Code:
HitmanPro 3.7.3.194
www.hitmanpro.com
Computer name . . . . : GEORGE-PC
Windows . . . . . . . : 6.1.1.7601.X64/8
User name . . . . . . : George-PC\George
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (Expired)
Scan date . . . . . . : 2013-04-25 23:45:28
Scan mode . . . . . . : Normal
Scan duration . . . . : 3m 49s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 1
Traces . . . . . . . : 186
Objects scanned . . . : 1,231,293
Files scanned . . . . : 17,325
Remnants scanned . . : 338,243 files / 875,725 keys
Malware _____________________________________________________________________
C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8BS3LTJ\installer-silent[1].exe
Size . . . . . . . : 487,754 bytes
Age . . . . . . . : 0.0 days (2013-04-25 23:43:26)
Entropy . . . . . : 7.9
SHA-256 . . . . . : F7A7FEB43D62D6BA8759E00B3EE3F0164DCBB1E3D785D0842E2A0C436D96D9BA
Source URL . . . . : hxxp://s3.amazonaws.com/adpk/gs/installer-silent.exe
> G Data . . . . . . : Adware.Agent.NPG
Fuzzy . . . . . . : 116.0
Potential Unwanted Programs _________________________________________________
C:\Program Files (x86)\Wajam\ (Claro)
C:\Program Files (x86)\Wajam\install.log (Claro)
C:\ProgramData\BrowserProtect\ (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\ (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\bl (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll (Claro)
Size . . . . . . . : 2,520,016 bytes
Age . . . . . . . : 1.7 days (2013-04-24 07:44:32)
Entropy . . . . . : 6.7
SHA-256 . . . . . : BCA2B76339A9331A089EA7A3297764767D7ED4E0CAC18935B85D462B08A67F6F
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : 3.0
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe (Claro)
Size . . . . . . . : 2,787,280 bytes
Age . . . . . . . : 1.7 days (2013-04-24 07:44:32)
Entropy . . . . . : 6.7
SHA-256 . . . . . : 67941CDDBC7FE0A6F913541ED9EDA6DCD73BED38281C498764077491501D62D4
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : 1.0
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.settings (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\dm (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\ (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\bprotector.js (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\ (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\00 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\01 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\02 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\03 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\10 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\11 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\12 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\13 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\20 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\21 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\22 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\23 (Claro)
C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe (Claro)
Size . . . . . . . : 2,787,280 bytes
Age . . . . . . . : 1.7 days (2013-04-24 07:44:33)
Entropy . . . . . : 6.7
SHA-256 . . . . . : 67941CDDBC7FE0A6F913541ED9EDA6DCD73BED38281C498764077491501D62D4
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : 1.0
C:\Users\George\AppData\Roaming\Babylon\ (Babylon)
C:\Users\George\AppData\Roaming\Babylon\log_file.txt (Babylon)
HKLM\SOFTWARE\Classes\AppID\escort.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}\ (Delta Search)
HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}\ (Delta Search)
HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro)
HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\c\ (Claro)
HKLM\SOFTWARE\Classes\delta.deltaappCore.1\ (Delta Search)
HKLM\SOFTWARE\Classes\delta.deltaappCore\ (Delta Search)
HKLM\SOFTWARE\Classes\escort.escortIEPane.1\ (Funmoods)
HKLM\SOFTWARE\Classes\escort.escortIEPane\ (Funmoods)
HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1\ (Delta Search)
HKLM\SOFTWARE\Classes\esrv.deltaESrvc\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}\ (Delta Search)
HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}\ (Delta Search)
HKLM\SOFTWARE\Classes\Prod.cap\ (Claro)
HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}\ (Delta Search)
HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}\ (Delta Search)
HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escort.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortApp.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escortEng.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\escorTlbr.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{39CB8175-E224-4446-8746-00566302DF8D}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}\ (Claro)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{99066096-8989-4612-841F-621A01D54AD7}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1231839B-064E-4788-B865-465A1B5266FD}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{57C91446-8D81-4156-A70E-624551442DE9}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}\ (Babylon)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}\ (Delta Search)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\ (Funmoods)
