C:\Windows\ERUNT
2013-07-06 02:05:13 -------- d-----w- C:\JRT
2013-07-01 19:25:34 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-07-01 19:25:34 -------- d-----w- C:\Program Files\iPod
2013-07-01 19:25:33 -------- d-----w- C:\Program Files\iTunes
.
==================== Find3M  ====================
.
2013-07-26 21:52:49 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-26 21:52:49 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-08 18:34:19 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-06-11 23:43:37 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-06-11 23:42:58 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-06-11 23:42:58 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-06-11 23:26:20 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-06-11 23:25:16 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-06-11 23:25:13 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-06-11 23:25:13 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-06-11 22:51:45 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-06-11 22:50:58 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-07 02:37:52 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-06-05 03:34:27 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-06-04 06:00:13 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-05-29 20:46:57 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-07 22:04:33 74703 ----a-w- C:\Windows\SysWow64\mfc45.dat
2013-05-06 06:03:49 1887744 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-05-06 04:56:35 1620480 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-05-02 09:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 13:48:30.04 ===============
 

 

 

 



#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,619 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:39 AM

Posted 31 July 2013 - 08:55 PM

Greetings Brad and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Please run this program for me.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST results
  • Addition log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 bkdesign

bkdesign
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 31 July 2013 - 09:30 PM

HI,

Thank you for your response and thank you for your help! Below are the logs from the scan.

