<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Safer-Networking Forums</title>
		<link>http://forums.spybot.info/</link>
		<description><![CDATA[Support forums for Spybot-S&amp;D and other products by Safer-Networking Limited]]></description>
		<language>en</language>
		<lastBuildDate>Wed, 22 May 2013 14:58:07 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.spybot.info/images/misc/rss.png</url>
			<title>Safer-Networking Forums</title>
			<link>http://forums.spybot.info/</link>
		</image>
		<item>
			<title>Manual Removal Guide for SimplyTech.HomeTab</title>
			<link>http://forums.spybot.info/showthread.php?68614-Manual-Removal-Guide-for-SimplyTech-HomeTab&amp;goto=newpost</link>
			<pubDate>Wed, 22 May 2013 10:20:40 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "SimplyTech.HomeTab" manually. 
Use this guide at your own risk; software...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;SimplyTech.HomeTab&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li style="">malware</li></ul><br />
<b>Description:</b> <div style="margin-left:40px">SimplyTech.HomeTab is a malicious software that gets installed without proper consent if bundled for instance in the CovusPro.Installer. It installs itself with generic names like newtab, hometab, browserupdate and launcher to avoid detection. It installes browser addons to display fraudulent advertising. The company also uses various names like Simply Tech, Predicted Media and HomeTab.</div><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Installed Software List:</font></b></font><br />
<br />
You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> or <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> to locate and get rid of these entries.<br />
<ul><li style="">Products that have a key or property named <i>&quot;{c5eac06d-16a7-4836-866d-ebf3ecfdcdaa}_is1&quot;</i>.</li><li style="">Products that have a key or property named <i>&quot;Browser Updater_is1&quot;</i>.</li><li style="">Products that have a key or property named <i>&quot;Protected Search_is1&quot;</i>.</li></ul><br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these files.<br />
<ul><li style="">The file at <i>&quot;&lt;$APPDATA&gt;\HomeTab\HomeTab.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$APPDATA&gt;\SimplyTech\home\home.htm&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\background.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\bundler\background.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\bundler\newtab.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\html1.htm&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\npwiddit.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\panel.htm&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\pop.htm&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\widdit.htm&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Local Storage\chrome-extension_djbdlklldbflagkkpaljamjfbpefcbpf_0.localstorage&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Local Storage\chrome-extension_djbdlklldbflagkkpaljamjfbpefcbpf_0.localstorage-journal&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALAPPDATA&gt;\HomeTab\contact.png&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$LOCALSETTINGS&gt;\Temp\43169_3580\default_search_provider12.png&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Browser Updater\Microsoft.Win32.TaskScheduler.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Browser Updater\Microsoft.Win32.TaskScheduler.xml&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Browser Updater\TaskSchedulerCreator.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Browser Updater\TBUpdater.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Browser Updater\unins000.dat&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Browser Updater\unins000.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\chrome\HomeTab.crx&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\hometab_icon.ico&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\InstallHelper.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\InstallHelperNet4.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\Interop.IWshRuntimeLibrary.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\chrome.manifest&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\chrome\HomeTab_3580.jar&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\components\wtb_complete.js&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\install.js&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\install.rdf&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\plugins\npwiddit.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\pop.htm&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\System.Data.SQLite.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\ToolbarUninstall.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\unins000.dat&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\unins000.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Mozilla Firefox\searchplugins\Web Search.xml&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$WINDIR&gt;\Launcher.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$WINDIR&gt;\Tasks\Browser Updater.job&quot;</i>.</li></ul>Make sure you set your file manager to display hidden and system files. If SimplyTech.HomeTab uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify files!<br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<br />
