Open Side Menu Go to the Top
Register
Questions, questions Questions, questions

02-09-2015 , 04:56 AM
you can compress your document and then create password
Questions, questions Quote
02-09-2015 , 06:11 AM
It depends on who you want to secure these documents from? An unauthorised user of your computer? Someone else that uses your computer but has a separate login? Or someone that uses your login on your computer?

Yes, you can password protect files individually - but this requires that you remember lots of passwords. To password protect the documents, you'll need to use the licensed software (Office, etc.) to save the files with a password.

What might be better for you, imo, is to look into encrypting the documents. You can either use something like BitLocker, if no one else is going to have access to your login on your computer http://www.howtogeek.com/178912/how-...8.1-using-efs/

or something like TrueCrypt to create an encypted container and have all your sensitive documents in there.
Questions, questions Quote
02-09-2015 , 08:22 AM
You describe a laptop with either a faulty CPU or one that is overheating to hell.
Can you replace it still?
Questions, questions Quote
02-09-2015 , 11:27 AM
What version of Windows are you using? This seems like it could be a networking type issue since it is happening when you are using the Internet. Router, download speed of your ISP, etc. would be helpful here.
Questions, questions Quote
02-09-2015 , 01:18 PM
windows 7.


Computer by default had just the regular hdd but i upgraded it to a 250gb ssd so i only got the ssd. I didn't know you could have both ssd and regular hd there. You telilng 2 hard drives inside my laptop?


What other files on a standard hdd do you mean? Basically i have poker pograms and then have lot of documents/videos/pcitures etc.
Questions, questions Quote
02-09-2015 , 01:20 PM
Well im the only one use this computer. However if someone were to access my computer, i dont want them to view some of my documents/pictures.


Is bitlocker simple though? I would want to lock mostly videos and pictures in my computer and certain documents on open office.
Questions, questions Quote
02-09-2015 , 02:38 PM
I use 7-zip for this. AES 256-bit encryption is prettay safe
Questions, questions Quote
02-09-2015 , 02:59 PM
your hardware is more than capable of handling any program. if youre lagging its probably due to software/virus. I never had 50 tabs of chrome open at once so it may be a lack of ram. You should check in task manager to see how much of the ram is being used when you have your programs running with all the tabs open. Also the lag mayb be due to HEM2. Here are some remedies to fix it.

http://hm2faq.holdemmanager.com/ques...+is+lagging%3F
Questions, questions Quote
02-09-2015 , 03:20 PM
Quote:
Originally Posted by Craggoo
The only time you should have a computer with only an ssd installed is if it's going to be used on a very irregular basis imo. You are supposed to install all your programs and OS on an ssd then put all your other files on a standard hdd.
This is a new one on me. That's the way I've done things, but only because of cost - if money wasn't an issue, why wouldn't you want the biggest SSD you could buy and just use that?
Questions, questions Quote
02-09-2015 , 03:34 PM
Quote:
Originally Posted by Craggoo
The only time you should have a computer with only an ssd installed is if it's going to be used on a very irregular basis imo. You are supposed to install all your programs and OS on an ssd then put all your other files on a standard hdd.
That's bull****, especially for a laptop where you might not store tons of stuff like movies. My work laptop which I use every day only has one 320GB SSD and it's fine. Also you can put stuff on an external HDD which is more than fast enough if using USB 3.0.
Questions, questions Quote
02-09-2015 , 03:51 PM
Quote:
Originally Posted by Morphismus
That's bull****, especially for a laptop where you might not store tons of stuff like movies. My work laptop which I use every day only has one 320GB SSD and it's fine. Also you can put stuff on an external HDD which is more than fast enough if using USB 3.0.
+1

Solo SSD is not that unusual, particularly in a laptop.

Having said all that, OP:

1. Do you really need 48+ Chrome tabs open? That is probably killing your performance. As suggested, have a look in Task Manager to see how much RAM Chrome is using. You'll have to add them all up. Maybe post a screenshot of Task Manager?

2. If you don't think your program usage is causing the problems, this could be symptomatic of virus infection. If you suspect this, follow the instructions in this post to create two OTL logs. Post them in this thread.
Questions, questions Quote
02-09-2015 , 05:04 PM
The advice is correct:
- archivers (Rar/7Zip/WinZip AES - it doesn't matter), if you would like to store your files
- TrueCrypt container (is enabled as a logical drive), if there are a lot of files and you regularly work with them

The protection of archivers and TrueCrypt is good and one may search for the password for years. The main thing is to set (and, of course, write down somewhere ) a complex password. Do not use simple combinations that can be easily found and nobody will be able to see your files.
Questions, questions Quote
02-09-2015 , 07:12 PM
These are my computer specs for my sager np2740


i7-4770HQ

8GB RAM

Samsung 850 Evo Series 250GB

Intel® Iris™ Pro Graphics 5200

Intel Dual Band AC7260


Usually it uses at least 4gb to 7gb of ram. At the moment its using more than 6gb of ram. I am not playing any poker. The only thing is i have lot of tabs in a lot of chrome windows. At the moment theres 6.5gb of ram being used... however my cpu usage is under 10 percent.


Yes i have lot of chrome tabs and thats why its adding up to that much ram.
Questions, questions Quote
02-09-2015 , 07:29 PM
OTL logfile created on: 2/9/2015 6:20:14 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Danny\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.92 Gb Total Physical Memory | 4.32 Gb Available Physical Memory | 54.56% Memory free
15.84 Gb Paging File | 11.76 Gb Available in Paging File | 74.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.54 Gb Total Space | 147.95 Gb Free Space | 63.62% Space Free | Partition Type: NTFS

Computer Name: DANNY-PC | User Name: Danny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2015/02/09 18:18:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Danny\Downloads\OTL.exe
PRC - [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015/01/30 23:32:11 | 005,227,112 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2015/01/28 23:31:41 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2015/01/22 09:13:16 | 005,373,952 | ---- | M] (random) -- C:\Program Files (x86)\PacificPoker\bin\poker.exe
PRC - [2014/12/11 11:03:12 | 000,089,864 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService .exe
PRC - [2014/12/08 21:45:28 | 039,207,112 | ---- | M] (Dropbox, Inc.) -- C:\Users\Danny\AppData\Roaming\Dropbox\bin\Dropbox .exe
PRC - [2014/12/03 00:31:16 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/11/21 05:12:46 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014/09/12 12:14:55 | 004,799,760 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2014/06/27 11:52:26 | 002,088,408 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2014/06/24 10:42:12 | 004,101,576 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2014/06/24 10:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2014/04/25 14:12:20 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2014/03/17 15:52:22 | 021,045,727 | ---- | M] () -- C:\Program Files (x86)\Electrum\electrum.exe
PRC - [2013/09/16 11:22:08 | 005,074,432 | ---- | M] () -- C:\Program Files (x86)\Hotkey\Hotkey.exe
PRC - [2013/06/23 19:32:38 | 001,132,920 | ---- | M] (Motorola Solutions, Inc.) -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
PRC - [2013/05/29 18:50:24 | 000,046,592 | ---- | M] () -- c:\Program Files (x86)\Hotkey\PowerBiosServer.exe
PRC - [2013/04/26 11:25:54 | 000,292,848 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2013/04/23 16:51:04 | 000,960,888 | ---- | M] (Motorola Solutions, Inc.) -- C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
PRC - [2013/04/23 16:50:50 | 001,366,392 | ---- | M] (Motorola Solutions, Inc.) -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
PRC - [2013/04/23 16:50:46 | 001,153,400 | ---- | M] (Motorola Solutions, Inc.) -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
PRC - [2013/03/22 09:38:32 | 000,286,704 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2013/03/22 09:38:32 | 000,015,344 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/07/06 14:35:22 | 000,121,456 | ---- | M] (Chicony) -- C:\Program Files (x86)\ChiconyCam\CECAPLF.exe
PRC - [2011/01/27 23:15:33 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe
PRC - [2011/01/27 23:13:43 | 004,538,368 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
PRC - [2010/11/20 21:24:27 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe


