Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-08-2013 02
Ran by MH (administrator) on 22-08-2013 01:50:56
Running from C:\Users\MH\Downloads
Microsoft Windows 7 Home Premium (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
(AMD) C:\windows\system32\atiesrxx.exe
(AMD) C:\windows\system32\atieclxx.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
() C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgtray.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
() C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgwdsvc.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Realtek) C:\Program Files\Realtek\RTL8185 Wireless LAN Utility\RtlService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgemcx.exe
(Realtek) C:\Program Files\Realtek\RTL8187B Wireless LAN Utility\RtlService.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RTL8185 Wireless LAN Utility\RtWlan.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RTL8187B Wireless LAN Utility\RtWlan.exe
(Sophos Limited) C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
(Sophos Limited) C:\Program Files\Sophos\Remote Management System\RouterNT.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG10\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG10\avgcsrvx.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
(Google Inc.) C:\Users\MH\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\MH\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\MH\AppData\Local\Google\Chrome\Application\chrome.exe
(Verizon) C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
(Google Inc.) C:\Users\MH\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\MH\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [] - [x]
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-07-30] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7625248 2009-07-29] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [476512 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [460088 2009-07-28] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [738616 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [ToshibaServiceStation] - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1294136 2009-08-17] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [611672 2009-08-03] (TOSHIBA Corporation)
HKLM\...\Run: [NortonOnlineBackupReminder] - C:\Program Files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe [529256 2009-07-16] (Toshiba)
HKLM\...\Run: [NeroFilterCheck] - C:\windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Common Files\Real\Update_OB\realsched.exe [198160 2010-01-18] (RealNetworks, Inc.)
HKLM\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2780432 2009-05-08] ()
HKLM\...\Run: [AVG_TRAY] - C:\Program Files\AVG\AVG10\avgtray.exe [2345592 2012-08-01] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Sophos AutoUpdate Monitor] - C:\Program Files\Sophos\AutoUpdate\almon.exe [900160 2012-08-08] (Sophos Limited)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41208 2012-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKCU\...\Run: [MyTOSHIBA] - C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe [264048 2009-08-06] (TOSHIBA)
HKCU\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [4280184 2012-03-08] (Microsoft Corporation)
HKCU\...\Run: [Wisdom-soft ScreenHunter 5.1 Free] - 0 [x]
HKCU\...\Run: [AdobeBridge] - [x]
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /syncC:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=U016&ocid=U016DHP&dt=041013
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
SearchScopes: HKCU - DefaultScope {2DDA7029-1B90-4BF1-AC49-AE6C2C7D990C} URL =
http://www.bing.com/search?FORM=U016DF&PC=U016&dt=041013&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKCU - {2DDA7029-1B90-4BF1-AC49-AE6C2C7D990C} URL =
http://www.bing.com/search?FORM=U016DF&PC=U016&dt=041013&q={searchTerms}&src=IE-SearchBox
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -No Name - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
DPF: {0349EF81-B9C1-4B97-86F7-7B931D0E2532}
http://sticube.clubbox.co.kr/sticubeupdate/cab/NowStarter2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4}
http://www.clubbox.co.kr/neo.fld/MultiUpload.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [87616] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\windows\system32\TVUAx\npTVUAx.dll (TVU networks)
FF Plugin: @real.com/nppl3260;version=6.0.12.450 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.448 - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @kcp.co.kr/plugin;version=1 - C:\Program Files\KCP\Plugin\npKCPPlugin.dll (KCP CO.,LTD)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\MH\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\MH\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: zettamedia.co.kr/ZmLauncher - C:\Users\MH\AppData\Local\Zettamedia\PdClubBox\npZmLauncher.dll (Zettamedia Co.,Ltd.)
FF Extension: Click to call with Skype - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] C:\Program Files\AVG\AVG10\Firefox4\
FF Extension: AVG Safe Search - C:\Program Files\AVG\AVG10\Firefox4\
Chrome:
=======
CHR HomePage: hxxp://google.com/
CHR RestoreOnStartup: "hxxp://google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google

riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\MH\AppData\Local\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\MH\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\MH\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U7) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (KCP) - C:\Program Files\KCP\Plugin\npKCPPlugin.dll (KCP CO.,LTD)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\MH\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Zettamedia Launcher) - C:\Users\MH\AppData\Local\Zettamedia\PdClubBox\npZmLauncher.dll (Zettamedia Co.,Ltd.)