<ul><li style="">The directory at <i>&quot;&lt;$APPDATA&gt;\HomeTab&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$APPDATA&gt;\Mozilla\Firefox\Profiles\&lt;$ENV(HomeTab_FF_path)&gt;\extensions\{aa9cc3fa-a5e4-449b-aab5-1ebdbc7314ee}&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$APPDATA&gt;\SimplyTech\home&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$APPDATA&gt;\SimplyTech&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0\bundler&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf\2.7_0&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$LOCALAPPDATA&gt;\Google\Chrome\User Data\Default\Extensions\djbdlklldbflagkkpaljamjfbpefcbpf&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$LOCALAPPDATA&gt;\HomeTab&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$LOCALAPPDATA&gt;\SimplyTech&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$LOCALSETTINGS&gt;\Temp\43169_3580&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Browser Updater&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\chrome&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\chrome&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\components&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com\plugins&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab\support@HomeTab.com&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\HomeTab&quot;</i>.</li></ul>Make sure you set your file manager to display hidden and system files. If SimplyTech.HomeTab uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<br />
<ul><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.Band.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.Band&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.NotificationSource.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.NotificationSource&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.SourceSinkImpl.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.SourceSinkImpl&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.ToolbarInfo.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;wtb.ToolbarInfo&quot;</i>, plus associated values.</li><li style="">Delete the registry key <i>&quot;{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{515e8851-15c5-4b5a-9c31-25d3dfc6302f}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{6e80943c-847c-4447-b830-f94e7dcbbd4e}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{74600557-e870-41ad-910a-83eba6cdc3ce}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{8DA8B89E-0C65-403B-8231-AB22ECFA0687}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{96edaac7-6183-4cb5-8823-b8b12d94f967}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{96edaac7-6183-4cb5-8823-b8b12d94f967}&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{96edaac7-6183-4cb5-8823-b8b12d94f967}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{A928E66C-F501-4E66-9953-855C712F93B2}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{A928E66C-F501-4E66-9953-855C712F93B2}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{afdbddaa-5d3f-42ee-b79c-185a7020515b}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{B7DC94D1-A06F-411B-9396-70CC757A9133}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\TypeLib\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{cfd485f0-96bd-47cd-bb6d-cd7dda95f102}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{ddb73aac-1a18-4c2d-878a-eef8936ec374}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{E6B4EE8F-C38E-4994-BE28-229A3F92262C}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{FCA8936E-403A-4487-A966-70F80F1D5A6A}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;BrowserUpdater&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;djbdlklldbflagkkpaljamjfbpefcbpf&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;HomeTab.DLL&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;HomeTab&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;HomeTab&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\AppDataLow\Software\Simplytech\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;ProtectedSearch&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;SimplyTech&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;Simplytech&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\AppDataLow\Software\&quot;</i>.</li><li style="">Delete the registry value <i>&quot;{96edaac7-6183-4cb5-8823-b8b12d94f967}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\&quot;</i>.</li><li style="">Delete the registry value <i>&quot;newtab&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\&quot;</i>.</li><li style="">Remove <i>&quot;about<b></b>:newtab&quot;</i> from registry value <i>&quot;Start Default_Page_URL&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\&quot;</i>.</li><li style="">Remove <i>&quot;about<b></b>:newtab&quot;</i> from registry value <i>&quot;Start Default_Page_URL&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\&quot;</i>.</li><li style="">Remove <i>&quot;about<b></b>:newtab&quot;</i> from registry value <i>&quot;Start Page&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\&quot;</i>.</li><li style="">Remove <i>&quot;about<b></b>:newtab&quot;</i> from registry value <i>&quot;Start Page&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\&quot;</i>.</li><li style="">Remove <i>&quot;about<b></b>:newtab&quot;</i> from registry value <i>&quot;Start Page&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\&quot;</i>.</li></ul>If SimplyTech.HomeTab uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="3"><b><font color="Navy">Browser:</font></b></font><br />
<br />
The following browser plugins or items can either be removed directly in your browser, or through the help of e.g. <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> or <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a>.<br />