========== Modules (No Company Name) ==========

MOD - [2015/02/09 09:58:11 | 000,110,080 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\pywint ypes27.dll
MOD - [2015/02/09 09:58:10 | 005,820,928 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtGui.pyd
MOD - [2015/02/09 09:58:10 | 001,662,976 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtCore.pyd
MOD - [2015/02/09 09:58:10 | 000,315,392 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtWebKit.pyd
MOD - [2015/02/09 09:58:10 | 000,201,216 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtOpenGL.pyd
MOD - [2015/02/09 09:58:10 | 000,191,488 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtXml.pyd
MOD - [2015/02/09 09:58:10 | 000,098,816 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\win32a pi.pyd
MOD - [2015/02/09 09:58:10 | 000,040,960 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\_socke t.pyd
MOD - [2015/02/09 09:58:09 | 000,721,920 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\_ssl.p yd
MOD - [2015/02/09 09:58:09 | 000,686,592 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\unicod edata.pyd
MOD - [2015/02/09 09:58:09 | 000,495,104 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtNetwork.pyd
MOD - [2015/02/09 09:58:09 | 000,285,184 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\_hashl ib.pyd
MOD - [2015/02/09 09:58:09 | 000,241,152 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtSql.pyd
MOD - [2015/02/09 09:58:09 | 000,084,480 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtSvg.pyd
MOD - [2015/02/09 09:58:09 | 000,069,632 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\sip.py d
MOD - [2015/02/09 09:58:09 | 000,022,016 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. QtTest.pyd
MOD - [2015/02/09 09:58:09 | 000,008,704 | ---- | M] () -- C:\Users\Danny\AppData\Local\Temp\_MEI79842\PyQt4. Qt.pyd
MOD - [2015/02/09 09:55:41 | 000,043,008 | ---- | M] () -- c:\Users\Danny\AppData\Local\Temp\dropbox_sqlite_e xt.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpm529i4.dll
MOD - [2015/02/05 10:28:24 | 016,852,144 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_ 305.dll
MOD - [2015/02/04 03:02:51 | 009,170,760 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\pdf. dll
MOD - [2015/02/04 03:02:47 | 001,117,512 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libg lesv2.dll
MOD - [2015/02/04 03:02:45 | 000,211,272 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\libe gl.dll
MOD - [2015/01/28 23:31:45 | 038,562,088 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2015/01/21 11:15:20 | 038,713,856 | ---- | M] () -- C:\Program Files (x86)\PacificPoker\bin\libcef.dll
MOD - [2015/01/21 11:15:20 | 000,880,128 | ---- | M] () -- C:\Program Files (x86)\PacificPoker\bin\libGLESv2.dll
MOD - [2015/01/21 11:15:20 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\PacificPoker\bin\libEGL.dll
MOD - [2015/01/21 11:15:16 | 000,873,472 | ---- | M] () -- C:\Program Files (x86)\PacificPoker\bin\ffmpegsumo.dll
MOD - [2015/01/17 01:03:19 | 010,069,504 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem\d18e2115a3270f89663fce831547f534\System.ni.dll
MOD - [2015/01/17 01:02:28 | 000,118,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMD iagnostics\93a0883923e78cc3e80b7ac4a9768c60\SMDiag nostics.ni.dll
MOD - [2015/01/17 01:01:54 | 019,734,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.ServiceModel\f9d8efe5e01d08740774a12f20a3e640\ System.ServiceModel.ni.dll
MOD - [2015/01/16 16:16:37 | 003,049,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.IdentityModel\201032e5afa8609da580589102a67857 \System.IdentityModel.ni.dll
MOD - [2015/01/16 16:16:19 | 001,123,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Servf73e6522#\edc5c7073370a2c2049f96761c1e3bfb \System.ServiceModel.Web.ni.dll
MOD - [2015/01/16 03:07:41 | 012,895,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Windows.Forms\d8223c30928e02bc7ed5b8b81effa7b5 \System.Windows.Forms.ni.dll
MOD - [2015/01/16 03:07:33 | 002,855,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Runteb92aa12#\187177229c00aec6dec613ea4b9ff209 \System.Runtime.Serialization.ni.dll
MOD - [2015/01/16 03:07:31 | 001,642,496 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Drawing\dd2f9ea99ac0f984b9dc430824638c9f\Syste m.Drawing.ni.dll
MOD - [2015/01/16 03:07:30 | 000,790,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Servd1dec626#\14cc73701aac461eb89d6473a88fcd56 \System.ServiceModel.Internals.ni.dll
MOD - [2015/01/16 03:05:54 | 007,793,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Xml\3d6ee4ffbd9a86ac1e7b01800b6fe9c7\System.Xm l.ni.dll
MOD - [2015/01/16 03:05:54 | 007,002,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Core\23d1162d1943c1b1d6c4fd7c6d8512d4\System.C ore.ni.dll
MOD - [2015/01/16 03:05:48 | 000,972,288 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Sys tem.Configuration\5a977e1f055b4f8f41da5d9142a1913c \System.Configuration.ni.dll
MOD - [2015/01/16 03:05:33 | 017,207,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\msc orlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni .dll
MOD - [2014/10/29 17:19:38 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Management\99cdfef98595ed91f14936cf52a49c54\Sy stem.Management.ni.dll
MOD - [2014/10/29 17:05:32 | 002,297,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Core\e3641fa3359f37ad12c84183ce765093\System.C ore.ni.dll
MOD - [2014/10/29 17:05:26 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.ServiceProce#\a229c5bed4a12b5db6ca55d223ada6df \System.ServiceProcess.ni.dll
MOD - [2014/10/29 17:04:34 | 012,435,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Windows.Forms\1453d9e9a4989833ef3db4b22549ba1a \System.Windows.Forms.ni.dll
MOD - [2014/10/29 17:04:25 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Drawing\836e10dfd0811b303553216f5cb092ef\Syste m.Drawing.ni.dll
MOD - [2014/10/29 17:04:19 | 005,467,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem.Xml\d49908aa93a23c84847b1f8b1b667860\System.Xm l.ni.dll
MOD - [2014/10/29 17:03:55 | 007,991,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Sys tem\908ba9e296e92b4e14bdc2437edac603\System.ni.dll
MOD - [2014/10/29 17:03:47 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\msc orlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni .dll
MOD - [2014/10/21 18:22:50 | 000,750,080 | ---- | M] () -- C:\Users\Danny\AppData\Roaming\Dropbox\bin\libGLES v2.dll
MOD - [2014/10/21 18:22:50 | 000,047,616 | ---- | M] () -- C:\Users\Danny\AppData\Roaming\Dropbox\bin\libEGL. dll
MOD - [2014/10/21 18:22:48 | 000,863,744 | ---- | M] () -- C:\Users\Danny\AppData\Roaming\Dropbox\bin\plugins \platforms\qwindows.dll
MOD - [2014/10/21 18:22:46 | 000,200,704 | ---- | M] () -- C:\Users\Danny\AppData\Roaming\Dropbox\bin\plugins \imageformats\qjpeg.dll
MOD - [2014/05/13 12:04:48 | 000,167,768 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2014/05/13 12:04:46 | 000,109,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2014/05/13 12:04:42 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2014/03/17 15:52:22 | 021,045,727 | ---- | M] () -- C:\Program Files (x86)\Electrum\electrum.exe
MOD - [2013/09/16 11:22:08 | 005,074,432 | ---- | M] () -- C:\Program Files (x86)\Hotkey\Hotkey.exe
MOD - [2013/06/01 14:31:46 | 000,106,496 | ---- | M] () -- C:\Program Files (x86)\Hotkey\en\HotKey.resources.dll
MOD - [2013/06/01 14:31:46 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Hotkey\en-US\HotKey.resources.dll
MOD - [2009/06/06 15:50:32 | 000,019,968 | ---- | M] () -- C:\Program Files (x86)\Hotkey\Audiodll.dll