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-07-2013 03
Ran by Brad (administrator) on 31-07-2013 19:26:47
Running from C:\Users\Brad\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(McAfee, Inc.) C:\Windows\system32\mfevtps.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Intuit) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
(SoftThinks SAS) C:\Program Files (x86)\AlienRespawn\sftservice.EXE
(Smith Micro Software, Inc.) C:\Program Files (x86)\Smith Micro\StuffIt\ArcNameService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(McAfee, Inc.) C:\PROGRA~1\McAfee\MSC\McAPExe.exe
() C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\ThermalController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(McAfee, Inc.) C:\Program Files\McAfee\MAT\McPvTray.exe
(Extensis) C:\Program Files (x86)\Extensis\Extensis Suitcase 11\Suitcase.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\AcroTray.exe
(Acresso Software Inc.) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\system32\taskmgr.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
(Microsoft Corporation) C:\Windows\sysWow64\SearchProtocolHost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [Command Center Controllers] - C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12656 2012-06-18] (Alienware)
HKLM-x32\...\RunOnce: [Launcher] - C:\Program Files (x86)\AlienRespawn\Components\Scheduler\Launcher.exe [165184 2010-07-21] (Softthinks)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKCU\...\Run: [Google Update] - C:\Users\Brad\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-06-06] (Google Inc.)
HKCU\...\Run: [GoogleChromeAutoLaunch_486A54232E7A6A76188CD6D03A70FC2E] - C:\Users\Brad\AppData\Local\Google\Chrome\Application\chrome.exe [846288 2013-07-24] (Google Inc.)
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [454600 2013-02-28] (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Calendar Sync.lnk
ShortcutTarget: Google Calendar Sync.lnk -> C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO-x32: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6287/mcfscan.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - No File
Handler: msdaipp - No CLSID Value -
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler-x32: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
FireFox:
========
FF ProfilePath: C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default
FF SelectedSearchEngine: Secure Search
FF Homepage: www.google.com
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=mcafee&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.2.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.2.1 - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @mcafee.com/MVT - C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll No File
FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Brad\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Brad\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
FF Extension: No Name - C:\Users\Brad\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Ant Video Downloader - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\anttoolbar@ant.com
FF Extension: SeoQuake - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
FF Extension: Html Validator - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
FF Extension: Dust-Me Selectors - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{3c6e1eed-a07e-4c80-9cf3-66ea0bf40b37}
FF Extension: ColorZilla - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
FF Extension: No Name - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi
FF Extension: No Name - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi
FF Extension: No Name - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
FF Extension: No Name - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}.xpi
FF Extension: No Name - C:\Users\Brad\AppData\Roaming\Mozilla\Firefox\Profiles\5ik040ax.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchURL: (McAfee) - http://search.yahoo.com/search?fr=mcafee&p={searchTerms}
CHR DefaultSuggestURL: (McAfee) - "suggest_url": ""
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Brad\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Brad\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Brad\AppData\Local\Google\Chrome\Application\28.0.1500.95\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (Skype Toolbars) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.220.4) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java™ Platform SE 6 U22) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll (Catalina Marketing Corporation)
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll No File
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll No File
CHR Plugin: (NPCIG.dll) - C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Virtual Technician) - C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll ()
CHR Extension: (HelloFax: 50 Free Fax Pages) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm\1.12_0
CHR Extension: (Logitech SetPoint) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd\6.52.74_0
CHR Extension: (SiteAdvisor) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.2.1341_0
CHR Extension: (PHP documentation - PHP.net) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfiahljocaflpaiopilgpiochncgdnhd\1.3.1_0
CHR Extension: (Skype Click to Call) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0
CHR Extension: (PHP Console) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfhmhhlpfleoednkpnnnkolmclajemef\2.1.10_0
CHR Extension: (RSS Subscription Extension (by Google)) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.2.2_0
CHR Extension: (WordPress Stats) - C:\Users\Brad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnadajlmiacgaakmeghbdhdbpcehacge\1.111_0
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
==================== Services (Whitelisted) =================
S2 CLKMSVC10_9EC60124; c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [232944 2010-04-26] (CyberLink)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [120592 2013-05-22] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [388680 2013-06-15] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1017016 2013-02-28] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-04-03] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-04-03] (McAfee, Inc.)
S4 MOBKbackup; C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe [231224 2010-04-13] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [221296 2013-03-05] (McAfee, Inc.)
R2 Stuffit Archive Name Service; C:\Program Files (x86)\Smith Micro\StuffIt\ArcNameService.exe [157016 2008-01-31] (Smith Micro Software, Inc.)
==================== Drivers (Whitelisted) ====================
S3 BthMtpEnum; C:\Windows\System32\DRIVERS\BthMtpEnum.sys [64512 2009-07-13] (Microsoft Corporation)
R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [321424 2010-11-30] (EldoS Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-04-03] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197264 2012-05-28] (McAfee, Inc.)
R2 McPvDrv; C:\Windows\system32\drivers\McPvDrv.sys [74560 2013-04-22] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-04-03] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309968 2013-04-03] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [516608 2013-04-03] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [772944 2013-04-03] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [337120 2013-02-18] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [95856 2013-02-18] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [342416 2013-04-03] (McAfee, Inc.)
R1 MOBKFilter; C:\Windows\System32\DRIVERS\MOBK.sys [66040 2010-04-13] (Mozy, Inc.)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
S3 ViaUsbModemDriver; C:\Windows\System32\DRIVERS\VIA_USB_MODEM.sys [28160 2011-10-04] ()
S3 VIA_USB_ETS; C:\Windows\System32\DRIVERS\VIA_USB_ETS.sys [21760 2011-10-04] (Via Telecom, Inc.)
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-31 19:24 - 2013-07-31 19:24 - 01781589 _____ (Farbar) C:\Users\Brad\Desktop\FRST64.exe
2013-07-31 19:02 - 2013-07-31 19:03 - 00001211 _____ C:\Users\Brad\Downloads\No More Banding 0.5.atn.zip
2013-07-31 17:44 - 2013-07-31 17:44 - 00169569 _____ C:\Users\Brad\Desktop\invoice.xps
2013-07-31 17:13 - 2013-07-31 17:14 - 597533170 _____ C:\Users\Brad\Desktop\iStock_000012544161XLarge delete.psd
2013-07-30 13:48 - 2013-07-30 13:48 - 00023400 _____ C:\Users\Brad\Desktop\dds.txt
2013-07-30 13:48 - 2013-07-30 13:48 - 00010506 _____ C:\Users\Brad\Desktop\attach.txt
2013-07-30 13:47 - 2013-07-30 13:48 - 00688992 ____R (Swearware) C:\Users\Brad\Downloads\dds.com
2013-07-29 22:44 - 2013-07-29 22:44 - 00013510 _____ C:\Users\Brad\Desktop\hijackthis2
2013-07-29 20:19 - 2013-07-30 21:57 - 00000000 ____D C:\Users\Brad\Desktop\Joan - Branding
2013-07-29 17:31 - 2013-07-29 17:31 - 00000000 ____D C:\Users\Brad\Desktop\wordpress