CHR Plugin: (TVU Web Player for FireFox) - C:\windows\system32\TVUAx\npTVUAx.dll (TVU networks)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (YouTube) - C:\Users\MAITAO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\MAITAO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (TweetDeck) - C:\Users\MAITAO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl\3.1.4_0
CHR Extension: (AVG Safe Search) - C:\Users\MAITAO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0
CHR Extension: (Gmail) - C:\Users\MAITAO~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [jmfkcklnlgedgbglfkkgedjfmejoahla] - C:\Program Files\AVG\AVG10\Chrome\safesearch.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [mffdcionknddopdmdnloanoafafkmckb] - C:\Users\MH\AppData\Roaming\OpenCandy\7475B9D73D2C43CEBCFA8C0C570C5BFA\extension.crx
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [7391072 2012-01-31] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG10\avgwdsvc.exe [269520 2011-02-08] (AVG Technologies CZ, s.r.o.)
R2 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [185712 2009-08-10] (TOSHIBA CORPORATION)
R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION)
R2 IHA_MessageCenter; C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [346696 2013-07-30] (Verizon)
R2 Realtek8185; C:\Program Files\Realtek\RTL8185 Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek)
R2 Realtek87B; C:\Program Files\Realtek\RTL8187B Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek)
R2 SAVAdminService; C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [216640 2012-09-17] (Sophos Limited)
R2 SAVService; C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe [139840 2012-07-26] (Sophos Limited)
R2 Sophos Agent; C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe [289856 2012-09-17] (Sophos Limited)
R2 Sophos Message Router; C:\Program Files\Sophos\Remote Management System\RouterNT.exe [818240 2012-09-17] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2012-07-26] (Sophos Limited)
R2 swi_service; C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2863168 2012-09-17] (Sophos Limited)
S2 swi_update; C:\ProgramData\Sophos\Web Intelligence\swi_update.exe [1465920 2012-08-08] (Sophos Limited)
R3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51512 2009-08-17] (TOSHIBA Corporation)
R3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2009-08-03] (TOSHIBA Corporation)
==================== Drivers (Whitelisted) ====================
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [16640 2010-12-30] (Wondershare)
R3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [134480 2011-05-27] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [22992 2011-02-22] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [24144 2011-02-10] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSShim; C:\Windows\System32\DRIVERS\AVGIDSShim.Sys [21968 2011-02-10] (AVG Technologies CZ, s.r.o. )
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [248656 2011-01-07] (AVG Technologies CZ, s.r.o.)
R1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [34896 2011-03-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [32592 2011-03-16] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [297168 2011-04-05] (AVG Technologies CZ, s.r.o.)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
R3 LVPr2Mon; C:\Windows\System32\Drivers\LVPr2Mon.sys [25624 2009-04-30] ()
S3 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [31560 2013-08-20] ()
S3 mbamswissarmy; C:\windows\system32\drivers\mbamswissarmy.sys [146648 2013-08-20] (Malwarebytes Corporation)
S3 NOWMEMDF; C:\windows\system32\NOWMEMDF.sys [15104 2009-12-07] ((c)NOWCOM)
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [376832 2009-12-15] (Realtek Semiconductor Corporation )
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [123680 2012-07-26] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [33696 2012-07-26] (Sophos Limited)