========== Services (SafeList) ==========

SRV:64bit: - [2015/01/28 23:31:41 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2015/01/28 23:31:25 | 004,012,248 | ---- | M] (Avast Software) [On_Demand | Running] -- C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe -- (AvastVBoxSvc)
SRV:64bit: - [2014/11/21 20:35:29 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/08/22 13:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/08/22 13:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2014/07/22 17:31:23 | 000,172,344 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2014/03/11 19:16:00 | 000,282,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService1.0.0.0)
SRV:64bit: - [2013/06/13 15:59:34 | 003,376,880 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe -- (ZeroConfigService)
SRV:64bit: - [2013/06/13 15:59:22 | 000,273,136 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2013/06/13 15:59:14 | 000,626,416 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2013/06/13 15:59:00 | 000,149,744 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2013/04/05 04:51:58 | 000,183,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel(R)
SRV:64bit: - [2013/03/22 09:38:32 | 000,015,344 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV:64bit: - [2012/12/11 19:00:52 | 000,027,768 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
SRV - [2015/02/05 10:28:29 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/01/30 15:36:34 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/12/11 11:03:12 | 000,089,864 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService .exe -- (HPSupportSolutionsFrameworkService)
SRV - [2014/12/03 00:31:16 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/09/12 12:14:55 | 004,799,760 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014/04/11 23:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\msco rsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2014/03/20 16:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/03/11 19:16:04 | 000,279,024 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2013/06/23 19:32:38 | 001,132,920 | ---- | M] (Motorola Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe -- (Bluetooth Device Monitor)
SRV - [2013/05/29 18:50:24 | 000,046,592 | ---- | M] () [Auto | Running] -- c:\Program Files (x86)\Hotkey\PowerBiosServer.exe -- (PowerBiosServer)
SRV - [2013/04/23 16:50:50 | 001,366,392 | ---- | M] (Motorola Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe -- (Bluetooth Media Service)
SRV - [2013/04/23 16:50:46 | 001,153,400 | ---- | M] (Motorola Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)
SRV - [2012/11/15 01:49:48 | 002,468,496 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2011/01/27 23:15:33 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe -- (postgresql-8.4)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2015/02/09 11:49:44 | 000,129,752 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2015/01/30 23:32:04 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:64bit: - [2015/01/28 23:31:48 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2015/01/28 23:31:48 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2015/01/28 23:31:48 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2015/01/28 23:31:48 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2015/01/28 23:31:48 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2015/01/28 23:31:48 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2015/01/28 23:31:48 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2015/01/28 23:31:25 | 000,271,752 | ---- | M] (Avast Software) [Kernel | Auto | Running] -- C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys -- (VBoxAswDrv)
DRV:64bit: - [2014/08/15 21:35:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/07/17 16:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2014/03/20 12:43:02 | 000,118,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
DRV:64bit: - [2014/03/07 10:26:42 | 000,450,520 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2014/03/07 10:18:22 | 003,729,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2013/12/16 17:46:34 | 000,690,864 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:64bit: - [2013/06/28 02:02:24 | 003,467,232 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwsw02.sys -- (NETwNs64)
DRV:64bit: - [2013/06/13 12:53:34 | 000,112,072 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ibtusb.sys -- (ibtusb)
DRV:64bit: - [2013/04/26 11:24:58 | 000,020,464 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2013/04/26 11:24:56 | 000,786,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2013/04/26 11:24:56 | 000,368,112 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2013/04/23 16:50:24 | 000,132,920 | ---- | M] (Motorola Solutions, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmaux.sys -- (btmaux)
DRV:64bit: - [2013/04/23 16:50:22 | 001,385,272 | ---- | M] (Motorola Solutions, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmhsf.sys -- (btmhsf)
DRV:64bit: - [2013/03/22 09:38:18 | 000,678,384 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2013/03/22 09:38:18 | 000,028,656 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:64bit: - [2013/02/26 03:23:40 | 000,496,400 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1d62x64.sys -- (e1dexpress)
DRV:64bit: - [2012/11/30 03:05:40 | 000,464,184 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2012/11/30 03:05:38 | 000,031,032 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:64bit: - [2012/11/25 21:12:42 | 000,281,744 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsP2Stor.sys -- (RSP2STOR)
DRV:64bit: - [2012/10/03 14:14:56 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/07/22 10:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 15:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/03/11 00:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 00:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 21:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 21:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/20 21:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 21:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F2 5E CE 43 EE EE CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.highlightCount: 1
FF - prefs.js..browser.search.isUS: true
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_ 305.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_ 305.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Danny\AppData\Roaming\Mozilla\plugins\npg oogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Danny\AppData\Roaming\Mozilla\plugins\npo 1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Danny\AppData\Local\Google\Update\1.3.26. 9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Danny\AppData\Local\Google\Update\1.3.26. 9\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extens ions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2015/01/31 10:21:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2014/12/30 15:29:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Danny\AppData\Roaming\Mozilla\Extensions
[2015/01/30 15:11:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Danny\AppData\Roaming\Mozilla\Firefox\Pro files\fcr4qpmr.default\extensions
[2015/01/30 15:36:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2015/02/04 21:52:11 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========

CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhon fmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfi lokake\0.9_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigk jlhalf\6.4_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmn hjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldk acnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkd nihall\1.7_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljnie djpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihc jkigck\10.0.2502.149_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpeb giejap\1.1_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbi glidom\2.17_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki\10.0.2502.149_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgoln pehhpl\2015.129.433.2_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoe jaedia\7_1\