2013-07-29 15:43 - 2013-07-29 15:43 - 07850382 _____ C:\Users\Brad\Desktop\H2Hshow collage2.psd
2013-07-25 14:25 - 2013-07-25 14:25 - 00000903 _____ C:\Users\Brad\Desktop\marjan list.txt
2013-07-25 11:11 - 2013-07-25 11:11 - 00347424 _____ (Microsoft Corporation) C:\Users\Brad\Downloads\MicrosoftFixit.Performance.RNP.148298206684651127.1.1.Run.exe
2013-07-24 16:23 - 2013-07-24 16:23 - 00000565 _____ C:\Users\Brad\Desktop\outbind___118-0000000084398BB311C2CA458D2FD45E450A24D7C4013B00_.log
2013-07-18 13:25 - 2013-07-18 13:25 - 00013824 _____ C:\Users\Brad\Desktop\h2h merge list.xls
2013-07-18 13:24 - 2013-07-18 13:24 - 00179200 _____ C:\Users\Brad\Desktop\Heels2Heal - Master Email List 122012.xls
2013-07-18 13:24 - 2013-07-18 13:24 - 00013824 _____ C:\Users\Brad\Desktop\Untitled_2.xls
2013-07-17 15:23 - 2013-07-17 15:23 - 00002992 _____ C:\Windows\System32\Tasks\{28F9DE3A-EB52-42FD-910D-F57E82B718F8}
2013-07-16 20:32 - 2013-07-16 20:32 - 00003166 _____ C:\Windows\System32\Tasks\{BC8072FC-1496-433D-8C5B-3547AC44FD86}
2013-07-15 23:24 - 2009-08-20 00:50 - 00024416 ____R (Adobe Systems Inc.) C:\Windows\system32\AdobePDFUI.dll
2013-07-15 15:17 - 2013-07-15 15:17 - 00003018 _____ C:\Windows\System32\Tasks\{678D49C1-EC9F-426C-A6B0-61591E80F1C8}
2013-07-15 13:59 - 2013-07-15 13:59 - 00002992 _____ C:\Windows\System32\Tasks\{1D3770CB-5FED-4E9B-9D7C-A1C7809B550E}
2013-07-15 11:09 - 2013-07-15 11:09 - 00002992 _____ C:\Windows\System32\Tasks\{44673710-7822-4101-86AF-355316935067}
2013-07-12 15:09 - 2013-07-12 15:21 - 00000000 ____D C:\Users\Brad\Desktop\postcard
2013-07-12 10:28 - 2013-07-12 10:28 - 00003018 _____ C:\Windows\System32\Tasks\{BC8299F2-3DA6-428C-B57C-1C7CC7DFF259}
2013-07-12 10:28 - 2013-07-12 10:28 - 00003018 _____ C:\Windows\System32\Tasks\{4B4101E6-C46E-469F-92AB-1FE0584EA08E}
2013-07-11 14:28 - 2013-07-11 14:28 - 00002992 _____ C:\Windows\System32\Tasks\{E47AF7BD-3D44-46C4-9277-DE5EA16564BF}
2013-07-11 12:33 - 2013-07-11 12:36 - 209700978 _____ C:\Users\Brad\Downloads\HEALTHY BABIES 5K KNSD-TV 5-6-13 11am.mov
2013-07-11 12:33 - 2013-07-11 12:34 - 45055049 _____ C:\Users\Brad\Downloads\MIRACLE BABIES BBQ KSWB-TV 7-6-13 10PM.mov
2013-07-11 12:33 - 2013-07-11 12:33 - 21733048 _____ C:\Users\Brad\Downloads\MIRACLE BABIES BBQ XETV-TV 7-6-13 10PM.mov
2013-07-11 11:28 - 2013-07-11 11:31 - 00906440 _____ (BillP Studios) C:\Users\Brad\Downloads\wpsetup.exe
2013-07-09 14:49 - 2013-07-09 17:54 - 00012141 _____ C:\Users\Brad\Desktop\h2h-board.html
2013-07-09 13:37 - 2013-07-09 13:40 - 00000000 ____D C:\Windows\system32\MRT
2013-07-09 13:27 - 2013-07-26 18:06 - 00001274 _____ C:\Windows\PFRO.log
2013-07-09 13:14 - 2013-07-09 13:17 - 00000000 ____D C:\4b7ba50c5139b70223506ca3
2013-07-09 13:13 - 2013-06-06 20:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-09 13:12 - 2013-06-11 16:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-09 13:12 - 2013-06-11 16:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-09 13:12 - 2013-06-11 16:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-09 13:12 - 2013-06-11 16:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-09 13:12 - 2013-06-11 16:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-09 13:12 - 2013-06-11 16:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-09 13:12 - 2013-06-11 16:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-09 13:12 - 2013-06-11 16:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-09 13:12 - 2013-06-11 16:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-09 13:12 - 2013-06-11 16:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-09 13:12 - 2013-06-11 16:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-09 13:12 - 2013-06-11 16:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-09 13:12 - 2013-06-11 16:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-09 13:12 - 2013-06-11 16:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-09 13:12 - 2013-06-11 16:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-09 13:12 - 2013-06-11 16:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-09 13:12 - 2013-06-11 16:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-09 13:12 - 2013-06-11 16:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-09 13:12 - 2013-06-11 15:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-09 13:12 - 2013-06-11 15:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-09 13:12 - 2013-06-06 19:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-09 13:00 - 2013-06-04 20:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-09 13:00 - 2013-06-03 23:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-09 13:00 - 2013-06-03 21:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-09 13:00 - 2013-05-05 23:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-09 13:00 - 2013-05-05 21:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-09 12:59 - 2013-04-09 16:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-09 12:59 - 2013-04-02 15:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-09 10:23 - 2013-07-09 10:23 - 00000000 ___HD C:\Windows\AxInstSV
2013-07-09 10:15 - 2013-07-09 10:15 - 00000000 ____D C:\Users\Brad\Desktop\backups
2013-07-09 08:09 - 2013-07-31 15:07 - 00002588 _____ C:\Windows\setupact.log
2013-07-09 08:09 - 2013-07-09 08:09 - 00000000 _____ C:\Windows\setuperr.log
2013-07-08 12:17 - 2013-07-08 12:18 - 00014973 _____ C:\Users\Brad\Desktop\hijackthis.log
2013-07-08 12:12 - 2013-07-08 12:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\Brad\Desktop\HijackThis.exe
2013-07-08 11:51 - 2013-07-08 11:52 - 00221172 _____ C:\Users\Brad\Desktop\cc_20130708_115155.reg
2013-07-08 11:34 - 2013-07-08 11:34 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-07-08 11:34 - 2013-07-08 11:34 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-08 11:34 - 2013-07-08 11:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-08 11:34 - 2013-07-08 11:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-08 11:34 - 2013-07-08 11:34 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-08 11:31 - 2013-07-29 20:42 - 00000000 ____D C:\Users\Brad\Desktop\TrichoView
2013-07-08 11:16 - 2013-07-08 11:16 - 00001270 _____ C:\Users\Brad\Desktop\Revo Uninstaller.lnk
2013-07-06 12:38 - 2013-07-09 17:16 - 00000000 ____D C:\Windows\erdnt
2013-07-05 19:05 - 2013-07-05 19:05 - 00000000 ____D C:\Windows\ERUNT
2013-07-05 19:05 - 2013-07-05 19:05 - 00000000 ____D C:\JRT
2013-07-05 10:35 - 2013-07-09 17:17 - 00000000 ____D C:\Users\Brad\Desktop\virus
2013-07-03 15:58 - 2013-07-06 12:50 - 81264640 _____ C:\Windows\system32\config\SOFTWARE.bak
2013-07-03 15:24 - 2013-07-03 15:24 - 00003070 _____ C:\Windows\System32\Tasks\{9B7926D2-EB22-4D6A-A80A-73E4F0BFA890}
2013-07-02 14:25 - 2013-07-03 12:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-01 12:25 - 2013-07-01 12:26 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-07-01 12:25 - 2013-07-01 12:26 - 00000000 ____D C:\Program Files\iTunes
2013-07-01 12:25 - 2013-07-01 12:25 - 00000000 ____D C:\Program Files\iPod
139
==================== One Month Modified Files and Folders =======
2013-07-31 19:26 - 2013-07-31 19:26 - 00000000 ____D C:\FRST
2013-07-31 19:24 - 2013-07-31 19:24 - 01781589 _____ (Farbar) C:\Users\Brad\Desktop\FRST64.exe
2013-07-31 19:03 - 2013-07-31 19:02 - 00001211 _____ C:\Users\Brad\Downloads\No More Banding 0.5.atn.zip
2013-07-31 19:03 - 2012-04-02 10:41 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-31 19:03 - 2010-11-04 21:56 - 00000000 ____D C:\Users\Brad\AppData\Local\Smith Micro
2013-07-31 18:51 - 2011-06-06 16:45 - 00000904 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001UA.job
2013-07-31 18:30 - 2011-08-04 08:32 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-31 17:44 - 2013-07-31 17:44 - 00169569 _____ C:\Users\Brad\Desktop\invoice.xps
2013-07-31 17:14 - 2013-07-31 17:13 - 597533170 _____ C:\Users\Brad\Desktop\iStock_000012544161XLarge delete.psd
2013-07-31 15:40 - 2013-04-25 18:44 - 00004096 ____H C:\Users\Brad\AppData\Local\keyfile3.drm
2013-07-31 15:29 - 2010-11-04 20:59 - 00000000 ____D C:\Users\Brad\AppData\Roaming\Extensis
2013-07-31 15:29 - 2010-11-04 12:48 - 00344600 _____ C:\Users\Brad\AppData\Local\GDIPFONTCACHEV1.DAT
2013-07-31 15:15 - 2009-07-13 21:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-31 15:15 - 2009-07-13 21:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-31 15:13 - 2012-08-24 10:39 - 00000000 __RSD C:\Users\Brad\Documents\McAfee Vaults
2013-07-31 15:11 - 2011-08-04 08:32 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-31 15:11 - 2010-11-04 12:47 - 00000000 ____D C:\Users\Brad\AppData\Local\SoftThinks
2013-07-31 15:08 - 2009-07-13 21:45 - 08139840 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-31 15:07 - 2013-07-09 08:09 - 00002588 _____ C:\Windows\setupact.log
2013-07-31 15:07 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-31 15:04 - 2009-07-13 22:10 - 01915790 _____ C:\Windows\WindowsUpdate.log
2013-07-31 14:14 - 2011-02-03 10:48 - 11020288 ___SH C:\Users\Brad\Desktop\Thumbs.db