HKLM\SOFTWARE\Classes\YontooIEClient.Api.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Babylon\ (Babylon)
HKLM\SOFTWARE\Wow6432Node\DataMngr\ (SearchQU)
HKLM\SOFTWARE\Wow6432Node\Delta\delta\ (Delta Search)
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}\ (Delta Search)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} (Delta Search)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}\ (Delta Search)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\.DEFAULT\Software\DataMngr\ (SearchQU)
HKU\.DEFAULT\Software\DataMngr_Toolbar\ (SearchQU)
HKU\S-1-5-18\Software\DataMngr\ (SearchQU)
HKU\S-1-5-18\Software\DataMngr_Toolbar\ (SearchQU)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\BabylonToolbar\ (Babylon)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\DataMngr_Toolbar\ (SearchQU)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Delta\delta\ (Delta Search)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} (Claro)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}\ (Delta Search)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}\ (Delta Search)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKU\S-1-5-21-3273392669-942026362-2847598145-1000_Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
HKU\S-1-5-21-3273392669-942026362-2847598145-1001\Software\Wajam\ (Claro)
Cookies _____________________________________________________________________
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:2843239.fls.doubleclick.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:a1.interclick.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.mlnadvertising.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.propellerads.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.creative-serving.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pointroll.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pubmatic.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.undertone.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserver.adreactor.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ar.atwola.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:atwola.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:collective-media.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:dmtracker.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:eset.122.2o7.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:interclick.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:kontera.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:pointroll.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:questionmarket.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:specificclick.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:t.pointroll.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.at.atwola.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.burstnet.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
C:\Users\George\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16447
Run by George at 23:51:03 on 2013-04-25
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8103.4168 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\FBAgent.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\AsScrPro.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe
C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\George\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
C:\Users\George\AppData\Roaming\SearchProtect\bin\cltmng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\George\Downloads\HitmanPro_x64.exe
C:\Program Files\HitmanPro\hmpsched.exe
C:\Windows\SysWow64\NOTEPAD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?ctid=CT3298573&octid=CT3298573&SearchSource=61&CUI=UN30526758832124728&UM=2&UP=SPBF3905DF-3133-40E0-BF09-08B08EFC473B
mStart Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
uURLSearchHooks: MixiDJ V37 Toolbar: {eef3855c-fc2d-41e6-8d91-d368f51b3055} - C:\Program Files (x86)\MixiDJ_V37\prxtbMixi.dll
mURLSearchHooks: MixiDJ V37 Toolbar: {eef3855c-fc2d-41e6-8d91-d368f51b3055} - C:\Program Files (x86)\MixiDJ_V37\prxtbMixi.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\George\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: delta Helper Object: {C1AF5FA5-852C-4C90-812E-A7F75E011D87} -
BHO: Updater By SweetPacks: {C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD} - C:\Program Files\Updater By SweetPacks\Extension32.dll
BHO: SweetPacks Browser Helper: {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
BHO: MixiDJ V37 Toolbar: {eef3855c-fc2d-41e6-8d91-d368f51b3055} - C:\Program Files (x86)\MixiDJ_V37\prxtbMixi.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -
BHO: GetSavin 5.0: {FFB716BD-6F4F-428E-9C9F-E88F4246FF36} - C:\Users\George\AppData\Local\getsavin\ie\getsavin_1366897201.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: SweetPacks Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