O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [BLEServicesCtrl] C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll (Motorola Solutions, Inc.)
O4:64bit: - HKLM..\Run: [CECAPLF] C:\Program Files (x86)\ChiconyCam\CECAPLF.exe (Chicony)
O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4:64bit: - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [CPN Notifier] C:\Program Files (x86)\Intertops Poker\PokerNotifier.exe File not found
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_980F3E46EDCC36C8F965DDC05D1 56569] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Users\Danny\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup\Dropbox.lnk = C:\Users\Danny\AppData\Roaming\Dropbox\bin\Dropbox .exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: SoftwareSASGeneration = 1
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 200.79.231.5 200.79.231.6
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{388EC68E-2434-4B81-B5E5-196DE9A7AA8B}: DhcpNameServer = 200.79.231.5 200.79.231.6
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{62900570-EE44-4AA6-9C65-C14F1AA9DC4B}: DhcpNameServer = 192.168.1.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


MsConfig:64bit - StartUpFolder: C:^Users^Danny^AppData^Roaming^Microsoft^Windows^S tart Menu^Programs^Startup^Dropbox.lnk - C:\Users\Danny\AppData\Roaming\Dropbox\bin\Dropbox .exe - (Dropbox, Inc.)
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: Aim - hkey= - key= - C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: Skype - hkey= - key= - C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig:64bit - StartUpReg: SUPERAntiSpyware - hkey= - key= - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware)
MsConfig:64bit - State: "startup" - Reg Error: Key error.

SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {26784146-6E05-3FF9-9335-786C7C0FB5BE} - .NET Framework
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} - .NET Framework
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {26784146-6E05-3FF9-9335-786C7C0FB5BE} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.111\Inst aller\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2015/02/09 12:00:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2015/02/09 11:59:58 | 000,021,040 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
[2015/02/09 11:59:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2015/02/09 11:59:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2015/02/08 21:48:15 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\cef-cache
[2015/02/08 21:48:13 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\theBorgata
[2015/02/08 21:47:09 | 000,000,000 | ---D | C] -- C:\Programs
[2015/02/08 21:41:45 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\CarbonPoker
[2015/02/08 21:41:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CarbonPoker
[2015/02/07 19:43:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Poker
[2015/02/07 19:43:31 | 000,000,000 | ---D | C] -- C:\True Poker
[2015/02/06 23:04:44 | 000,009,000 | ---- | C] (EldoS Corporation) -- C:\Windows\SysNative\elevtmsg.dll
[2015/02/06 16:20:21 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Electrum
[2015/02/06 16:20:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electrum
[2015/02/05 22:21:27 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\Electrum
[2015/02/04 22:02:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2015/02/04 22:01:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2015/02/04 22:01:46 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2015/02/04 22:01:45 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2015/02/04 22:01:45 | 000,000,000 | ---D | C] -- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
[2015/01/30 15:36:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015/01/28 23:58:19 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vbox
[2015/01/28 23:58:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vbox
[2015/01/28 23:32:38 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\AVAST Software
[2015/01/28 23:32:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2015/01/28 23:31:52 | 001,050,432 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2015/01/28 23:31:52 | 000,436,624 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2015/01/28 23:31:52 | 000,116,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2015/01/28 23:31:52 | 000,093,568 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2015/01/28 23:31:52 | 000,083,280 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2015/01/28 23:31:51 | 000,364,512 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2015/01/28 23:31:47 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2015/01/28 23:30:21 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2015/01/28 23:29:55 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2015/01/22 19:06:00 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\SitNGoWizard
[2015/01/19 22:16:28 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Intertops Poker
[2015/01/19 19:36:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Poker at bet365
[2015/01/18 15:01:21 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Local\Macromedia
[2015/01/18 15:00:16 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2015/01/17 15:36:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AmericasCardroom
[2015/01/17 15:36:30 | 000,000,000 | ---D | C] -- C:\AmericasCardroom
[2015/01/16 20:35:51 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Local\eclipse
[2015/01/16 20:33:54 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Local\CarbonPoker
[2015/01/14 09:59:18 | 000,000,000 | ---D | C] -- C:\Users\Danny\Documents\HandHistory
[2015/01/13 20:38:14 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2015/01/13 20:38:13 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2015/01/13 20:38:10 | 005,553,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015/01/13 20:38:09 | 003,971,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2015/01/13 20:38:09 | 003,916,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2015/01/13 20:38:08 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2015/01/13 20:38:08 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2015/01/13 20:38:08 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2015/01/13 00:23:39 | 000,000,000 | ---D | C] -- C:\Users\Danny\Documents\888poker
[2015/01/13 00:23:37 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\888poker
[2015/01/13 00:23:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\888poker
[2015/01/13 00:23:02 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\PacificPoker
[2015/01/13 00:22:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PacificPoker
[2015/01/13 00:17:39 | 000,000,000 | ---D | C] -- C:\Users\Danny\AppData\Roaming\Macromedia
[2015/01/13 00:17:36 | 000,701,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015/01/13 00:17:36 | 000,071,344 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015/01/13 00:17:32 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2015/01/13 00:17:28 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2015/01/13 00:14:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Titan Poker

========== Files - Modified Within 30 Days ==========

[2015/02/09 18:14:55 | 000,024,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/02/09 18:14:55 | 000,024,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/02/09 17:51:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/02/09 17:50:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1578670902-1798264098-2537406194-1001UA.job
[2015/02/09 17:28:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/02/09 14:50:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1578670902-1798264098-2537406194-1001Core.job
[2015/02/09 12:41:37 | 000,000,559 | ---- | M] () -- C:\Windows\wininit.ini
[2015/02/09 12:00:11 | 000,001,390 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2015/02/09 11:49:44 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015/02/09 11:34:38 | 000,783,606 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015/02/09 11:34:38 | 000,663,348 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015/02/09 11:34:38 | 000,122,682 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015/02/09 09:55:44 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/02/09 09:55:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/02/09 09:55:24 | 2084,450,303 | -HS- | M] () -- C:\hiberfil.sys
[2015/02/08 21:41:45 | 000,001,917 | ---- | M] () -- C:\Users\Danny\Desktop\CarbonPoker.lnk
[2015/02/08 13:45:20 | 000,001,099 | ---- | M] () -- C:\Users\Public\Desktop\HoldemManager2.lnk
[2015/02/07 19:43:35 | 000,001,485 | ---- | M] () -- C:\Users\Public\Desktop\True Poker.lnk
[2015/02/06 19:09:12 | 000,015,246 | ---- | M] () -- C:\Users\Danny\Documents\Database1.kdbx
[2015/02/06 16:20:21 | 000,001,018 | ---- | M] () -- C:\Users\Danny\Desktop\Electrum.lnk
[2015/02/05 10:28:28 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015/02/05 10:28:28 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2015/02/05 00:52:40 | 000,002,190 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2015/02/04 22:02:34 | 000,001,760 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2015/02/03 20:59:27 | 000,010,380 | ---- | M] () -- C:\Users\Danny\Documents\blo.odt
[2015/02/03 18:54:22 | 000,033,393 | ---- | M] () -- C:\Users\Danny\Documents\Canada Expenses.ods
[2015/02/01 10:53:35 | 000,021,355 | ---- | M] () -- C:\Users\Danny\Documents\5dimes.odt
[2015/01/30 23:32:04 | 001,050,432 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2015/01/29 10:19:22 | 000,300,056 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015/01/29 02:59:25 | 000,013,053 | ---- | M] () -- C:\Users\Danny\Documents\Sports Betting Prepicks.ods
[2015/01/28 23:32:11 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2015/01/28 23:31:48 | 000,436,624 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2015/01/28 23:31:48 | 000,364,512 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2015/01/28 23:31:48 | 000,267,632 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2015/01/28 23:31:48 | 000,116,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2015/01/28 23:31:48 | 000,093,568 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2015/01/28 23:31:48 | 000,083,280 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2015/01/28 23:31:48 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2015/01/28 23:31:48 | 000,029,208 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2015/01/28 23:31:47 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2015/01/28 20:26:45 | 000,004,968 | ---- | M] () -- C:\ProgramData\lrbivjdu.eai
[2015/01/23 15:18:36 | 000,015,327 | ---- | M] () -- C:\Users\Danny\Documents\mb post.odt
[2015/01/19 22:16:28 | 000,001,121 | ---- | M] () -- C:\Users\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\Intertops Poker.lnk
[2015/01/19 20:04:10 | 000,001,642 | ---- | M] () -- C:\Users\Public\Desktop\Poker at bet365.lnk
[2015/01/17 15:36:40 | 000,001,569 | ---- | M] () -- C:\Users\Public\Desktop\AmericasCardroom.lnk
[2015/01/16 03:03:26 | 000,776,220 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2015/01/13 00:23:37 | 000,002,032 | ---- | M] () -- C:\Users\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\888poker.lnk
[2015/01/13 00:23:37 | 000,002,014 | ---- | M] () -- C:\Users\Danny\Desktop\888poker.lnk
[2015/01/13 00:15:32 | 000,001,614 | ---- | M] () -- C:\Users\Public\Desktop\Titan Poker.lnk