R1 SKMScan; C:\Windows\System32\DRIVERS\skmscan.sys [31736 2012-07-26] (Sophos Plc)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [22536 2012-07-21] (Sophos Plc)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-22 01:50 - 2013-08-22 01:50 - 00000000 ____D C:\FRST
2013-08-21 23:15 - 2013-08-21 23:16 - 15163458 _____ C:\Users\MH\Downloads\[NAVER STARCAST] TVXQ in Nissan Stadium Highlight.mp4
2013-08-20 21:25 - 2013-08-20 21:25 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{F4ED4186-811C-484B-B0BF-E0C6FCC77E33}
2013-08-20 02:36 - 2013-08-20 02:36 - 00146648 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamswissarmy.sys
2013-08-20 02:35 - 2013-08-20 02:35 - 00031560 _____ C:\windows\system32\Drivers\mbamchameleon.sys
2013-08-20 02:34 - 2013-08-20 02:34 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{37000D07-3EB2-4C42-A5E7-9E9AE6F6DBA3}
2013-08-20 00:49 - 2013-08-20 02:39 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-08-20 00:45 - 2013-08-20 02:14 - 00000000 ____D C:\Users\MH\Desktop\mbar
2013-08-20 00:39 - 2013-08-20 00:42 - 12081912 _____ (Malwarebytes Corp.) C:\Users\MH\Downloads\mbar-1.06.1.1005.exe
2013-08-20 00:38 - 2013-08-20 00:38 - 00002708 _____ C:\Users\MH\Desktop\RKreport[0]_D_08202013_003801.txt
2013-08-20 00:37 - 2013-08-20 00:37 - 00002593 _____ C:\Users\MH\Desktop\RKreport[0]_S_08202013_003743.txt
2013-08-20 00:33 - 2013-08-20 00:40 - 00000000 ____D C:\Users\MH\Desktop\RK_Quarantine
2013-08-20 00:33 - 2013-08-20 00:33 - 00923136 _____ C:\Users\MH\Downloads\RogueKiller.exe
2013-08-16 18:29 - 2013-08-16 18:30 - 00016298 _____ C:\Users\MH\Desktop\dds.txt
2013-08-16 18:29 - 2013-08-16 18:30 - 00010390 _____ C:\Users\MH\Desktop\attach.txt
2013-08-16 18:24 - 2013-08-16 18:25 - 00688992 ____R (Swearware) C:\Users\MH\Downloads\dds.com
2013-08-16 18:23 - 2013-08-16 18:23 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{011730D3-3492-4179-A620-D8567E7634CE}
2013-08-16 17:46 - 2013-08-16 18:22 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-16 17:46 - 2013-08-16 17:46 - 00001042 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-16 17:46 - 2013-08-16 17:46 - 00000000 ____D C:\Users\MH\AppData\Roaming\Malwarebytes
2013-08-16 17:46 - 2013-08-16 17:46 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-16 17:46 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-08-16 17:43 - 2013-08-16 17:45 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\MH\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-14 21:28 - 2013-08-14 21:28 - 00000000 ____D C:\Users\MH\Downloads\130814 Changmin @ Filming + PressCon @ Cool Kiz on the block
2013-08-13 22:24 - 2013-08-13 22:25 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{FD16079E-7F88-4CE6-839A-D4E180A9668C}
2013-08-08 18:43 - 2013-08-08 18:43 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{15B97F17-5AAD-4BC0-9DF8-02D2C8AEB907}
2013-08-08 18:41 - 2013-08-16 18:21 - 00146378 _____ C:\windows\PFRO.log
2013-08-08 08:03 - 2013-08-08 08:03 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-08-08 08:03 - 2013-08-08 08:03 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-08-08 06:43 - 2013-08-20 21:24 - 00001064 _____ C:\windows\setupact.log
2013-08-08 06:43 - 2013-08-08 06:43 - 00000000 ____D C:\Users\MH\.android
2013-08-08 06:43 - 2013-08-08 06:43 - 00000000 _____ C:\windows\setuperr.log
2013-08-07 07:13 - 2013-08-07 07:13 - 273083480 _____ C:\Users\MH\Downloads\[DBSKnights] Bigeast Limited DVD 2013 Summer ver (480p).avi
2013-08-06 22:48 - 2013-08-06 22:48 - 00000940 _____ C:\Users\Public\Desktop\ClipGrab.lnk
2013-08-06 22:48 - 2013-08-06 22:48 - 00000000 ____D C:\Program Files\ClipGrab
2013-08-06 16:00 - 2013-08-06 16:42 - 00000000 ____D C:\Users\MH\
www.apowersoft.com
2013-08-03 14:07 - 2013-08-03 14:07 - 00000042 _____ C:\windows\system32\AK083E209605E394C.lie