<ul><li style="">Please check your bookmarks for links to <i>&quot;about<b></b>:newtab&quot;</i>.</li></ul><br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help, <ol class="decimal"><li style=""><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li><li style="">Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li></ol><br />
<br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?54-Malware-Removal-Guides">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68614-Manual-Removal-Guide-for-SimplyTech-HomeTab</guid>
		</item>
		<item>
			<title>Manual Removal Guide for FakePorn.Winlock</title>
			<link>http://forums.spybot.info/showthread.php?68613-Manual-Removal-Guide-for-FakePorn-Winlock&amp;goto=newpost</link>
			<pubDate>Wed, 22 May 2013 10:20:38 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "FakePorn.Winlock" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;FakePorn.Winlock&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li style="">trojan</li></ul><br />
<b>Description:</b> <div style="margin-left:40px">FakePorn.Winlock is a Trojan horse that pretends to be a porn video to get executed. Once run it will lock down the computer while pretending to demand money for official authorities because of copyright infringement done by the computer user. Removal requires the usage of a different user account or a different boot media.</div><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help, <ol class="decimal"><li style=""><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li><li style="">Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li></ol><br />
<br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?54-Malware-Removal-Guides">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68613-Manual-Removal-Guide-for-FakePorn-Winlock</guid>
		</item>
		<item>
			<title>Manual Removal Guide for Bandoo.Toolbar</title>
			<link>http://forums.spybot.info/showthread.php?68612-Manual-Removal-Guide-for-Bandoo-Toolbar&amp;goto=newpost</link>
			<pubDate>Wed, 22 May 2013 10:20:08 GMT</pubDate>
			<description><![CDATA[The following instructions have been created to help you to get rid of "Bandoo.Toolbar" manually. 
Use this guide at your own risk; software should...]]></description>
			<content:encoded><![CDATA[<div>The following instructions have been created to help you to get rid of <i>&quot;Bandoo.Toolbar&quot;</i> manually.<br />
Use this guide at your own risk; software <i>should</i> usually be better suited to remove malware, since it is able to look deeper.<br />
<br />
If this guide was helpful to you, please consider <a href="http://www.safer-networking.org/index.php?page=donate" target="_blank">donating towards this site</a>.<br />
<br />
<font size="5"><b><font color="Navy">Threat Details:</font></b></font><br />
<br />
<b>Categories:</b><ul><li style="">pups</li></ul><br />
<b>Description:</b> <div style="margin-left:40px">Bandoo.Toolbar promises free emoticons for instant messengers like MSN and Yahoo IM. Bandoo.Toolbar installs hidden toolbars to browser and also installs a service which runs in background. By default the installer will install adware and set the homepage to searchnu. The installer also fails to show an EULA and the privacy policy, it also does not explicitly show that users must be older than 12.</div><font size="5"><b><font color="Navy">Removal Instructions:</font></b></font><br />
<br />
<font size="3"><b><font color="Navy">Installed Software List:</font></b></font><br />
<br />
You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> or <a href="http://www.safer-networking.org/index.php?page=runalyzer" target="_blank">RunAlyzer</a> to locate and get rid of these entries.<br />
<ul><li style="">Products that have a key or property named <i>&quot;Bandoo&quot;</i>.</li></ul><br />
<font size="3"><b><font color="Navy">Files:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these files.<br />
<ul><li style="">The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\Bandoo\Bandoo Extensions.lnk&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\Bandoo\Bandoo Tutorial.lnk&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$COMMONPROGRAMS&gt;\Bandoo\License Agreement.lnk&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Bandoo.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\BandooGo.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\BandooRes.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\BandooUI.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\BndCore.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\BndHook.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\ChromePackage.crx&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\CrashRpt.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\ExtensionsManager.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\ffext.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\FlashAnimator.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\ftalk.ico&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\GIFAnimator.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\InstallerNsisHelper.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\libungif4.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\license.rtf&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins.ini&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\IE\ieplugin.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\IE\Resources\bandoo.js&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\IE\Resources\HTML\blank.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\IE\Resources\HTML\error.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\msnplugin.