========== Files Created - No Company Name ==========

[2015/02/09 12:41:37 | 000,000,559 | ---- | C] () -- C:\Windows\wininit.ini
[2015/02/09 12:00:11 | 000,001,402 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2015/02/09 12:00:11 | 000,001,390 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2015/02/08 21:41:45 | 000,001,917 | ---- | C] () -- C:\Users\Danny\Desktop\CarbonPoker.lnk
[2015/02/07 19:43:35 | 000,001,485 | ---- | C] () -- C:\Users\Public\Desktop\True Poker.lnk
[2015/02/06 18:02:30 | 000,015,246 | ---- | C] () -- C:\Users\Danny\Documents\Database1.kdbx
[2015/02/06 16:20:21 | 000,001,018 | ---- | C] () -- C:\Users\Danny\Desktop\Electrum.lnk
[2015/02/04 22:02:34 | 000,001,760 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2015/02/03 20:59:25 | 000,010,380 | ---- | C] () -- C:\Users\Danny\Documents\blo.odt
[2015/02/01 10:53:33 | 000,021,355 | ---- | C] () -- C:\Users\Danny\Documents\5dimes.odt
[2015/01/28 23:32:11 | 000,001,971 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2015/01/28 23:31:52 | 000,267,632 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2015/01/28 23:31:52 | 000,065,776 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2015/01/28 23:31:52 | 000,029,208 | ---- | C] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2015/01/28 20:26:45 | 000,004,968 | ---- | C] () -- C:\ProgramData\lrbivjdu.eai
[2015/01/23 14:43:25 | 000,015,327 | ---- | C] () -- C:\Users\Danny\Documents\mb post.odt
[2015/01/19 22:16:28 | 000,001,121 | ---- | C] () -- C:\Users\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\Intertops Poker.lnk
[2015/01/19 20:04:02 | 000,001,654 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Poker at bet365.lnk
[2015/01/19 20:04:02 | 000,001,642 | ---- | C] () -- C:\Users\Public\Desktop\Poker at bet365.lnk
[2015/01/17 15:36:40 | 000,001,569 | ---- | C] () -- C:\Users\Public\Desktop\AmericasCardroom.lnk
[2015/01/13 00:23:37 | 000,002,032 | ---- | C] () -- C:\Users\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\888poker.lnk
[2015/01/13 00:23:37 | 000,002,014 | ---- | C] () -- C:\Users\Danny\Desktop\888poker.lnk
[2015/01/13 00:17:38 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/01/13 00:15:32 | 000,001,626 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Titan Poker.lnk
[2015/01/13 00:15:32 | 000,001,614 | ---- | C] () -- C:\Users\Public\Desktop\Titan Poker.lnk
[2014/12/09 12:03:40 | 014,147,584 | ---- | C] () -- C:\Program Files (x86)\Common Files\lpuninstall.exe
[2014/10/30 15:45:28 | 000,000,045 | ---- | C] () -- C:\Users\Danny\AppData\Local\machpro.dat
[2014/10/17 12:36:55 | 000,000,024 | ---- | C] () -- C:\Windows\SetupTemp.ini
[2014/10/17 12:30:24 | 000,776,220 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/10/17 10:48:14 | 000,068,608 | ---- | C] () -- C:\Windows\SysWow64\igfxexps32.dll
[2014/10/17 10:47:56 | 000,342,944 | ---- | C] () -- C:\Windows\SysWow64\igdmd32.dll
[2014/10/17 10:47:49 | 000,183,296 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2014/10/17 10:47:49 | 000,142,848 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
[2013/05/13 16:48:06 | 002,567,680 | ---- | C] () -- C:\Windows\SysWow64\DeviceControl.exe

========== ZeroAccess Check ==========

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\cls id\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\cls id\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc8 7-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 20:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\cl sid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 19:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA 9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\cl sid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CD B-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\cl sid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %APPDATA%\Microsoft\*.* >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >
[2014/12/12 10:52:43 | 014,147,584 | ---- | M] () -- C:\Program Files (x86)\Common Files\lpuninstall.exe

< %systemroot%\winn32\*.* >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2015/02/04 21:52:11 | 000,260,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe
[2015/02/04 21:52:11 | 000,338,032 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
[2015/02/04 21:52:09 | 000,114,800 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
[2015/02/04 21:52:09 | 000,185,432 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
[2015/02/04 21:52:08 | 000,243,312 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
[2015/02/04 21:52:08 | 000,127,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe
[2015/02/04 21:52:08 | 000,273,008 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\updater.exe
[2015/02/04 21:52:08 | 000,091,032 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\webapp-uninstaller.exe
[2015/02/04 21:52:07 | 000,094,320 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe
[2015/02/04 21:52:07 | 000,073,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\wow_helper.exe

< %ProgramFiles%\TinyProxy. >

< %systemroot%\system32\*.* /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.* /lockedfiles >