TB: Delta Toolbar: {82E1477C-B154-48D3-9891-33D83C26BCD3} -
TB: MixiDJ V37 Toolbar: {eef3855c-fc2d-41e6-8d91-d368f51b3055} - C:\Program Files (x86)\MixiDJ_V37\prxtbMixi.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [DW6] "C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe"
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [GoogleChromeAutoLaunch_B4EC1D2429CD24DC38F0F0B254F35ABB] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
uRun: [SearchProtect] C:\Users\George\AppData\Roaming\SearchProtect\bin\cltmng.exe
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
StartupFolder: C:\Users\George\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOLREC~1.LNK - C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDevMgrUpdate = dword:0
uPolicies-Explorer: NoDFSTab = dword:0
uPolicies-Explorer: NoEncryptOnMove = dword:0
uPolicies-Explorer: NoRunasInstallPrompt = dword:0
uPolicies-Explorer: NoResolveTrack = dword:0
uPolicies-Explorer: NoStartMenuSubFolders = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:0
mPolicies-Explorer: NoDevMgrUpdate = dword:0
mPolicies-Explorer: NoDFSTab = dword:0
mPolicies-Explorer: NoEncryptOnMove = dword:0
mPolicies-Explorer: NoRunasInstallPrompt = dword:0
mPolicies-Explorer: NoResolveTrack = dword:0
mPolicies-Explorer: NoStartMenuSubFolders = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-Explorer: DisableLocalMachineRun = dword:0
mPolicies-Explorer: DisableLocalMachineRunOnce = dword:0
mPolicies-Explorer: DisableCurrentUserRun = dword:0
mPolicies-Explorer: DisableCurrentUserRunOnce = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:0
mPolicies-Explorer: NoFile = dword:0
mPolicies-Explorer: HideClock = dword:0
mPolicies-Explorer: NoDevMgrUpdate = dword:0
mPolicies-Explorer: NoDFSTab = dword:0
mPolicies-Explorer: NoEncryptOnMove = dword:0
mPolicies-Explorer: NoRunasInstallPrompt = dword:0
mPolicies-Explorer: NoResolveTrack = dword:0
mPolicies-Explorer: NoStartMenuSubFolders = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{25D56ACD-40F8-4398-BACA-365CBBFB1460} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{25D56ACD-40F8-4398-BACA-365CBBFB1460}\2375942554338303 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{25D56ACD-40F8-4398-BACA-365CBBFB1460}\245796 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{25D56ACD-40F8-4398-BACA-365CBBFB1460}\75F6E6465627C616E6462303837343 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{25D56ACD-40F8-4398-BACA-365CBBFB1460}\C4962627162797 : DHCPNameServer = 10.9.0.37 10.9.0.45 8.8.4.4
AppInit_DLLs= c:\progra~3\browse~1\261249~1.132\{c16c1~1\browserprotect.dll
SecurityProviders: SecurityProviders = schannel.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://www.google.com
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-3 65336]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2012-10-25 30056]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-3-22 1025808]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-3-22 377920]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-5-25 17536]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]
R2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2011-12-9 379520]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-3-22 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-3-22 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-3-22 45248]
R2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [2013-4-11 93984]
R2 DefaultTabSearch;DefaultTabSearch;C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [2013-2-11 572928]
R2 DefaultTabUpdate;DefaultTabUpdate;C:\Users\George\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [2013-4-25 107520]
R2 HitmanProScheduler;HitmanPro Scheduler;C:\Program Files\HitmanPro\hmpsched.exe [2013-4-25 109352]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-4-16 13832]
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-4-16 134928]
R2 Updater By SweetPacks;Updater By SweetPacks;C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe [2013-4-22 188760]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-6-2 128488]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-6-2 401896]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2011-12-6 142632]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2013-4-25 32000]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-12-6 317440]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-12-9 413800]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SystemStoreService;System Store;C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [2013-4-22 474112]
S2 Yontoo Desktop Updater;Yontoo Desktop Updater;"C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe" "C:\Users\George\AppData\Roaming\Yontoo\YontooDesktop.exe" --> C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [?]
S3 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-3-3 178624]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-5-2 340240]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\System32\GameMon.des -service --> C:\Windows\System32\GameMon.des -service [?]