2013-07-31 12:51 - 2011-06-06 16:45 - 00000852 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001Core.job
2013-07-30 21:57 - 2013-07-29 20:19 - 00000000 ____D C:\Users\Brad\Desktop\Joan - Branding
2013-07-30 16:23 - 2011-01-24 10:48 - 00001456 _____ C:\Users\Brad\AppData\Local\Adobe Save for Web 12.0 Prefs
2013-07-30 13:48 - 2013-07-30 13:48 - 00023400 _____ C:\Users\Brad\Desktop\dds.txt
2013-07-30 13:48 - 2013-07-30 13:48 - 00010506 _____ C:\Users\Brad\Desktop\attach.txt
2013-07-30 13:48 - 2013-07-30 13:47 - 00688992 ____R (Swearware) C:\Users\Brad\Downloads\dds.com
2013-07-29 22:44 - 2013-07-29 22:44 - 00013510 _____ C:\Users\Brad\Desktop\hijackthis2
2013-07-29 20:42 - 2013-07-08 11:31 - 00000000 ____D C:\Users\Brad\Desktop\TrichoView
2013-07-29 17:31 - 2013-07-29 17:31 - 00000000 ____D C:\Users\Brad\Desktop\wordpress
2013-07-29 15:43 - 2013-07-29 15:43 - 07850382 _____ C:\Users\Brad\Desktop\H2Hshow collage2.psd
2013-07-26 18:06 - 2013-07-09 13:27 - 00001274 _____ C:\Windows\PFRO.log
2013-07-26 18:06 - 2013-05-01 22:57 - 00000000 ____D C:\Program Files (x86)\McAfee
2013-07-26 15:42 - 2010-12-06 13:26 - 00000000 ____D C:\Users\Brad\AppData\Roaming\Skype
2013-07-26 15:41 - 2013-05-01 22:51 - 00000000 ____D C:\Program Files\Common Files\McAfee
2013-07-26 14:54 - 2010-12-06 13:26 - 00000000 ____D C:\ProgramData\Skype
2013-07-26 14:53 - 2010-12-06 13:26 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-26 14:52 - 2012-04-02 10:41 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-26 14:52 - 2012-04-02 10:41 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-26 14:52 - 2011-05-19 10:53 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-26 12:10 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-25 14:25 - 2013-07-25 14:25 - 00000903 _____ C:\Users\Brad\Desktop\marjan list.txt
2013-07-25 11:11 - 2013-07-25 11:11 - 00347424 _____ (Microsoft Corporation) C:\Users\Brad\Downloads\MicrosoftFixit.Performance.RNP.148298206684651127.1.1.Run.exe
2013-07-24 16:23 - 2013-07-24 16:23 - 00000565 _____ C:\Users\Brad\Desktop\outbind___118-0000000084398BB311C2CA458D2FD45E450A24D7C4013B00_.log
2013-07-24 08:42 - 2009-07-13 22:08 - 00032548 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-22 11:39 - 2012-11-14 12:43 - 00000000 ___RD C:\Users\Brad\Dropbox
2013-07-22 11:38 - 2012-11-14 12:39 - 00000000 ____D C:\Users\Brad\AppData\Roaming\Dropbox
2013-07-18 20:56 - 2009-07-13 22:13 - 00784866 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-18 13:25 - 2013-07-18 13:25 - 00013824 _____ C:\Users\Brad\Desktop\h2h merge list.xls
2013-07-18 13:24 - 2013-07-18 13:24 - 00179200 _____ C:\Users\Brad\Desktop\Heels2Heal - Master Email List 122012.xls
2013-07-18 13:24 - 2013-07-18 13:24 - 00013824 _____ C:\Users\Brad\Desktop\Untitled_2.xls
2013-07-17 18:31 - 2011-12-05 16:57 - 00000132 _____ C:\Users\Brad\AppData\Roaming\Adobe GIF Format CS5 Prefs
2013-07-17 15:23 - 2013-07-17 15:23 - 00002992 _____ C:\Windows\System32\Tasks\{28F9DE3A-EB52-42FD-910D-F57E82B718F8}
2013-07-16 20:32 - 2013-07-16 20:32 - 00003166 _____ C:\Windows\System32\Tasks\{BC8072FC-1496-433D-8C5B-3547AC44FD86}
2013-07-15 15:17 - 2013-07-15 15:17 - 00003018 _____ C:\Windows\System32\Tasks\{678D49C1-EC9F-426C-A6B0-61591E80F1C8}
2013-07-15 14:48 - 2011-01-06 16:23 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-15 13:59 - 2013-07-15 13:59 - 00002992 _____ C:\Windows\System32\Tasks\{1D3770CB-5FED-4E9B-9D7C-A1C7809B550E}
2013-07-15 11:09 - 2013-07-15 11:09 - 00002992 _____ C:\Windows\System32\Tasks\{44673710-7822-4101-86AF-355316935067}
2013-07-12 15:21 - 2013-07-12 15:09 - 00000000 ____D C:\Users\Brad\Desktop\postcard
2013-07-12 13:25 - 2011-08-04 08:32 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-12 13:25 - 2011-08-04 08:32 - 00003638 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-12 12:46 - 2011-06-06 16:45 - 00003876 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001UA
2013-07-12 12:46 - 2011-06-06 16:45 - 00003480 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001Core
2013-07-12 10:28 - 2013-07-12 10:28 - 00003018 _____ C:\Windows\System32\Tasks\{BC8299F2-3DA6-428C-B57C-1C7CC7DFF259}
2013-07-12 10:28 - 2013-07-12 10:28 - 00003018 _____ C:\Windows\System32\Tasks\{4B4101E6-C46E-469F-92AB-1FE0584EA08E}
2013-07-11 14:28 - 2013-07-11 14:28 - 00002992 _____ C:\Windows\System32\Tasks\{E47AF7BD-3D44-46C4-9277-DE5EA16564BF}
2013-07-11 14:28 - 2011-01-24 09:59 - 00800126 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-07-11 14:15 - 2010-11-04 22:20 - 00000376 _____ C:\Windows\ODBC.INI
2013-07-11 14:14 - 2009-07-13 19:34 - 00000566 _____ C:\Windows\win.ini
2013-07-11 12:36 - 2013-07-11 12:33 - 209700978 _____ C:\Users\Brad\Downloads\HEALTHY BABIES 5K KNSD-TV 5-6-13 11am.mov
2013-07-11 12:34 - 2013-07-11 12:33 - 45055049 _____ C:\Users\Brad\Downloads\MIRACLE BABIES BBQ KSWB-TV 7-6-13 10PM.mov
2013-07-11 12:33 - 2013-07-11 12:33 - 21733048 _____ C:\Users\Brad\Downloads\MIRACLE BABIES BBQ XETV-TV 7-6-13 10PM.mov
2013-07-11 11:31 - 2013-07-11 11:28 - 00906440 _____ (BillP Studios) C:\Users\Brad\Downloads\wpsetup.exe
2013-07-09 17:54 - 2013-07-09 14:49 - 00012141 _____ C:\Users\Brad\Desktop\h2h-board.html
2013-07-09 17:17 - 2013-07-05 10:35 - 00000000 ____D C:\Users\Brad\Desktop\virus
2013-07-09 17:16 - 2013-07-06 12:38 - 00000000 ____D C:\Windows\erdnt
2013-07-09 13:40 - 2013-07-09 13:37 - 00000000 ____D C:\Windows\system32\MRT
2013-07-09 13:29 - 2010-11-01 13:09 - 00000000 ____D C:\Windows\Panther
2013-07-09 13:27 - 2012-07-09 18:39 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-09 13:27 - 2012-07-09 18:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-09 13:25 - 2009-07-13 22:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-09 13:25 - 2009-07-13 22:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-09 13:24 - 2009-07-14 00:47 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-09 13:17 - 2013-07-09 13:14 - 00000000 ____D C:\4b7ba50c5139b70223506ca3
2013-07-09 10:23 - 2013-07-09 10:23 - 00000000 ___HD C:\Windows\AxInstSV
2013-07-09 10:15 - 2013-07-09 10:15 - 00000000 ____D C:\Users\Brad\Desktop\backups
2013-07-09 08:09 - 2013-07-09 08:09 - 00000000 _____ C:\Windows\setuperr.log
2013-07-08 12:18 - 2013-07-08 12:17 - 00014973 _____ C:\Users\Brad\Desktop\hijackthis.log
2013-07-08 12:12 - 2013-07-08 12:12 - 00388608 _____ (Trend Micro Inc.) C:\Users\Brad\Desktop\HijackThis.exe
2013-07-08 11:52 - 2013-07-08 11:51 - 00221172 _____ C:\Users\Brad\Desktop\cc_20130708_115155.reg
2013-07-08 11:43 - 2010-11-01 13:15 - 00000000 ____D C:\Program Files (x86)\Steam
2013-07-08 11:34 - 2013-07-08 11:34 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-07-08 11:34 - 2013-07-08 11:34 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-08 11:34 - 2013-07-08 11:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-08 11:34 - 2013-07-08 11:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-08 11:34 - 2013-07-08 11:34 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-08 11:34 - 2010-11-01 10:42 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-07-08 11:34 - 2010-11-01 10:42 - 00000000 ____D C:\Program Files (x86)\Java
2013-07-08 11:16 - 2013-07-08 11:16 - 00001270 _____ C:\Users\Brad\Desktop\Revo Uninstaller.lnk
2013-07-07 10:39 - 2009-07-13 19:34 - 00000215 _____ C:\Windows\system.ini
2013-07-06 12:50 - 2013-07-03 15:58 - 81264640 _____ C:\Windows\system32\config\SOFTWARE.bak
2013-07-06 12:50 - 2009-07-13 19:34 - 25427968 _____ C:\Windows\system32\config\SYSTEM.bak
2013-07-06 12:50 - 2009-07-13 19:34 - 01048576 _____ C:\Windows\system32\config\DEFAULT.bak
2013-07-06 12:50 - 2009-07-13 19:34 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak
2013-07-06 12:50 - 2009-07-13 19:34 - 00262144 _____ C:\Windows\system32\config\SAM.bak
2013-07-05 19:05 - 2013-07-05 19:05 - 00000000 ____D C:\Windows\ERUNT
2013-07-05 19:05 - 2013-07-05 19:05 - 00000000 ____D C:\JRT
2013-07-03 15:24 - 2013-07-03 15:24 - 00003070 _____ C:\Windows\System32\Tasks\{9B7926D2-EB22-4D6A-A80A-73E4F0BFA890}
2013-07-03 12:53 - 2011-04-10 14:20 - 00072448 _____ C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT
2013-07-03 12:53 - 2011-02-04 09:30 - 00072448 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2013-07-03 12:45 - 2012-05-10 09:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-03 12:42 - 2013-07-02 14:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-01 12:26 - 2013-07-01 12:25 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-07-01 12:26 - 2013-07-01 12:25 - 00000000 ____D C:\Program Files\iTunes
2013-07-01 12:26 - 2011-01-30 13:48 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-07-01 12:25 - 2013-07-01 12:25 - 00000000 ____D C:\Program Files\iPod
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-23 11:22
==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-07-2013 03
Ran by Brad at 2013-07-31 19:28:41
Running from C:\Users\Brad\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================