< %PROGRAMFILES%\*. >
[2014/11/08 17:47:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
[2014/10/29 17:13:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AIM
[2014/10/29 17:17:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
[2014/10/17 12:51:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\BisonCam
[2014/10/29 17:17:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
[2015/02/09 15:01:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CarbonPoker
[2014/10/17 12:51:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ChiconyCam
[2014/10/17 12:44:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cisco
[2014/12/09 12:03:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
[2015/02/06 16:20:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electrum
[2015/01/29 20:33:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Full Tilt Poker
[2014/12/06 18:53:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
[2015/01/04 16:51:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hewlett-Packard
[2015/02/08 13:45:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Holdem Manager 2
[2014/10/17 12:39:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hotkey
[2015/01/04 16:51:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hp
[2014/10/17 12:51:26 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2014/10/17 12:45:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
[2014/12/11 02:05:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
[2015/01/19 22:16:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intertops Poker
[2015/02/04 22:01:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
[2014/11/11 17:40:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\KeePass Password Safe 2
[2014/12/03 18:06:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/10/17 12:38:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
[2014/12/09 11:43:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft OneDrive
[2014/10/29 14:47:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Security Client
[2014/10/17 12:28:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
[2015/02/04 21:52:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
[2015/01/31 10:21:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
[2014/10/29 17:19:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice 4
[2015/02/08 12:50:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PacificPoker
[2015/01/29 10:19:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Panda Security
[2015/01/19 20:11:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Poker at bet365
[2015/01/13 00:04:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PokerStars
[2014/11/02 11:29:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PostgreSQL
[2014/11/02 11:49:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PSQLINSTALL
[2014/10/17 12:36:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
[2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
[2014/11/02 11:28:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\RVG Software
[2014/10/29 17:15:57 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
[2015/02/09 12:14:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2015/02/09 02:58:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TableNinja
[2014/10/29 17:13:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TeamViewer
[2015/02/09 15:00:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Titan Poker
[2009/07/13 22:57:06 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information
[2014/10/17 12:36:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VIA
[2014/10/29 17:15:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VideoLAN
[2014/10/17 12:51:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WebCam
[2014/10/29 17:15:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Winamp
[2014/10/29 17:00:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
[2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
[2014/10/29 17:09:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
[2009/07/13 23:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
[2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
[2010/11/20 21:31:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
[2010/11/21 01:06:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar

< MD5 for: EXPLORER.EXE >
[2011/02/25 23:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87 e574ddfe652d\explorer.exe
[2014/06/24 10:42:02 | 004,818,848 | ---- | M] (Safer-Networking Ltd.) MD5=280C014187E24860A7C860329513208F -- C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
[2011/02/25 00:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 00:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa7 9dc39081d0ba\explorer.exe
[2011/02/26 00:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b033 3b22a99da332\explorer.exe
[2010/11/20 21:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f 56d3c4bcbafb\explorer.exe
[2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc 4815c4e292b5\explorer.exe
[2010/11/20 21:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afda ac81905bf900\explorer.exe

< MD5 for: NETLOGON.DLL >
[2010/11/20 21:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010/11/20 21:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bdd bcb24e997298\netlogon.dll
[2010/11/20 21:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010/11/20 21:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632 670482fa3493\netlogon.dll

< MD5 for: SERVICES.EXE >
[2009/07/13 19:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/13 19:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_ none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591a fc466a15356\svchost.exe
[2014/11/21 05:12:42 | 000,761,656 | ---- | M] (MalwareBytes) MD5=625BB08813743947985B0DEEFC35ED12 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
[2009/07/13 19:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/13 19:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04 b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 21:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 21:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de30 24012ff21116\userinit.exe
[2010/11/20 21:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 21:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4e bf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 21:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde9 0685eb910636\winlogon.exe
[2014/11/21 05:12:42 | 000,761,656 | ---- | M] (MalwareBytes) MD5=625BB08813743947985B0DEEFC35ED12 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2014/03/04 05:08:14 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=6CE2AE073BD21C542FC2C707CAE944CC -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_ce74 8d1d04acf24f\winlogon.exe
[2014/03/04 03:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_cdf8 bf35eb848572\winlogon.exe
[2014/07/16 20:07:24 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=8CEBD9D0A0A879CDE9F36F4383B7CAEA -- C:\Windows\SysNative\winlogon.exe
[2014/07/16 20:07:24 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=8CEBD9D0A0A879CDE9F36F4383B7CAEA -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18540_none_cdc4 7ed1ebad0e4e\winlogon.exe
[2014/07/15 21:23:23 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=98AA0BFEE089C7E5DADB94190D93456C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22750_none_ce43 4d9704d2c730\winlogon.exe

< hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Win dowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2015/02/04 21:52:08 | 000,922,168 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2015/02/04 21:52:08 | 000,922,168 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2015/02/04 21:52:08 | 000,922,168 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\shell\open\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [2015/02/04 21:52:11 | 000,338,032 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2015/02/04 21:52:11 | 000,338,032 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2015/02/04 21:52:11 | 000,338,032 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --hide-icons [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --show-icons [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\shell\open\command\\: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2014/11/26 19:43:02 | 000,813,744 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2014/11/26 19:43:02 | 000,813,744 | ---- | M] (Microsoft Corporation)

< hklm\software\clients\startmenuinternet|command /64 /rs >
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2015/02/04 21:52:08 | 000,922,168 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2015/02/04 21:52:08 | 000,922,168 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2015/02/04 21:52:08 | 000,922,168 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\shell\open\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" [2015/02/04 21:52:11 | 000,338,032 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -PREFERENCES [2015/02/04 21:52:11 | 000,338,032 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\FIREFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -SAFE-MODE [2015/02/04 21:52:11 | 000,338,032 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\Google Chrome\shell\open\command\\: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" [2015/02/04 03:02:55 | 000,843,592 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2014/11/21 19:49:29 | 000,718,848 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2014/11/21 19:49:29 | 000,718,848 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2014/11/21 19:49:29 | 000,718,848 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2014/11/26 19:43:02 | 000,813,744 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinter net\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE [2014/11/26 19:43:02 | 000,813,744 | ---- | M] (Microsoft Corporation)

< hkcu\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /s >

< hklm\SOFTWARE\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 83 bytes -> C:\Users\Danny\Desktop\KeePass 2.lnk:com.dropbox.attributes
@Alternate Data Stream - 81 bytes -> C:\Program Files (x86)\Intertops Poker:MID

< End of report >
Questions, questions Quote
02-09-2015 , 07:30 PM
OTL Extras logfile created on: 2/9/2015 6:20:14 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Danny\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.92 Gb Total Physical Memory | 4.32 Gb Available Physical Memory | 54.56% Memory free
15.84 Gb Paging File | 11.76 Gb Available in Paging File | 74.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.54 Gb Total Space | 147.95 Gb Free Space | 63.62% Space Free | Partition Type: NTFS