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\Resources\HTML\blank.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\Resources\HTML\error.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\Resources\Toolbar\BandooToolbar.xml&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources\HTML\blank.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources\HTML\error.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources\Toolbar\BandooToolbar.xml&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources\Toolbar\BandooToolbarV9.xml&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\YahooPlugin.dll&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Resources\BandooMessages.xml&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Resources\downloading.gif&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Resources\tutorial\tutorial.html&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\uninstall.log&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\uninstaller.exe&quot;</i>.</li><li style="">The file at <i>&quot;&lt;$SYSDIR&gt;\Macromed\Flash\FlashPlayerTrust\Bandoo.cfg&quot;</i>.</li></ul>Make sure you set your file manager to display hidden and system files. If Bandoo.Toolbar uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify files!<br />
<br />
<b>Important:</b> There are more files that cannot be safely described in simple words. Please use <a href="http://www.safer-networking.org/index.php?page=spybotsd" target="_blank">Spybot-S&amp;D</a> to remove them.<br />
<br />
<font size="3"><b><font color="Navy">Folders:</font></b></font><br />
<br />
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.<br />
<ul><li style="">The directory at <i>&quot;&lt;$APPDATA&gt;\Mozilla\Firefox\Profiles\&lt;$ENV(Bandoo_FF_path)&gt;\extensions\ffox@bandoo.com&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$COMMONAPPDATA&gt;\Bandoo&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$COMMONPROGRAMS&gt;\Bandoo&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\IE\Resources\HTML&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\IE\Resources&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\IE&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\Resources\HTML&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\Resources\Toolbar\Images&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\Resources\Toolbar&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN\Resources&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\MSN&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources\HTML&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources\Toolbar\Images&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources\Toolbar&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo\Resources&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins\Yahoo&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Plugins&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Resources\tutorial&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo\Resources&quot;</i>.</li><li style="">The directory at <i>&quot;&lt;$PROGRAMFILES&gt;\Bandoo&quot;</i>.</li></ul>Make sure you set your file manager to display hidden and system files. If Bandoo.Toolbar uses rootkit technologies, use our <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
You will have to use a global search for files without a name specified. <b>Be extra careful</b>, because just the name might not be enough to identify folders!<br />
<br />
<font size="3"><b><font color="Navy">Registry:</font></b></font><br />
<br />
You can use <i>regedit.exe</i> (included in Windows) to locate and delete these registry entries.<br />
<ul><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.BandooCoordinator.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.BandooCoordinator&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.CoordinatorUI.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.CoordinatorUI&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.HTTPAsyncResult.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.HTTPAsyncResult&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.PlugInNotifier.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCoordinator.PlugInNotifier&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.BandooCore.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.BandooCore&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.ResourcesMngr.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.ResourcesMngr&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.SettingsMngr.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.SettingsMngr&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.StatisticMngr.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooCore.StatisticMngr&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooIEPlugin.BandooIEPlugin.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BandooIEPlugin.BandooIEPlugin&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BFlashAnimator.BFlashAnimatorCtrl.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BFlashAnimator.BFlashAnimatorCtrl&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BGIFAnimator.BGIFAnimatorCtrl.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;BGIFAnimator.BGIFAnimatorCtrl&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPDataAccessor.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPDataAccessor&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPDownloadStatus.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPDownloadStatus&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPFileDownloadService.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPFileDownloadService&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPProxyInfo.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPProxyInfo&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPService.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPService&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPServiceFactory.1&quot;</i>, plus associated values.</li><li style="">A key in HKEY_CLASSES_ROOT\ named <i>&quot;CURL.HTTPServiceFactory&quot;</i>, plus associated values.</li><li style="">Delete the registry key <i>&quot;{01222E21-6BD0-4EB3-94F1-967EB09CCED5}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{06DE5702-44CF-4B79-B4EF-3DDF653358F5}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{074E4EFE-81BB-4EA4-866E-082CB0E01070}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{0CE5B352-9D9C-41E1-9551-FCCD92820217}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{1301A8A5-3DFB-4731-A162-B357D00C9644}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{167B2B5F-2757-434A-BBDA-2FDB2003F14F}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{266294D5-5A0D-46E8-9294-BCB6EAFA478F}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{27F69C85-64E1-43CE-98B5-3C9F22FB408E}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{2E9A60EA-5554-49C3-BC9D-D0404DBACC62}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{33DDFC61-F531-4982-8C32-4212B7835D44}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{3AD7A5B6-610D-4A82-979E-0AED20920690}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{3AD7A5B6-610D-4A82-979E-0AED20920690}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\TypeLib\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{3E63C9BC-DD51-4E83-ABA6-B350EAD28531}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{424624F4-C5DD-4e1d-BDD0-1E9C9B7799CC}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{4410C118-B23C-406C-9F52-9CDABD90A5EA}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\TypeLib\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{44CFFEF4-E7E1-44BD-B1F5-29F828ADA1B8}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{477F210A-2A86-4666-9C4B-1189634D2C84}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{518CA0FD-F755-4F98-A2A8-CD450FB203AB}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{5E9B4D72-C58D-48BF-AC09-68182D472160}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{6087829B-114F-42A1-A72B-B4AEDCEA4E5B}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{62E5C9E1-A0E8-4F8C-8EAF-0F9250CC5786}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\TypeLib\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{6F43FA77-C18F-4D0C-9C7E-958876FE2061}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{72434BC1-E46D-47A1-A597-8749DFBCC24A}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{7DBA2B02-EA31-4B98-812B-C6E8AE5C2972}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{7f000001-db8e-f89c-2fec-49bf726f8c12}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{872F3C0B-4462-424c-BB9F-74C6899B9F92}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\TypeLib\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{929FCA79-44E2-4408-83E7-F93AAE0B0909}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{94FBDF11-676E-42E5-A516-1FD39970386B}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{9932C738-5580-4408-A0E8-5EA03BE5FB18}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{9C123289-82E1-4da7-A3C2-B8D28AAD114B}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{9C123289-82E1-4DA7-A3C2-B8D28AAD114B}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\TypeLib\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{A01A3335-0C30-4312-A430-92356CC37A92}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{A288B32D-1001-479F-8DA2-E259010B7A31}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{A5D99259-ADA3-48A5-B861-39813B713DCB}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{A9005ED5-4A1D-4606-A4DF-1A25E7D7B417}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{AFFA986E-4B0F-4F15-9DDC-19FE8129602A}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{B348A16C-64A6-4EAE-A42A-722623572C7E}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{B543EF05-9758-464E-9F37-4C28525B4A4C}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{BB76A90B-2B4C-4378-8506-9A2B6E16943C}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{C29CF951-7F4F-4B8D-ACA8-C4EE934C27DC}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{CE1CB632-6817-47b3-8587-D05AF75D6D5A}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{D60A7941-4F69-4A79-BED7-72ADA784B8F7}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{DF948646-8BF4-450E-A059-CF8A4E0FE2BE}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{DFF35F25-E783-4E26-8DA6-EBB66B8B0E39}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{E57D3C8D-ADD0-4AE0-8A14-0D0F6A3487FB}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{E96B49B0-E11F-48FC-984A-EEC29A4F57E1}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{EB5CEE80-030A-4ED8-8E20-454E9C68380F}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{EB5CEE80-030A-4ED8-8E20-454E9C68380F}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{EDE2C296-2458-4E3B-A846-4B512C0703B5}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{EF2B6317-C367-401B-83B8-80302D6588A7}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{F5379B4B-24D8-432A-9A96-BE75EE5117DB}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{F7FB2BC4-6C27-4EAC-B5E2-037B71FDE101}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{F9189560-573A-4fde-B055-AE7B0F4CF080}&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{FD53FE35-4368-4B71-89D6-F29F3DB29DF1}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\CLSID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;{FF871E51-2655-4D06-AED5-745962A96B32}&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Interface\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;Bandoo