64 Bit HP CIO Components Installer (Version: 7.2.8)
Adobe Acrobat 9 Pro - English, Français, Deutsch (x32 Version: 9.5.5)
Adobe Acrobat 9.5.5 - CPSID_83708 (x32)
Adobe AIR (x32 Version: 3.7.0.1860)
Adobe CMM (x32 Version: 1.1)
Adobe Color Common Settings (x32 Version: 1.0.1)
Adobe Community Help (x32 Version: 3.5.23)
Adobe Connect Add-in (HKCU)
Adobe Creative Suite 5 Design Premium (x32 Version: 5.0)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Media Player (x32 Version: 1.8)
Adobe Setup (x32 Version: 1.0)
Adobe Setup (x32 Version: 2.0)
Adobe Widget Browser (x32 Version: 1.0 Build 543)
Adobe Widget Browser (x32 Version: 1.0.543)
Advertising Center (x32 Version: 0.0.0.2)
AIO_CDB_Software (x32 Version: 130.0.365.000)
AIO_Scan (x32 Version: 130.0.421.000)
AlienRespawn - Support Software (x32)
AlienRespawn (x32 Version: 9.4.48)
Alienware Command Center (Version: 2.8.9.0)
Alienware Command Center (x32 Version: 2.8.9.0)
Amazon MP3 Downloader 1.0.17 (x32 Version: 1.0.17)
Android SDK Tools (x32 Version: 1.16)
Any Video Converter 3.2.3 (x32)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
ATI Catalyst Control Center (x32 Version: 2.010.0803.2124)
Banctec Service Agreement (x32 Version: 2.0.0)
Bonjour (Version: 3.0.0.10)
BufferChm (x32 Version: 130.0.331.000)
CameraHelperMsi (x32 Version: 13.31.1038.0)
CANON iMAGE GATEWAY Task for ZoomBrowser EX (x32 Version: 1.7.2.11)
Canon Internet Library for ZoomBrowser EX (x32 Version: 1.6.3.9)
Canon MOV Decoder (x32 Version: 1.5.0.7)
Canon MOV Encoder (x32 Version: 1.3.1.3)
Canon MovieEdit Task for ZoomBrowser EX (x32 Version: 3.4.1.9)
Canon Utilities Digital Photo Professional 3.8 (x32 Version: 3.8.1.0)
Canon Utilities EOS Utility (x32 Version: 2.8.1.0)
Canon Utilities PhotoStitch (x32 Version: 3.1.22.46)
Canon Utilities Picture Style Editor (x32 Version: 1.7.0.0)
Canon Utilities WFT Utility (x32 Version: 3.5.1.1)
Canon Utilities ZoomBrowser EX (x32 Version: 6.5.1.15)
Canon ZoomBrowser EX Memory Card Utility (x32 Version: 1.3.0.4)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0803.2125.36577)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0803.2125.36577)
Catalyst Control Center InstallProxy (x32 Version: 2010.0803.2125.36577)
Catalyst Control Center Localization All (x32 Version: 2010.0803.2125.36577)
CCC Help Chinese Standard (x32 Version: 2010.0803.2124.36577)
CCC Help Chinese Traditional (x32 Version: 2010.0803.2124.36577)
CCC Help Czech (x32 Version: 2010.0803.2124.36577)
CCC Help Danish (x32 Version: 2010.0803.2124.36577)
CCC Help Dutch (x32 Version: 2010.0803.2124.36577)
CCC Help English (x32 Version: 2010.0803.2124.36577)
CCC Help Finnish (x32 Version: 2010.0803.2124.36577)
CCC Help French (x32 Version: 2010.0803.2124.36577)
CCC Help German (x32 Version: 2010.0803.2124.36577)
CCC Help Greek (x32 Version: 2010.0803.2124.36577)
CCC Help Hungarian (x32 Version: 2010.0803.2124.36577)
CCC Help Italian (x32 Version: 2010.0803.2124.36577)
CCC Help Japanese (x32 Version: 2010.0803.2124.36577)
CCC Help Korean (x32 Version: 2010.0803.2124.36577)
CCC Help Norwegian (x32 Version: 2010.0803.2124.36577)
CCC Help Polish (x32 Version: 2010.0803.2124.36577)
CCC Help Portuguese (x32 Version: 2010.0803.2124.36577)
CCC Help Russian (x32 Version: 2010.0803.2124.36577)
CCC Help Spanish (x32 Version: 2010.0803.2124.36577)
CCC Help Swedish (x32 Version: 2010.0803.2124.36577)
CCC Help Thai (x32 Version: 2010.0803.2124.36577)
CCC Help Turkish (x32 Version: 2010.0803.2124.36577)
ccc-core-static (x32 Version: 2010.0803.2125.36577)
ccc-utility64 (Version: 2010.0803.2125.36577)
Citrix XenApp Plugin for Hosted Apps (x32 Version: 11.0.0.5357)
Compatibility Pack for the 2007 Office system (x32 Version: 12.0.6612.1000)
Copy (x32 Version: 130.0.428.000)
CyberLink PowerDVD 9.5 (x32 Version: 9.5.0.2829)
Dell DataSafe Online (x32 Version: 1.2.0011)
Dell Driver Download Manager (HKCU Version: 2.1.0.0)
Destinations (x32 Version: 130.0.0.0)
DeviceDiscovery (x32 Version: 130.0.465.000)
DocProc (x32 Version: 13.0.0.0)
Dropbox (HKCU Version: 1.6.18)
eReg (x32 Version: 1.20.138.34)
Extensis Suitcase 11.0.1 (x32 Version: 11.0.1)
Fax (x32 Version: 130.0.418.000)
Google Apps Migration For Microsoft Outlook® 2.3.14.36 (x32 Version: 2.3.14.36)
Google Apps Sync™ for Microsoft Outlook® 3.3.355.950 (x32 Version: 3.3.355.950)
Google Calendar Sync (x32)
Google Chrome (HKCU Version: 28.0.1500.95)
Google Update Helper (x32 Version: 1.3.21.153)
GPBaseService2 (x32 Version: 130.0.371.000)
HP Customer Participation Program 13.0 (Version: 13.0)
HP Photosmart Essential 3.5 (Version: 3.5)
HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (Version: 13.0)
HP Smart Web Printing 4.51 (Version: 4.51)
HP Update (x32 Version: 4.000.011.006)
HPDiagnosticAlert (x32 Version: 1.00.0000)
HPPhotoGadget (x32 Version: 130.0.282.000)
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000)
HPPhotosmartEssential (x32 Version: 2.04.0000)
HPSSupply (x32 Version: 130.0.371.000)
Imaging Device Functions 13.0 (Version: 13.0)
ImagXpress (x32 Version: 7.0.74.0)
Intel® Control Center (x32 Version: 1.2.1.1007)
Intel® Rapid Storage Technology (x32 Version: 9.6.0.1014)
iTunes (Version: 11.0.4.4)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Java™ 6 Update 20 (64-bit) (Version: 6.0.200)
Java™ 7 Update 2 (64-bit) (Version: 7.0.20)
Java™ SE Development Kit 7 Update 2 (64-bit) (Version: 1.7.0.20)
JavaFX 2.0.2 (64-bit) (Version: 2.0.2)
JavaFX 2.0.2 SDK (64-bit) (Version: 2.0.2)
JNLP (HKCU)
Logitech Harmony Remote Software 7 (x32 Version: 7.6.0.8)
Logitech SetPoint 6.52 (Version: 6.52.74)
Logitech Vid HD (x32 Version: 7.2 (7253))
Logitech Webcam Software (x32 Version: 2.30)
LWS Facebook (x32 Version: 13.31.1038.0)
LWS Gallery (x32 Version: 13.31.1038.0)
LWS Help_main (x32 Version: 13.31.1044.0)
LWS Launcher (x32 Version: 13.31.1038.0)
LWS Motion Detection (x32 Version: 13.30.1395.0)
LWS Pictures And Video (x32 Version: 13.31.1038.0)
LWS Twitter (x32 Version: 13.30.1346.0)
LWS Video Mask Maker (x32 Version: 13.30.1379.0)
LWS VideoEffects (Version: 13.30.1379.0)
LWS Webcam Software (x32 Version: 13.31.1038.0)
LWS WLM Plugin (x32 Version: 1.30.1201.0)
LWS YouTube Plugin (x32 Version: 13.31.1038.0)
MarketResearch (x32 Version: 130.0.374.000)
McAfee Online Backup (Version: 1.16.4.0)
McAfee Online Backup (x32)
McAfee Total Protection (x32 Version: 12.1.353)
McAfee Virtual Technician (x32 Version: 6.5.0.2101)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Office 2003 Primary Interop Assemblies (x32 Version: 11.0.6553.0)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Professional Edition 2003 (x32 Version: 11.0.8173.0)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (x32 Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual Studio 2005 Tools for Office Runtime (x32 Version: 8.0.60940.0)
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053)
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000)
Mozilla Firefox 22.0 (x86 en-US) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
MSXML 4.0 SP2 Parser and SDK (x32 Version: 4.20.9818.0)
Nero 9 Essentials (x32)
Nero BurnRights (x32 Version: 3.4.13.100)
Nero BurnRights Help (x32 Version: 3.4.4.100)
Nero ControlCenter (x32 Version: 9.0.0.1)
Nero CoverDesigner (x32 Version: 4.4.12.100)
Nero CoverDesigner Help (x32 Version: 4.4.9.100)
Nero Disc Copy Gadget (x32 Version: 2.4.34.0)
Nero Disc Copy Gadget Help (x32 Version: 2.4.34.0)
Nero DiscSpeed (x32 Version: 5.4.13.100)
Nero DiscSpeed Help (x32 Version: 5.4.4.100)
Nero DriveSpeed (x32 Version: 4.4.12.100)
Nero DriveSpeed Help (x32 Version: 4.4.4.100)
Nero Express Help (x32 Version: 9.4.26.100)
Nero InfoTool (x32 Version: 6.4.12.100)
Nero InfoTool Help (x32 Version: 6.4.4.100)
Nero Installer (x32 Version: 4.4.9.0)
Nero Online Upgrade (x32 Version: 1.3.0.0)
Nero Rescue Agent (x32 Version: 2.4.14.100)
Nero RescueAgent Help (x32 Version: 2.4.4.100)
Nero StartSmart (x32 Version: 9.4.19.100)
Nero StartSmart Help (x32 Version: 9.4.19.100)
NeroExpress (x32 Version: 9.4.26.100)
neroxml (x32 Version: 1.0.0)
Network64 (Version: 130.0.572.000)
OCR Software by I.R.I.S. 13.0 (Version: 13.0)
Package: Galaxy Nexus ToolKit [JellyBean Edition] (x32 Version: 1.0.0.0)
PDF Settings CS5 (x32 Version: 10.0)
Picasa 3 (x32 Version: 3.9)
QuickBooks (x32 Version: 22.0.4012.2206)
QuickBooks File Doctor (x32 Version: 3.5.1)
QuickBooks Pro 2012 (x32 Version: 22.0.4012.2206)
QuickTime (x32 Version: 7.74.80.86)
Realtek Ethernet Diagnostic Utility (x32 Version: 1.00.0000)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6039)
Remote Control USB Driver (x32 Version: 2.3.2.317)
Revo Uninstaller 1.95 (x32 Version: 1.95)
Safari (x32 Version: 5.34.57.2)
SAMSUNG USB Driver for Mobile Phones (Version: 1.4.6.0)
Scan (x32 Version: 13.0.0.0)
Shared C Run-time for x64 (Version: 10.0.0)
Shop for HP Supplies (Version: 13.0)
Skins (x32 Version: 2010.0803.2125.36577)
Skype Click to Call (x32 Version: 5.10.9560)
Skype™ 6.6 (x32 Version: 6.6.106)
SmartWebPrinting (x32 Version: 130.0.457.000)
Status (x32 Version: 130.0.469.000)
Steam (x32 Version: 1.0.0.0)
StuffIt 12 (x32 Version: 12.0.0)
StuffIt Expander 2011 (Version: 15.0.0.12)
SupportSoft Assisted Service (x32 Version: 15)
TeamViewer 8 (x32 Version: 8.0.18051)
THX TruStudio PC (x32 Version: 1.0)
Toolbox (x32 Version: 130.0.648.000)
TrayApp (x32 Version: 130.0.422.000)
TweetDeck (x32 Version: 1.5.3)
UnloadSupport (x32 Version: 11.0.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
ViewSonic Monitor Drivers (x32)
Visual Studio 2005 Tools for Office Second Edition Runtime (x32)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
WD Discovery Software (x32 Version: 1.80)
WebReg (x32 Version: 130.0.132.017)
Windows Live OneCare safety scanner (x32 Version: 1.0.0.0)
==================== Restore Points =========================
22-07-2013 17:40:40 Windows Update
26-07-2013 16:15:24 Windows Update
26-07-2013 21:50:01 McAfee Vulnerability Scanner
30-07-2013 16:11:29 Windows Update
==================== Hosts content: ==========================
2009-07-13 19:34 - 2013-07-06 12:53 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {09A9BC5F-9D5D-4E53-92F8-D976DD9F811F} - System32\Tasks\{1D3770CB-5FED-4E9B-9D7C-A1C7809B550E} => C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE [2010-06-23] (Microsoft Corporation)
Task: {0FFAE243-DCBC-4E93-B452-3977137FB54C} - System32\Tasks\{678D49C1-EC9F-426C-A6B0-61591E80F1C8} => C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02] (Google)
Task: {13732A63-2DF9-4EFB-AB05-0477196EA4C1} - System32\Tasks\{E47AF7BD-3D44-46C4-9277-DE5EA16564BF} => C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE [2010-06-23] (Microsoft Corporation)
Task: {14EABC6D-2D28-4826-B69A-C0BEFD4D2AC3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {17992B1D-0C0B-40C7-9C97-54DD09DD0E3B} - System32\Tasks\{BC8299F2-3DA6-428C-B57C-1C7CC7DFF259} => C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02] (Google)
Task: {32157ED4-96DA-4C2E-9C32-687231FAF483} - System32\Tasks\{F29A811E-A1CF-4B06-AF08-28054007C1BC} => c:\program No File