Computer Name: DANNY-PC | User Name: Danny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\PublicPr ofile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Firewall Rules]
"{030B96F5-0529-4DDA-8D0A-EDF9CA6494AC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A3F7537-1A83-40DA-96F7-8E83A4B1ED35}" = lport=5432 | protocol=6 | dir=in | name=postgres |
"{0FDA6317-A152-4312-ACA4-21ACFA2D1049}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1882F332-917D-4D47-800C-C2AE30560574}" = rport=10243 | protocol=6 | dir=out | app=system |
"{1E13C1F5-82F0-47F7-866A-724C78FB7376}" = rport=139 | protocol=6 | dir=out | app=system |
"{20D5E9B1-B964-4B4F-87E0-775D8DCDE6FB}" = rport=445 | protocol=6 | dir=out | app=system |
"{21310976-CCAE-47CC-A76C-7653A00673C9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{254A37CE-3F6E-4E31-8163-D512DB428D75}" = rport=138 | protocol=17 | dir=out | app=system |
"{3D123ADF-62B6-4C0D-BCF8-3EC311E5A111}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4B27351F-5E8C-40EA-976A-2BFCE9949D31}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4E196F7E-999B-4070-B105-01ADE5784B1F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{56B038D1-8053-4B13-B7CE-CB1B0697C220}" = lport=137 | protocol=17 | dir=in | app=system |
"{5E1DEB32-5E4B-49FA-8EB9-01E6D335029B}" = lport=138 | protocol=17 | dir=in | app=system |
"{7D6B4EDD-EBE7-4B89-8984-F465EF84ADEB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{89D27C18-0F26-4921-9C3F-5D251DDA3D81}" = lport=445 | protocol=6 | dir=in | app=system |
"{C4A08D8E-5626-4F6B-B2D8-42EB48E16DE6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C8E364DC-1337-42BB-9B07-553ACD6C381E}" = rport=137 | protocol=17 | dir=out | app=system |
"{CAF26776-8337-4DBD-A0E7-1046B1494DD3}" = lport=139 | protocol=6 | dir=in | app=system |
"{CD2116FF-B1A8-4BBF-A186-F3A3DFDAB416}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D376F8DC-1829-48BC-8EB0-47CBC3D34395}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EB474610-3FA9-4735-A2AD-8A7879AFB99D}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{EFE9A3A3-8DB3-4100-BCFD-75B75CADD221}" = lport=10243 | protocol=6 | dir=in | app=system |
"{F9044B72-5952-45AB-B6DA-0D5152128E67}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Firewall Rules]
"{01508B2F-1038-4C71-BD5C-D6F9AD45F61A}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{04242FC0-6862-4948-AAE6-154E4E03AACB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{05759751-B78D-4803-B57C-41EA081331BF}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{1003CD2F-FA64-4EEC-972E-FC160BFB608C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{105F4BAA-2BB8-4F10-A1B7-84BD517456A9}" = protocol=6 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{10F442C4-3034-4A3A-B81A-ED364DDD3C93}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1E4F0BA0-CA68-44E7-9FE0-8879CBC7354C}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{2D0A998A-1993-4957-99C7-61D298285F51}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{31A76C41-31E9-4736-B523-1684B9EC7AB1}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{31D04460-3EC5-4413-AE17-A9CA6B783A1C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3289FCC3-7812-4121-AA0B-040D5B3D8210}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{44E64CF0-F9F3-47AB-8FFC-2609729626CD}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{4DD1F377-FB2D-4637-B2A8-689B46E9B451}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{64A9B8FD-9706-44F3-913F-B8EDA2072068}" = protocol=17 | dir=in | app=c:\program files (x86)\intertops poker\pokerclient.exe |
"{651CFE8F-1377-4D9B-8D7E-70B0096E8756}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{67F9B3FC-A034-43F2-BEF6-EA54525FBBFE}" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"{6C831929-F375-4E5B-B603-F6AF9F2986FD}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{72D212F1-FA44-44BA-BE7B-6A6D1649AA18}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{813F5BF9-741B-43A4-B837-A9EEAB66D65B}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{87EC4E68-817E-45D3-AE63-C72E6AAA2E72}" = protocol=6 | dir=out | app=system |
"{8D0EC126-2E2A-4798-A432-18BECBC05217}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8D58ABFB-7C59-4A99-8910-3AC915E414DD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{94D4292C-8F79-47C4-92DE-A5D2094636E3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{97F0A734-EFD4-4473-99AC-95ABEBBB5C3D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{9ED32E55-1503-4626-A0F8-01DF9479E0CD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A699940C-D896-430C-A1F4-6034CAEF6C0D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B0C8B0D8-A568-4D3B-8DBE-6C050DC8B3C1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B0D343DB-BDC8-43E6-A065-B8F70DA93CDB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B995F8E7-477C-440C-8480-9E12CC3E5B22}" = protocol=17 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{BF7E8647-7327-4EE7-B484-6CA77544B0C4}" = protocol=17 | dir=in | app=c:\users\danny\appdata\roaming\dropbox\bin\dro pbox.exe |
"{C4CCCAF0-A59C-4D9C-9A6B-39FAD66DE683}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{C6ED2D3D-3243-473E-94BB-AC5E13CCEA45}" = protocol=6 | dir=in | app=c:\program files (x86)\intertops poker\pokerclient.exe |
"{D2CA1C5D-4CE4-4D84-9FE6-A5ECA4FA2B7C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D790B7C6-A130-47D7-ADB7-8251BA834E59}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DA666098-4329-465A-B0B6-0EB8EABC191A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{DD7DF1E6-03C2-4496-AFB8-235F44E4F2BC}" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"{DF74079C-0BCA-46F9-8D0F-2069C6AAFCFD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E13C4DD5-AD4A-44D8-8041-FA1CAC602047}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{E1A66A8A-AA0D-4F15-94A1-63EE8757AEEF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F059D671-547D-4A44-AAA5-FF3B7DBB5829}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{F2A4000F-0B16-4E4F-8B74-72BD51ECF5F8}" = protocol=6 | dir=in | app=c:\users\danny\appdata\roaming\dropbox\bin\dro pbox.exe |
"{FEF0E579-5F81-4F0E-9F2C-058DBB713808}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{A54773CC-EF11-429F-AFF4-5415950A475B}C:\users\danny\appdata\roaming\dropbo x\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\danny\appdata\roaming\dropbox\bin\dro pbox.exe |
"TCP Query User{F93D8B47-AF1E-4847-9F2D-B440E7DAD262}C:\program files (x86)\pacificpoker\bin\poker.exe" = protocol=6 | dir=in | app=c:\program files (x86)\pacificpoker\bin\poker.exe |
"UDP Query User{A4C5947F-FE54-4E21-90AF-205FD2286FB6}C:\program files (x86)\pacificpoker\bin\poker.exe" = protocol=17 | dir=in | app=c:\program files (x86)\pacificpoker\bin\poker.exe |
"UDP Query User{D67A4E7F-8926-4C3A-9F6D-D60975345651}C:\users\danny\appdata\roaming\dropbo x\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\danny\appdata\roaming\dropbox\bin\dro pbox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall]
"{1CEAC85D-2590-4760-800F-8DE5E91F3700}" = Intel(R) Management Engine Components
"{23F2C78C-E131-4CA0-8F84-3473FB7728BA}" = Microsoft Security Client
"{26784146-6E05-3FF9-9335-786C7C0FB5BE}" = Microsoft .NET Framework 4.5.2
"{28791292-D18D-42FA-AE66-3D3D20AA8618}" = Apple Application Support (64-bit)
"{302600C1-6BDF-4FD1-1306-148929CC1385}" = Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{54F2237F-018C-483B-8884-9FC0D88840C3}" = VC_CRT_x64
"{5EB368A4-562A-41B6-A5B3-06054A27F5A6}" = Intel(R) Rapid Storage Technology
"{5ED7462B-EF58-4757-B609-53755021EC34}" = Apple Mobile Device Support
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7B8D4E8A-EA2B-4A71-BFEB-A4AAAB87C5D0}" = iTunes
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.2
"{bda3368d-37bf-4e4a-84b3-3cc1b2155e46}" = Intel(R) PRO/Wireless Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D4FC649C-0247-4873-930D-D9E6904DCAF5}" = Intel(R) Management Engine Components
"{DD1AF090-041E-4403-B27A-AC6FA4B985E8}" = Intel® PROSet/Wireless WiFi Software
"{FCF3ECF7-7AE0-4E26-B387-09A3A80B79CC}" = Intel(R) Network Connections 18.3.72.0
"Microsoft Security Client" = Microsoft Security Essentials
"PROSetDX" = Intel(R) Network Connections 18.3.72.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 5.20 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall]
"{164714B6-46BC-4649-9A30-A6ED32F03B5A}" = Hotkey 7.0032
"{1845470B-EB14-4ABC-835B-E36C693DC07D}" = Skype™ 6.21
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{22ACCF34-7FF3-3990-B0DA-697C8A16F121}" = Google Chrome
"{240AED60-1548-49C6-AB90-C069C1807A57}" = TableNinja
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{2A14D7BC-1876-4B38-830B-18856C27F550}" = WebCam Installer
"{2FE00055-C4F3-4F7A-AEDD-E198D54CF12F}" = Apple Application Support (32-bit)
"{5BBC4803-C96E-4D3E-9D1D-2E43774C4062}" = BisonCam
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{702b0b5f-bcbb-44fc-b613-e96f2a3006ed}" = Intel® PROSet/Wireless Software
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{90150000-0138-0409-0000-0000000FF1CE}" = Microsoft Office
"{9395F41D-0F80-432E-9A59-B8E477E7E163}" = OpenOffice 4.1.1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2201542-DA80-457F-8BD9-6C9C90196481}" = ChiconyCam
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.10)
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C77CC230-7417-3F01-B70D-52583DC9FEC9}" = Google Talk Plugin
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{E35601C0-BA8E-4F32-919A-C7EF4CA81F67}" = HP Support Solutions Framework
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"296836EA-EF3A-4C36-8C13-3A6C1DB2D4BE" = AmericasCardroom
"888poker" = 888poker
"9A147762-0190-4F8B-B8C9-64A6A6838F5C" = True Poker
"Adobe Flash Player ActiveX" = Adobe Flash Player 16 ActiveX
"Adobe Flash Player NPAPI" = Adobe Flash Player 16 NPAPI
"AIM_7" = AIM 7
"Avast" = Avast Free Antivirus
"bet365poker" = Poker at bet365
"FE4D6F94-B3D5-484b-94F7-8BC45DEB7A82" = BlackChipPoker
"herdProtectScan" = herdProtect Anti-Malware Scanner
"HoldemManager" = Holdem Manager
"HoldemManager2" = Holdem Manager 2
"InstallShield_{164714B6-46BC-4649-9A30-A6ED32F03B5A}" = Hotkey 7.0032
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{2A14D7BC-1876-4B38-830B-18856C27F550}" = WebCam Installer
"Intertops Poker" = Intertops Poker
"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.28
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.4.1028
"Mozilla Firefox 35.0.1 (x86 en-US)" = Mozilla Firefox 35.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"PokerStars" = PokerStars
"PostgreSQL 8.4" = PostgreSQL 8.4
"TeamViewer 9" = TeamViewer 9
"Titan Poker" = Titan Poker
"VLC media player" = VLC media player
"Winamp" = Winamp