Coordinator&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;Bandoo Coordinator&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;Bandoo Coordinator&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;Bandoo&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;BandooCoordinator.EXE&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;BandooCore.EXE&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;BandooV8.exe&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\Applications\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;dloejdefkancmfajekobpfoacecnhpgp&quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;FlashAnimator.DLL&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;GIFAnimator.DLL&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry key <i>&quot;IEPlugin.DLL&quot;</i> at <i>&quot;HKEY_CLASSES_ROOT\AppID\&quot;</i>.</li><li style="">Delete the registry value <i>&quot;AppInit_DLLs=&lt;$PROGRAMFILES&gt;\bandoo\bndhook.dll &quot;</i> at <i>&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\&quot;</i>.</li><li style="">Delete the registry value <i>&quot;ffox@bandoo.com&quot;</i> at <i>&quot;HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\&quot;</i>.</li></ul>If Bandoo.Toolbar uses rootkit technologies, use our <a href="http://www.safer-networking.org/index.php?page=regalyzer" target="_blank">RegAlyzer</a>, <a href="http://forums.spybot.info/downloads.php?id=8" target="_blank">RootAlyzer</a> or our <a href="http://forums.spybot.info/downloads.php?id=3" target="_blank">Total Commander anti-rootkit plugins</a>.<br />
<br />
<font size="5"><b><font color="Navy">Final Words:</font></b></font><br />
<br />
If neither Spybot-S&amp;D nor self help did resolve the issue or you would prefer one on one help, <ol class="decimal"><li style=""><a href="http://forums.spybot.info/showthread.php?t=288" target="_blank">Please read these instructions</a> <b>before</b> requesting assistance,</li><li style="">Then start your own thread in the <a href="http://forums.spybot.info/forumdisplay.php?f=22" target="_blank">Malware Removal Forum</a> where a volunteer analyst will advise you as soon as available.</li></ol><br />
<br />
There are more files or system entries belonging to this product that &lt;$SPYBOTSD&gt; can remove, but that cannot be easily described in text. Please use &lt;$SPYBOTSD&gt; to make sure &lt;$PRODUCTNAME&gt; gets completely removed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?54-Malware-Removal-Guides">Malware Removal Guides</category>
			<dc:creator>Friday</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68612-Manual-Removal-Guide-for-Bandoo-Toolbar</guid>
		</item>
		<item>
			<title>Simple question - What does PUPSC stand for?</title>
			<link>http://forums.spybot.info/showthread.php?68611-Simple-question-What-does-PUPSC-stand-for&amp;goto=newpost</link>
			<pubDate>Wed, 22 May 2013 09:38:30 GMT</pubDate>
			<description><![CDATA[OK so I occasionally get a result of a "PUPSC" as the "threat" after a scan. 
 
I think it's important that _if_ abbreviations are used, then those...]]></description>
			<content:encoded><![CDATA[<div>OK so I occasionally get a result of a &quot;PUPSC&quot; as the &quot;threat&quot; after a scan.<br />
<br />
I think it's important that <u>if</u> abbreviations are used, then those abbreviations should always be explained (or even just mentioned!) in the Help files for the program, but in this case it isn't. <br />
(It's not just Spybot that fails here, I've even had it where whole menu items in professional programs are not mentioned in their own 'Help')<br />
<br />
Anyway, so I've searched the forum here, and in several places it tells me that &quot;PUP&quot; = &quot;potentially unwanted program&quot;, but everyone seems very quiet about what the &quot;SC&quot; may mean.<br />
<br />
Can anyone just give the full meaning for the letters PUPSC please?<br />
<br />
Thanks!</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?4-Spybot">Spybot</category>
			<dc:creator>Andy_P2002</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68611-Simple-question-What-does-PUPSC-stand-for</guid>
		</item>
		<item>
			<title>4 days</title>
			<link>http://forums.spybot.info/showthread.php?68610-4-days&amp;goto=newpost</link>
			<pubDate>Wed, 22 May 2013 06:44:17 GMT</pubDate>
			<description><![CDATA[http://forums.spybot.info/showthread.php?68572-browser-hijacked 
I 've set up ERUNT and read how to make it work properly on Windows 7.]]></description>
			<content:encoded><![CDATA[<div><a href="http://forums.spybot.info/showthread.php?68572-browser-hijacked" target="_blank">http://forums.spybot.info/showthread...owser-hijacked</a><br />
I 've set up ERUNT and read how to make it work properly on Windows 7.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?37-The-Waiting-Room">The Waiting Room</category>
			<dc:creator>elenagarchom</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68610-4-days</guid>
		</item>
		<item>
			<title>Annoying pop-ups in all browsers in bottom right/left corner</title>
			<link>http://forums.spybot.info/showthread.php?68605-Annoying-pop-ups-in-all-browsers-in-bottom-right-left-corner&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 22:36:40 GMT</pubDate>
			<description>Hello. 