Task: {3F47EB3C-DDB9-460C-88FF-7B20303B1A37} - System32\Tasks\{1DA23EF3-3907-4908-ADC0-06B97885AC20} => C:\Users\Brad\Desktop\qbcmtool\Clean Install Tool.exe No File
Task: {4C27C430-5DB8-486C-92D2-67B0A1109357} - System32\Tasks\{99A81893-433E-4824-B1BF-58A6CAA4250C} => F:\setup.exe No File
Task: {50520C19-0021-4438-8CDF-F54345516C40} - System32\Tasks\{F06A6717-C58B-4593-99BB-303D42918D52} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.)
Task: {514E35BB-65BB-4A83-BB4C-1DE5C41FD437} - System32\Tasks\{0F528EB4-0693-4913-A7EF-527E6CFC2A19} => C:\Program Files (x86)\Citrix\ICA Client\pnagent.exe [2008-08-16] (Citrix Systems, Inc.)
Task: {56C7C4D0-CC4A-4DA3-A54F-769B4FE91C62} - System32\Tasks\{95C4281C-E3EA-4C4B-BD52-66C31057FD85} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe No File
Task: {57450C74-5580-4E68-A3F7-7B6AFA0CE597} - System32\Tasks\{2C17CA57-C82E-4955-85D6-8917071C3141} => C:\Program Files (x86)\Citrix\ICA Client\pnagent.exe [2008-08-16] (Citrix Systems, Inc.)
Task: {6485C085-43DF-4939-84E7-1B2CB99DB537} - System32\Tasks\{67F548FF-3FB0-4C00-A1D7-90AF2C840E58} => C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32Pro.exe [2012-12-06] (Intuit Inc.)
Task: {66AA6639-9099-4C13-8D71-32738134E878} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-13] (Microsoft Corporation)
Task: {7C23650D-5702-41FE-B7BC-68C573D4E51C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-26] (Adobe Systems Incorporated)
Task: {84CEA976-2C05-4DA8-BEA7-4EC244940066} - System32\Tasks\{9B7926D2-EB22-4D6A-A80A-73E4F0BFA890} => C:\Windows\System32\msiexec.exe [2010-11-20] (Microsoft Corporation)
Task: {8C5235AE-FDC9-49B8-8114-13E56348AEE1} - System32\Tasks\PC Shutdown => C:\Windows\System32\shutdown.exe [2009-07-13] (Microsoft Corporation)
Task: {9E3E2F7B-C77B-44EB-B6AA-F5FCEC8621C9} - System32\Tasks\{5C6966FF-D0D3-4070-8B67-B7C4D5F5A2F0} => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-09-20] (Hewlett-Packard Co.)
Task: {A36A6BD9-A3A6-4403-89EF-3AA88A53D736} - System32\Tasks\{6D33044D-768E-4156-A672-8F855411BC2B} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe No File
Task: {ACE58F49-9426-4E83-A7DC-3EECB0258348} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-04] (Google Inc.)
Task: {B097E122-62D5-412C-B4FD-16EE5BDAD1A9} - System32\Tasks\{4327C7C4-AB6A-4AAB-B24C-F326DC8977C3} => F:\Setup.exe No File
Task: {B13E497E-41F5-44EE-9DBE-B1386DEE40A0} - System32\Tasks\{CF881962-9184-413A-89F4-CC43304C18BA} => F:\Setup.exe No File
Task: {B55DB068-3705-4FEF-A0D8-CBCC7083C9A7} - System32\Tasks\AdobeAAMUpdater-1.0-designremedy-Brad => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {B7C712C4-BE4E-44DE-801C-458889F0B81D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-04] (Google Inc.)
Task: {BC787C03-752C-4016-A4C3-D67EB75BD9A2} - System32\Tasks\{F6CCC47A-E805-449A-9F3C-47A7C1D7D68A} => F:\Setup.exe No File
Task: {C22E1176-86BF-49AA-B345-A577BF257ECD} - System32\Tasks\{28F9DE3A-EB52-42FD-910D-F57E82B718F8} => C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE [2010-06-23] (Microsoft Corporation)
Task: {C8718CD6-067A-4215-87FA-36A5DB843786} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001UA => C:\Users\Brad\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-06] (Google Inc.)
Task: {C9D7CE16-F43A-4EAD-8104-48D9A57B2340} - System32\Tasks\{44673710-7822-4101-86AF-355316935067} => C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE [2010-06-23] (Microsoft Corporation)
Task: {CAC80B37-CD8D-4338-8EB4-5C0ABEF171CF} - System32\Tasks\{48DFFA26-24FA-47A4-B5A0-E0F1CA4DE9A9} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe No File
Task: {D135C0FD-65F8-48CC-AC74-7369948EDB82} - System32\Tasks\{62E59FB3-71F0-4491-9CBB-F162743449B8} => C:\Program Files (x86)\Hemera\The Big Box of Art 350,000 collection\GraphicsDesk.exe No File
Task: {D8DB3C76-E5C5-4189-BA5C-633B07D08493} - System32\Tasks\{4B4101E6-C46E-469F-92AB-1FE0584EA08E} => C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02] (Google)
Task: {DAC13410-08BE-4F16-AC4A-799720163BD3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001Core => C:\Users\Brad\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-06] (Google Inc.)
Task: {E2BA8F4E-F819-42B2-BF59-2B12211AC093} - System32\Tasks\{AB87F8FB-1AD1-4330-9C32-A907F342727D} => c:\program No File
Task: {FBBE3FED-E299-4D59-B4B9-00B76FD66C44} - System32\Tasks\{EFF9B145-71E2-4159-B691-48C8A0AFF879} => C:\Users\Brad\Desktop\qbcmtool\Clean Install Tool.exe No File
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AdobeAAMUpdater-1.0-designremedy-Brad.job => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001Core.job => C:\Users\Brad\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3143275825-1710083395-3427249252-1001UA.job => C:\Users\Brad\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Faulty Device Manager Devices =============
Name: Officejet 7300 series
Description: Officejet 7300 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/31/2013 06:12:26 PM) (Source: Application Hang) (User: )
Description: The program IEXPLORE.EXE version 10.0.9200.16635 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1ea8
Start Time: 01ce8e536f03b3c3
Termination Time: 6
Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Report Id:
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
DMError Information:-6069Additional Info:An Invalid Id or password was specified.
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Design Remedy 022613.QBW;ENG=QB_data_engine_22;DBN=6a0d59c8f9cc46138dd5ae28f5f3cef1
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
Connection Error:Invalid user ID or password
Error: (07/31/2013 03:30:35 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'
Error: (07/31/2013 03:30:35 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Design Remedy 022613.QBW;ENG=QB_data_engine_22;DBN=febb3185132b432e91387766e4d91bb3
Error: (07/31/2013 03:30:35 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
Connection Error:Invalid user ID or password
Error: (07/31/2013 03:30:21 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'
Error: (07/31/2013 03:30:21 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2012":
Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Design Remedy 022613.QBW;ENG=QB_data_engine_22;DBN=a385040011b042ce955be15cf13347f3
System errors:
=============
Error: (07/31/2013 03:07:25 PM) (Source: BTHUSB) (User: )
Description: The Bluetooth driver expected an HCI event with a certain size but did not receive it.
Error: (07/31/2013 03:05:25 PM) (Source: Service Control Manager) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the mfecore service.
Error: (07/31/2013 11:38:39 AM) (Source: DCOM) (User: )
Description: "C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE" -Embedding740{0006F03A-0000-0000-C000-000000000046}
Error: (07/31/2013 11:01:44 AM) (Source: Service Control Manager) (User: )
Description: The QBCFMonitorService service terminated unexpectedly. It has done this 1 time(s).
Error: (07/30/2013 04:22:01 PM) (Source: DCOM) (User: )
Description: "C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE" -Embedding740{0006F03A-0000-0000-C000-000000000046}
Error: (07/30/2013 03:44:56 PM) (Source: DCOM) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (07/30/2013 11:42:11 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: machine-defaultLocalActivation{10DA4F3C-CC99-4190-BE4D-58330754E882}{7DDEFEA6-98EE-4F13-A25B-EC83D9BC5541}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)
Error: (07/26/2013 06:15:00 PM) (Source: DCOM) (User: )
Description: {211EBA3A-EA5A-496B-A021-5C6BEB365E4C}
Error: (07/26/2013 03:41:34 PM) (Source: DCOM) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (07/26/2013 11:58:46 AM) (Source: BTHUSB) (User: )
Description: The Bluetooth driver expected an HCI event with a certain size but did not receive it.
Microsoft Office Sessions:
=========================
Error: (07/31/2013 06:12:26 PM) (Source: Application Hang)(User: )
Description: IEXPLORE.EXE10.0.9200.166351ea801ce8e536f03b3c36C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012DMError Information:-6069Additional Info:An Invalid Id or password was specified.
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Design Remedy 022613.QBW;ENG=QB_data_engine_22;DBN=6a0d59c8f9cc46138dd5ae28f5f3cef1
Error: (07/31/2013 03:30:42 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012Connection Error:Invalid user ID or password
Error: (07/31/2013 03:30:35 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'
Error: (07/31/2013 03:30:35 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Design Remedy 022613.QBW;ENG=QB_data_engine_22;DBN=febb3185132b432e91387766e4d91bb3
Error: (07/31/2013 03:30:35 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012Connection Error:Invalid user ID or password
Error: (07/31/2013 03:30:21 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'
Error: (07/31/2013 03:30:21 PM) (Source: QuickBooks)(User: )
Description: QuickBooks Pro 2012Connection String:CON=QBConnectionPool-Probe-QB_data_engine_22; ;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Design Remedy 022613.QBW;ENG=QB_data_engine_22;DBN=a385040011b042ce955be15cf13347f3
CodeIntegrity Errors:
===================================
Date: 2013-07-31 15:17:35.170
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-07-31 15:17:35.167
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-07-31 15:17:35.163
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-07-31 15:17:35.060
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-07-06 12:48:42.851
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-07-06 12:48:42.696
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-06-11 21:47:35.561
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Users\Brad\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-06-11 21:47:35.429
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Users\Brad\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-06-11 21:47:34.066
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Users\Brad\Desktop\everest\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-06-11 21:47:33.932
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Users\Brad\Desktop\everest\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Percentage of memory in use: 39%
Total physical RAM: 4087.08 MB
Available physical RAM: 2457.38 MB
Total Pagefile: 9548.55 MB
Available Pagefile: 6671.88 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:919.96 GB) (Free:813.67 GB) NTFS (Disk=0 Partition=3)
Drive d: (DATAPART1) (Fixed) (Total:931.51 GB) (Free:508.41 GB) NTFS (Disk=1 Partition=1)
Drive e: (WDO_Media64) (CDROM) (Total:0.32 GB) (Free:0 GB) UDF
Drive g: (Public) (Network) (Total:928.3 GB) (Free:443.59 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: C796C701)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=12 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=920 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: A94B125C)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)
==================== End Of Log ============================