2013-08-03 13:00 - 2013-08-03 13:00 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{E3A60500-BA9E-419A-A8C0-B688D21168F2}
2013-08-03 12:55 - 2013-08-03 12:55 - 00002214 _____ C:\Users\Public\Desktop\REALTEK RTL8187B Wireless LAN Utility.lnk
2013-08-03 11:10 - 2013-08-03 11:10 - 00001122 _____ C:\Users\Public\Desktop\Vz In-Home Agent.lnk
2013-08-03 11:10 - 2013-08-03 11:10 - 00000260 _____ C:\windows\system32\cmdVBS.vbs
2013-08-03 11:10 - 2013-08-03 11:10 - 00000256 _____ C:\windows\system32\MSIevent.bat
2013-08-03 11:09 - 2013-08-03 11:10 - 04818944 _____ C:\ProgramData\IHAMC.msi
2013-08-03 10:39 - 2013-08-03 10:39 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{2C405ACD-4522-4972-AF60-443BA5CE1BC7}
2013-08-02 23:22 - 2013-08-02 23:22 - 00002170 _____ C:\Users\MH\Uninstall-VzInHomeAgentlog.log
2013-08-02 23:18 - 2013-08-03 11:11 - 00000000 ____D C:\Program Files\Verizon
2013-08-02 23:18 - 2013-08-03 11:10 - 00001767 _____ C:\Users\MH\Install-VzInHomeAgentLog.log
2013-08-02 23:18 - 2013-08-03 11:10 - 00000000 ____D C:\Users\MH\AppData\Roaming\Verizon
2013-08-02 11:41 - 2013-08-02 11:42 - 01358496 _____ C:\Users\MH\Downloads\VzInHomeAgent.exe
2013-07-29 15:11 - 2013-07-29 16:28 - 00017233 _____ C:\Users\MH\Documents\thefirstbloom_css_072913.txt
==================== One Month Modified Files and Folders =======
2013-08-22 01:50 - 2013-08-22 01:50 - 01070315 _____ (Farbar) C:\Users\MH\Downloads\FRST.exe
2013-08-22 01:50 - 2013-08-22 01:50 - 00000000 ____D C:\FRST
2013-08-21 23:16 - 2013-08-21 23:15 - 15163458 _____ C:\Users\MH\Downloads\[NAVER STARCAST] TVXQ in Nissan Stadium Highlight.mp4
2013-08-21 18:35 - 2009-11-05 06:50 - 01277621 _____ C:\windows\WindowsUpdate.log
2013-08-20 21:32 - 2009-07-14 00:34 - 00015568 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-20 21:32 - 2009-07-14 00:34 - 00015568 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-20 21:25 - 2013-08-20 21:25 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{F4ED4186-811C-484B-B0BF-E0C6FCC77E33}
2013-08-20 21:24 - 2013-08-08 06:43 - 00001064 _____ C:\windows\setupact.log
2013-08-20 21:24 - 2010-05-08 00:18 - 00000000 ____D C:\Users\MH\Tracing
2013-08-20 21:24 - 2009-07-14 00:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-20 02:39 - 2013-08-20 00:49 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-08-20 02:36 - 2013-08-20 02:36 - 00146648 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamswissarmy.sys
2013-08-20 02:35 - 2013-08-20 02:35 - 00031560 _____ C:\windows\system32\Drivers\mbamchameleon.sys
2013-08-20 02:34 - 2013-08-20 02:34 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{37000D07-3EB2-4C42-A5E7-9E9AE6F6DBA3}
2013-08-20 02:14 - 2013-08-20 00:45 - 00000000 ____D C:\Users\MH\Desktop\mbar
2013-08-20 00:42 - 2013-08-20 00:39 - 12081912 _____ (Malwarebytes Corp.) C:\Users\MH\Downloads\mbar-1.06.1.1005.exe
2013-08-20 00:40 - 2013-08-20 00:33 - 00000000 ____D C:\Users\MH\Desktop\RK_Quarantine
2013-08-20 00:38 - 2013-08-20 00:38 - 00002708 _____ C:\Users\MH\Desktop\RKreport[0]_D_08202013_003801.txt
2013-08-20 00:37 - 2013-08-20 00:37 - 00002593 _____ C:\Users\MH\Desktop\RKreport[0]_S_08202013_003743.txt
2013-08-20 00:33 - 2013-08-20 00:33 - 00923136 _____ C:\Users\MH\Downloads\RogueKiller.exe
2013-08-16 18:30 - 2013-08-16 18:29 - 00016298 _____ C:\Users\MH\Desktop\dds.txt
2013-08-16 18:30 - 2013-08-16 18:29 - 00010390 _____ C:\Users\MH\Desktop\attach.txt
2013-08-16 18:25 - 2013-08-16 18:24 - 00688992 ____R (Swearware) C:\Users\MH\Downloads\dds.com
2013-08-16 18:23 - 2013-08-16 18:23 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{011730D3-3492-4179-A620-D8567E7634CE}
2013-08-16 18:22 - 2013-08-16 17:46 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-16 18:21 - 2013-08-08 18:41 - 00146378 _____ C:\windows\PFRO.log
2013-08-16 18:21 - 2009-07-13 22:37 - 00000000 ____D C:\windows\Cursors