 
Some unwanted and annoying ads keep popping up in all of my browsers (Firefox, Chrome, IE) for the last few months in almost all websites...</description>
			<content:encoded><![CDATA[<div>Hello.<br />
<br />
Some unwanted and annoying ads keep popping up in all of my browsers (Firefox, Chrome, IE) for the last few months in almost all websites except facebook and google. I tried some malware removal tools like tdsskiller and rkill, but it didn't solve the problem. There are three kinds of popups which keep coming: one is a square shaped ad in left-bottom corner of the browser, then a facebook message kind of popup in the right bottom corner (with that typical FB msg notification sound) which usually has the &quot;are you looking for + <i>title of the webpage</i>?&quot; as its message, and the third is a rectangular white box in the right bottom corner with a 'click here' button which when clicked redirects to &quot;tlbsearch.com&quot;. I tried some suggestions in some forums which has further complicated things for me. Earlier first type of pop-up (the left bottom corner) had a close button with which I can close it. Now it has become invisible and I am not able to access the left bottom corner of any of my browsers at all, hence not able to click any links or html objects in that place of the browser.<br />
<br />
I got annoyed to an extent of taking it to service center before finding out this forum. I appreciate the effort and time of those who contribute to this forum, so thanks a lot in advance.<br />
<br />
Waiting for your guidance,<br />
SS<br />
<br />
PS, I use a 64-bit Windows-7 Fujitsu laptop, if that info is needed.</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?22-Malware-Removal">Malware Removal</category>
			<dc:creator>anton_ego</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68605-Annoying-pop-ups-in-all-browsers-in-bottom-right-left-corner</guid>
		</item>
		<item>
			<title>Continuation - Infection Cleanout</title>
			<link>http://forums.spybot.info/showthread.php?68604-Continuation-Infection-Cleanout&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 22:01:16 GMT</pubDate>
			<description><![CDATA[Well, I get pulled away for a few days and the thread gets archived! Understandable, but hopefully we can continue, and if not, well. That's that...]]></description>
			<content:encoded><![CDATA[<div>Well, I get pulled away for a few days and the thread gets archived! Understandable, but hopefully we can continue, and if not, well. That's that then. I finally had the time to sit down and run the requested scanner, which I really didn't want to leave on overnight, but had too. <br />
<br />
Quote from what I was to-do:<br />
<div class="bbcode_container">
	<div class="bbcode_description">Quote:</div>
	<div class="bbcode_quote printable">
		<hr />
		
			0k. thanks for the info. Not sure why Roguekiller is flagging those .exe on your desktop. They dont appear to be cracks or keygens.<br />
<br />
In any case we can remove the proxy setting. Run Rougekiller again, after the prescan is done click the scan button. Once thats done click on the Registry tab and uncheck everything but this one:<br />
<br />
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (203.232.208.116:8080<br />
Then click the delete button to remove the checked item.<br />
<br />
You can get a copy of the free version of malwarebytes which you can use as another antimalware app: Let see if it digs anything up.<br />
<br />
Please download the free version of Malwarebytes to your desktop.<br />
<br />
Double-click mbam-setup.exe and follow the prompts to install the program.<br />
<br />
Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.<br />
<br />
If an update is found, it will download and install the latest version.<br />
<br />
Once the program has loaded, select Perform FULL SCAN, then click Scan.<br />
When the scan is complete, click OK, then Show Results to view the results.<br />
<br />
Be sure that everything is checked, and click *Remove Selected.*<br />
<br />
*A restart of your computer may be required to remove some items. If prompted please restart your computer to complete the fix.*<br />
<br />
When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start &gt; All Programs &gt; Malwarebytes' Anti-Malware &gt; Logs &gt; log-date.txt<br />
Post the log in your reply.<br />
NOTE: The free version must be updated manually and a scan started manually.