S3 rak;rak;C:\Game\SoftnyxGame\RakionIS\Bin\avital\rakion64.sys [2012-11-25 81880]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\rtsuvstor.sys [2011-12-9 290920]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-12-18 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-12-18 1255736]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\Windows\SysWow64\NOTEPAD.EXE %1
FileExt: .ini: inifile=C:\Windows\SysWow64\NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2013-04-26 06:45:3032000----a-w-C:\Windows\System32\drivers\hitmanpro37.sys
2013-04-26 06:45:28--------d-----w-C:\Program Files\HitmanPro
2013-04-26 06:44:12--------d-----w-C:\Program Files (x86)\Conduit
2013-04-26 06:44:11--------d-----w-C:\Users\George\AppData\Local\Conduit
2013-04-26 06:44:11--------d-----w-C:\Program Files (x86)\MixiDJ_V37
2013-04-26 06:43:58--------d-----w-C:\Program Files (x86)\SearchProtect
2013-04-26 06:43:52--------d-----w-C:\Users\George\AppData\Roaming\SearchProtect
2013-04-26 06:43:37--------d-----w-C:\Program Files (x86)\DefaultTab
2013-04-26 06:43:35--------d-----w-C:\Program Files (x86)\Wajam
2013-04-26 06:43:32--------d-----w-C:\Users\George\AppData\Roaming\DefaultTab
2013-04-26 06:43:29--------d-----w-C:\Users\George\AppData\Local\getsavin
2013-04-25 18:26:2076232----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1D6813EF-FC5F-40DA-B684-2529D9468080}\offreg.dll
2013-04-24 16:56:39--------d-----w-C:\Program Files (x86)\ESET
2013-04-24 16:52:11--------d-sh--w-C:\$RECYCLE.BIN
2013-04-24 16:38:49--------d-----w-C:\ComboFix
2013-04-24 14:46:019317456----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1D6813EF-FC5F-40DA-B684-2529D9468080}\mpengine.dll
2013-04-24 14:44:30--------d-----w-C:\ProgramData\BrowserProtect
2013-04-24 14:44:11--------d-----w-C:\Users\George\AppData\Roaming\Babylon
2013-04-24 14:43:57--------d-----w-C:\Users\George\AppData\Local\PutLockerDownloader
2013-04-23 21:10:13--------d-----w-C:\Program Files\CCleaner
2013-04-22 19:52:32--------d-----w-C:\Users\George\AppData\Local\Freemium
2013-04-22 19:29:50--------d-----w-C:\Program Files\Updater By SweetPacks
2013-04-22 19:29:41--------d-----w-C:\Program Files (x86)\SweetIM
2013-04-22 19:26:04--------d-----w-C:\Users\George\AppData\Local\DownloadGuide
2013-04-22 19:18:30--------d-----w-C:\Program Files (x86)\SoftwareUpdater
2013-04-22 19:18:29--------d-----w-C:\ProgramData\FreeSystemUtilities
2013-04-22 19:18:28--------d-----w-C:\Program Files (x86)\Covus Freemium
2013-04-22 19:18:15--------d-----w-C:\ProgramData\Package Cache
2013-04-15 17:03:28--------d-----w-C:\Users\George\AppData\Local\Graboid_Inc
2013-04-15 17:03:27--------d-----w-C:\Users\George\AppData\Local\Graboid Inc
2013-04-15 17:03:27--------d-----w-C:\Users\George\AppData\Local\Graboid
2013-04-15 17:01:56--------d-----w-C:\Program Files (x86)\Graboid
2013-04-10 20:59:12--------d-----w-C:\2fbd02ab44d70f4afa30ec8594394cb6
2013-03-29 15:41:32--------d-----w-C:\Program Files (x86)\The Weather Channel FW
2013-03-29 15:41:08--------d-----w-C:\Users\George\AppData\Local\The Weather Channel
.
==================== Find3M ====================
.
2013-04-25 07:34:4245056----a-w-C:\Windows\System32\acovcnt.exe
2013-04-20 08:25:1771048----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-20 08:25:17691592----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-04-11 14:22:56421200----a-w-C:\Windows\SysWow64\msvcp100.dll
2013-04-04 21:50:3225928----a-w-C:\Windows\System32\drivers\mbam.sys
2013-03-22 11:04:47294----a-w-C:\Windows\DeleteOnReboot.bat
2013-03-12 08:10:56282744------w-C:\Windows\System32\MpSigStub.exe
2013-03-06 22:33:2170992----a-w-C:\Windows\System32\drivers\aswRdr2.sys
2013-03-06 22:33:2165336----a-w-C:\Windows\System32\drivers\aswRvrt.sys
2013-03-06 22:33:21178624----a-w-C:\Windows\System32\drivers\aswVmm.sys
2013-03-06 22:33:211025808----a-w-C:\Windows\System32\drivers\aswSnx.sys
2013-03-06 22:33:2080816----a-w-C:\Windows\System32\drivers\aswMonFlt.sys
2013-03-06 22:32:5141664----a-w-C:\Windows\avastSS.scr
2013-02-24 12:09:46258352----a-w-C:\Windows\SysWow64\unicows.dll
.
============= FINISH: 23:51:18.49 ===============