2013-08-16 17:46 - 2013-08-16 17:46 - 00001042 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-16 17:46 - 2013-08-16 17:46 - 00000000 ____D C:\Users\MH\AppData\Roaming\Malwarebytes
2013-08-16 17:46 - 2013-08-16 17:46 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-16 17:45 - 2013-08-16 17:43 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\MH\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-14 21:28 - 2013-08-14 21:28 - 00000000 ____D C:\Users\MH\Downloads\130814 Changmin @ Filming + PressCon @ Cool Kiz on the block
2013-08-13 22:25 - 2013-08-13 22:24 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{FD16079E-7F88-4CE6-839A-D4E180A9668C}
2013-08-12 19:15 - 2009-07-13 22:37 - 00000000 ____D C:\windows\system32\NDF
2013-08-08 18:43 - 2013-08-08 18:43 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{15B97F17-5AAD-4BC0-9DF8-02D2C8AEB907}
2013-08-08 08:04 - 2010-11-14 17:11 - 00000000 ____D C:\Users\MH\AppData\Roaming\DVDVideoSoft
2013-08-08 08:03 - 2013-08-08 08:03 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-08-08 08:03 - 2013-08-08 08:03 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-08-08 07:36 - 2012-12-31 03:06 - 00000000 ____D C:\Program Files\YouKu
2013-08-08 07:36 - 2012-11-17 08:29 - 00000000 ____D C:\Program Files\yy
2013-08-08 07:35 - 2012-11-17 08:29 - 00000000 ____D C:\Users\MH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YY
2013-08-08 06:43 - 2013-08-08 06:43 - 00000000 ____D C:\Users\MH\.android
2013-08-08 06:43 - 2013-08-08 06:43 - 00000000 _____ C:\windows\setuperr.log
2013-08-08 06:43 - 2009-12-24 21:16 - 00000000 ___HD C:\Users\MH
2013-08-07 07:13 - 2013-08-07 07:13 - 273083480 _____ C:\Users\MH\Downloads\[DBSKnights] Bigeast Limited DVD 2013 Summer ver (480p).avi
2013-08-06 22:48 - 2013-08-06 22:48 - 00000940 _____ C:\Users\Public\Desktop\ClipGrab.lnk
2013-08-06 22:48 - 2013-08-06 22:48 - 00000000 ____D C:\Program Files\ClipGrab
2013-08-06 16:42 - 2013-08-06 16:00 - 00000000 ____D C:\Users\MH\
www.apowersoft.com
2013-08-03 14:07 - 2013-08-03 14:07 - 00000042 _____ C:\windows\system32\AK083E209605E394C.lie
2013-08-03 13:00 - 2013-08-03 13:00 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{E3A60500-BA9E-419A-A8C0-B688D21168F2}
2013-08-03 12:55 - 2013-08-03 12:55 - 00002214 _____ C:\Users\Public\Desktop\REALTEK RTL8187B Wireless LAN Utility.lnk
2013-08-03 12:53 - 2009-11-05 07:32 - 00000000 ____D C:\Program Files\Realtek
2013-08-03 12:53 - 2009-08-23 21:51 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-08-03 11:11 - 2013-08-02 23:18 - 00000000 ____D C:\Program Files\Verizon
2013-08-03 11:10 - 2013-08-03 11:10 - 00001122 _____ C:\Users\Public\Desktop\Vz In-Home Agent.lnk
2013-08-03 11:10 - 2013-08-03 11:10 - 00000260 _____ C:\windows\system32\cmdVBS.vbs
2013-08-03 11:10 - 2013-08-03 11:10 - 00000256 _____ C:\windows\system32\MSIevent.bat
2013-08-03 11:10 - 2013-08-03 11:09 - 04818944 _____ C:\ProgramData\IHAMC.msi
2013-08-03 11:10 - 2013-08-02 23:18 - 00001767 _____ C:\Users\MH\Install-VzInHomeAgentLog.log
2013-08-03 11:10 - 2013-08-02 23:18 - 00000000 ____D C:\Users\MH\AppData\Roaming\Verizon
2013-08-03 10:39 - 2013-08-03 10:39 - 00000000 ____D C:\Users\MAITAO~1\AppData\Local\{2C405ACD-4522-4972-AF60-443BA5CE1BC7}
2013-08-02 23:22 - 2013-08-02 23:22 - 00002170 _____ C:\Users\MH\Uninstall-VzInHomeAgentlog.log
2013-08-02 11:42 - 2013-08-02 11:41 - 01358496 _____ C:\Users\MH\Downloads\VzInHomeAgent.exe
2013-08-02 03:08 - 2010-02-05 20:29 - 00000000 ____D C:\Users\MH\Documents\readings
2013-08-02 02:26 - 2010-01-04 18:05 - 00000000 ____D C:\Users\MH\AppData\Roaming\vlc
2013-07-31 23:21 - 2010-02-22 18:37 - 00000000 ____D C:\Users\MH\Documents\writing
2013-07-29 16:28 - 2013-07-29 15:11 - 00017233 _____ C:\Users\MH\Documents\thefirstbloom_css_072913.txt
2013-07-26 16:55 - 2009-12-25 17:56 - 00000000 ____D C:\Users\MH\Documents\DBSG 5
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-10 14:48
==================== End Of Log ============================