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Uninstall]
"CarbonPoker" = CarbonPoker
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/9/2015 4:30:49 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:31:04 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:31:09 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:31:24 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:31:44 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:32:04 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:32:09 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:32:14 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:32:24 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:32:29 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

Error - 2/9/2015 4:32:34 PM | Computer Name = Danny-PC | Source = PostgreSQL | ID = 0
Description =

[ System Events ]
Error - 1/27/2015 2:44:20 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7031
Description = The Panda Protection Service service terminated unexpectedly. It
has done this 2 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 1/27/2015 2:44:20 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7034
Description = The Panda Protection Service service terminated unexpectedly. It
has done this 3 time(s).

Error - 1/27/2015 2:45:54 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7031
Description = The Panda Product Service service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 1/27/2015 2:45:54 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7031
Description = The Panda Product Service service terminated unexpectedly. It has
done this 2 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 1/27/2015 2:45:54 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7034
Description = The Panda Product Service service terminated unexpectedly. It has
done this 3 time(s).

Error - 1/27/2015 2:46:39 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/27/2015 3:55:41 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/27/2015 7:44:49 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/28/2015 2:24:01 PM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/29/2015 1:21:17 AM | Computer Name = Danny-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5


< End of report >

Last edited by PaulyJames200x; 02-09-2015 at 07:42 PM.
Questions, questions Quote
02-09-2015 , 08:25 PM
http://www.7-zip.org/download.html



which link am i suppose to click on?
Questions, questions Quote
02-09-2015 , 09:15 PM
Swapping your HDD with an SSD often requires some BIOS adjustments, fwiw:

How to configure bios for SSD installation.

Note: The advice in the article might not apply 100% to your hardware. I just googled "SSD BIOS settings" and linked the first article as an example.
Questions, questions Quote
02-09-2015 , 09:56 PM
Quote:
Originally Posted by PaulyJames200x
http://www.7-zip.org/download.html



which link am i suppose to click on?
Download the 32 bit version if you have a 32 bit OS, 64 bit version if you have a 64 bit OS. I'm guessing you don't know which one you have. To find it:

1) Right click on my computer in the task menu/desktop. This will show information about your computer.

2) Under system, find the one that says "system type".

3) That will tell you if your OS is 32 bit or 64 bit. Download the relevant msi or exe link.
Questions, questions Quote
02-09-2015 , 10:04 PM
I have the 64 bit but not sure which one it is. Is it the msi. file?
Questions, questions Quote
02-09-2015 , 10:15 PM
This one, not the beta version

Download 7-Zip 9.20 (2010-11-18) for Windows:

.msi 64-bit x64 7-Zip for 64-bit Windows x64 (Intel 64 or AMD64)
Questions, questions Quote
02-09-2015 , 10:32 PM
okay done. So how do i do it for each document? I dont see any word that says this.


So basically i have to do each document/picture/video then? Could i copy a few of the videos/pictures and do a password for all of them same or it has to be separate one by one? Obviously if its all at same time, it would be same password i assume. But i definitely want to put 1 password for everything.
Questions, questions Quote
02-09-2015 , 10:54 PM
I don't have 7 zip installed so that's as far as I can go. There is usually an option somewhere that allows you to add files to an existing zip file.
Questions, questions Quote
02-10-2015 , 11:03 AM
Do those 2 files tell you anything about my computer whether theres virus/malware or something else? As you can see theres lot of Errors i see mentioned.
Questions, questions Quote
02-11-2015 , 01:55 AM
Another way is to use keypass and just attach the file to an entry.
After you have attached the file and saved the keypass db, you can delete the original.

Keypass v1 was quick, but you will need to save the files back to your harddrive to view.
Keypass v2 was slower to save the db but allows you to view w/o saving to disk.

Keypass v2 also allows you to attach multiple files to a single entry which could make things easier if you plan to protect a lot.

Last edited by xyzzz; 02-11-2015 at 02:06 AM.
Questions, questions Quote

      
m