Edited by Oh My, 31 July 2013 - 09:37 PM.


#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,619 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:39 AM

Posted 31 July 2013 - 10:01 PM

Hi Brad,

Can you tell me if you notice any problems with your computer performance (other than Outlook) apart from these notifications?

Please run this to clean out some unwanted stuff.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
HKLM-x32\...\Run: [] - [x]
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO-x32: No Name - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - No File
Handler: msdaipp - No CLSID Value -
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: msdaipp - No CLSID Value -
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll No File
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Virtual Technician) - C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll No File
Task: {32157ED4-96DA-4C2E-9C32-687231FAF483} - System32\Tasks\{F29A811E-A1CF-4B06-AF08-28054007C1BC} => c:\program No File
Task: {3F47EB3C-DDB9-460C-88FF-7B20303B1A37} - System32\Tasks\{1DA23EF3-3907-4908-ADC0-06B97885AC20} => C:\Users\Brad\Desktop\qbcmtool\Clean Install Tool.exe No File
Task: {4C27C430-5DB8-486C-92D2-67B0A1109357} - System32\Tasks\{99A81893-433E-4824-B1BF-58A6CAA4250C} => F:\setup.exe No File
Task: {56C7C4D0-CC4A-4DA3-A54F-769B4FE91C62} - System32\Tasks\{95C4281C-E3EA-4C4B-BD52-66C31057FD85} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe No File
Task: {A36A6BD9-A3A6-4403-89EF-3AA88A53D736} - System32\Tasks\{6D33044D-768E-4156-A672-8F855411BC2B} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe No File
Task: {B097E122-62D5-412C-B4FD-16EE5BDAD1A9} - System32\Tasks\{4327C7C4-AB6A-4AAB-B24C-F326DC8977C3} => F:\Setup.exe No File
Task: {B13E497E-41F5-44EE-9DBE-B1386DEE40A0} - System32\Tasks\{CF881962-9184-413A-89F4-CC43304C18BA} => F:\Setup.exe No File
Task: {BC787C03-752C-4016-A4C3-D67EB75BD9A2} - System32\Tasks\{F6CCC47A-E805-449A-9F3C-47A7C1D7D68A} => F:\Setup.exe No File
Task: {CAC80B37-CD8D-4338-8EB4-5C0ABEF171CF} - System32\Tasks\{48DFFA26-24FA-47A4-B5A0-E0F1CA4DE9A9} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe No File
Task: {D135C0FD-65F8-48CC-AC74-7369948EDB82} - System32\Tasks\{62E59FB3-71F0-4491-9CBB-F162743449B8} => C:\Program Files (x86)\Hemera\The Big Box of Art 350,000 collection\GraphicsDesk.exe No File
Task: {E2BA8F4E-F819-42B2-BF59-2B12211AC093} - System32\Tasks\{AB87F8FB-1AD1-4330-9C32-A907F342727D} => c:\program No File
Task: {FBBE3FED-E299-4D59-B4B9-00B76FD66C44} - System32\Tasks\{EFF9B145-71E2-4159-B691-48C8A0AFF879} => C:\Users\Brad\Desktop\qbcmtool\Clean Install Tool.exe No File
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog log
  • Computer performance?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 bkdesign

bkdesign
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 31 July 2013 - 10:17 PM

Thanks for your reply.  My system has been running a little slow and I am not sure if it's a memory issue or what.   My CPU usage history and Physical Memory Usage History have been really high and I am not really sure why.  Also when I did a scan a few days ago with Microsoft Mr Fixit it said that another user was logged into my computer.  I am the only one that uses this computer and I have no other user accounts created.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 30-07-2013 03
Ran by Brad at 2013-07-31 20:08:50 Run:1
Running from C:\Users\Brad\Desktop
Boot Mode: Normal
==============================================

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully.
HKCR\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Value deleted successfully.
HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Key not found.
HKCR\PROTOCOLS\Handler\intu-help-qb5 => Key deleted successfully.
HKCR\CLSID\{867FCB77-9823-4cd6-8210-D85F968D466F} => Key not found.
HKCR\PROTOCOLS\Handler\Handler: msdaipp - No CLSID Value - => Key not found.
HKCR\PROTOCOLS\Handler\qbwc => Key deleted successfully.
HKCR\CLSID\{FC598A64-626C-4447-85B8-53150405FD57} => Key not found.
HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully.
HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\Handler-x32: msdaipp - No CLSID => Key not found.
HKCR\PROTOCOLS\Filter\text/xml => Key deleted successfully.
HKCR\CLSID\{807553E5-5146-11D5-A672-00B0D022E945} => Key not found.
C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll not found.
C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll not found.
C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll not found.
C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll not found.
C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll not found.
C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{32157ED4-96DA-4C2E-9C32-687231FAF483} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32157ED4-96DA-4C2E-9C32-687231FAF483} => Key deleted successfully.
C:\Windows\System32\Tasks\{F29A811E-A1CF-4B06-AF08-28054007C1BC} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F29A811E-A1CF-4B06-AF08-28054007C1BC} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\Task: {3F47EB3C-DDB9-460C-88FF-7B20303B1A37} - => Key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4C27C430-5DB8-486C-92D2-67B0A1109357} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C27C430-5DB8-486C-92D2-67B0A1109357} => Key deleted successfully.
C:\Windows\System32\Tasks\{99A81893-433E-4824-B1BF-58A6CAA4250C} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{99A81893-433E-4824-B1BF-58A6CAA4250C} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{56C7C4D0-CC4A-4DA3-A54F-769B4FE91C62} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56C7C4D0-CC4A-4DA3-A54F-769B4FE91C62} => Key deleted successfully.
C:\Windows\System32\Tasks\{95C4281C-E3EA-4C4B-BD52-66C31057FD85} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{95C4281C-E3EA-4C4B-BD52-66C31057FD85} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A36A6BD9-A3A6-4403-89EF-3AA88A53D736} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A36A6BD9-A3A6-4403-89EF-3AA88A53D736} => Key deleted successfully.
C:\Windows\System32\Tasks\{6D33044D-768E-4156-A672-8F855411BC2B} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6D33044D-768E-4156-A672-8F855411BC2B} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B097E122-62D5-412C-B4FD-16EE5BDAD1A9} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B097E122-62D5-412C-B4FD-16EE5BDAD1A9} => Key deleted successfully.
C:\Windows\System32\Tasks\{4327C7C4-AB6A-4AAB-B24C-F326DC8977C3} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4327C7C4-AB6A-4AAB-B24C-F326DC8977C3} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B13E497E-41F5-44EE-9DBE-B1386DEE40A0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B13E497E-41F5-44EE-9DBE-B1386DEE40A0} => Key deleted successfully.
C:\Windows\System32\Tasks\{CF881962-9184-413A-89F4-CC43304C18BA} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CF881962-9184-413A-89F4-CC43304C18BA} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC787C03-752C-4016-A4C3-D67EB75BD9A2} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC787C03-752C-4016-A4C3-D67EB75BD9A2} => Key deleted successfully.
C:\Windows\System32\Tasks\{F6CCC47A-E805-449A-9F3C-47A7C1D7D68A} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F6CCC47A-E805-449A-9F3C-47A7C1D7D68A} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CAC80B37-CD8D-4338-8EB4-5C0ABEF171CF} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CAC80B37-CD8D-4338-8EB4-5C0ABEF171CF} => Key deleted successfully.
C:\Windows\System32\Tasks\{48DFFA26-24FA-47A4-B5A0-E0F1CA4DE9A9} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{48DFFA26-24FA-47A4-B5A0-E0F1CA4DE9A9} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D135C0FD-65F8-48CC-AC74-7369948EDB82} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D135C0FD-65F8-48CC-AC74-7369948EDB82} => Key deleted successfully.
C:\Windows\System32\Tasks\{62E59FB3-71F0-4491-9CBB-F162743449B8} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{62E59FB3-71F0-4491-9CBB-F162743449B8} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E2BA8F4E-F819-42B2-BF59-2B12211AC093} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2BA8F4E-F819-42B2-BF59-2B12211AC093} => Key deleted successfully.
C:\Windows\System32\Tasks\{AB87F8FB-1AD1-4330-9C32-A907F342727D} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AB87F8FB-1AD1-4330-9C32-A907F342727D} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FBBE3FED-E299-4D59-B4B9-00B76FD66C44} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FBBE3FED-E299-4D59-B4B9-00B76FD66C44} => Key deleted successfully.
C:\Windows\System32\Tasks\{EFF9B145-71E2-4159-B691-48C8A0AFF879} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EFF9B145-71E2-4159-B691-48C8A0AFF879} => Key deleted successfully.

==== End of Fixlog ====



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,619 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:39 AM

Posted 31 July 2013 - 10:22 PM

OK, thanks.  I am finishing for the evening but I would like you to go into the Processes tab in Task Manager and list for me the 5 highest processes/readings in both the CPU and Memory columns.

 

I will check your reply first thing in the morning.

 

G'nite.......


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 bkdesign

bkdesign
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 31 July 2013 - 10:44 PM

As of right now the top 6 are:

 

ThermalController.exe 11,088K ThermalController

McUICnt.exe 10,072K McAfee

taskhost.exe 9,932K Host Process for Windows Tasks

iexplore.exe *32 8,916K Internet Explorer

iexplore.exe 8,512K Internet Explorer

AWCCServiceController.exe 7,788 Remoting Service Controller

 

Are these suppose to be running as well?  They don't have a user name associated to them like the others do:

 

winlogon.exe

atiedxx.exe

rundll32.exe

rundll32.exe

rundll32.exe



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,619 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:39 AM

Posted 01 August 2013 - 01:00 PM

Greetings,
 

winlogon.exe
atiedxx.exe
rundll32.exe
rundll32.exe
rundll32.exe

Can you tell me if there is any information in the Description category?

---------
 

ThermalController.exe 11,088K ThermalController
AWCCServiceController.exe 7,788 Remoting Service Controller

Please stop these 2 processes and let me know if you see any change in your computer performance.

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Descriptions?
  • Any change in computer performance?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 bkdesign

bkdesign
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 01 August 2013 - 01:16 PM

For these processes there is nothing in the description or user field.  See attached screenshot.

 

winlogon.exe
atiedxx.exe

csrss.exe
rundll32.exe
rundll32.exe
rundll32.exe

 

I stopped these processes (below).  I will have to see if it makes a difference

 

ThermalController.exe 11,088K ThermalController
AWCCServiceController.exe 7,788 Remoting Service Controller

 

 

 



Thank you!



#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,619 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:39 AM

Posted 01 August 2013 - 02:20 PM

No attached screen shot.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#14 bkdesign

bkdesign
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Diego, CA
  • Local time:09:39 AM

Posted 01 August 2013 - 02:35 PM

Sorry I forget to add the screenshot.  Also I closed out all my programs, except Outlook and IE and my Memory is 1.78GB and CPU is 1%-4%.  It does still say I have 72 Processes running on the Performance Tab.  Not sure if that is good or bad?
 

 



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,619 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:39 AM

Posted 01 August 2013 - 03:04 PM

Could you send the screen shot as an attachment. I only wanted to stop Alienware and leave everything else running.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users