			
		<hr />
	</div>
</div><a href="http://forums.spybot.info/showthread.php?68481-Infected-Computer-Hacked-Account" target="_blank">http://forums.spybot.info/showthread...Hacked-Account</a><br />
<br />
So I ran Roguekill a few nights ago when I could and didn't find any sort of Proxy or HKCU in the results, nothing that looked close unfortunately. Then I went on a trip and had to take care of the house (that pesky lawn) with some fire department and ambulance corp events respectfully and finally ran Malwarebytes overnight last night. It didn't find anything, which hopefully means I'm on the up and up and won't be having any account theft issues.<br />
<br />
Malwarebytes Anti-Malware 1.75.0.1300<br />
<a href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.05.20.08<br />
<br />
Windows 7 Service Pack 1 x64 NTFS<br />
Internet Explorer 8.0.7601.17514<br />
Cameron :: CAMERON-PC [administrator]<br />
<br />
5/20/2013 10:00:10 PM<br />
mbam-log-2013-05-20 (22-00-10).txt<br />
<br />
Scan type: Full scan (C:\|D:\|F:\|)<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 812763<br />
Time elapsed: 3 hour(s), 25 minute(s), 22 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 0<br />
(No malicious items detected)<br />
<br />
(end)</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?22-Malware-Removal">Malware Removal</category>
			<dc:creator>Redfefnir</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68604-Continuation-Infection-Cleanout</guid>
		</item>
		<item>
			<title>The end of Spybot.</title>
			<link>http://forums.spybot.info/showthread.php?68603-The-end-of-Spybot&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 21:19:14 GMT</pubDate>
			<description>Dear friends and developers of Spybot, I have always been fond of your utility and as a PC Reclamation and Networking Technician, and you will be...</description>
			<content:encoded><![CDATA[<div>Dear friends and developers of Spybot, I have always been fond of your utility and as a PC Reclamation and Networking Technician, and you will be missed. I would like to say that up until your sudden shift in business strategy, I toted your name and encouraged donations from every personal client I met, and even some people when I worked for IBM and DELL as a Field Service Technician as I preformed virus removals and registry restructuring.<br />
<br />
<b>It seems that your spirit of free marketing and non-profit antivirus solutions for the masses, has died.</b> A short burst of cash from your current stature, will eventually lead to your inevitable downfall and destruction. Any technician worth his salt understands that there are a plethora of other free anti-virus solutions, even if its doing things the old-fashioned way.. A companies network and security structure, even down to a small business is not made up of executives willing to spend money. They will find one or several computer technicians to find a solution for them, and they <b>(we) will pursue the most affordable option even if its not the &quot;best&quot;, especially in this economy.</b><br />
<br />
<b>Your companies removal of its primary antivirus function in the free edition will lose you favor in the eyes of technicians</b>, not because you don't have a wonderful product that has a history of efficiency and a long standing record of success (which I can vouch for), but because there are so many OTHER free (working) solutions, that your product falls short of when finances come into play. I started my personal business as a street technician, and preformed a full hardware diagnostic and virus removal for $20 to put food on my plate. Now, I'm not alone. <b>The costs of removals and repairs in commercial are comparable to buying a BRAND NEW PC.</b> The field of professional technicians who are capable of password removals, data recovery, solder rework and yes, even virus removal has all but dried up in this desert of an economy. My point is this: <b>If I offered a virus removal for $40 (a little under what most local tech shops offer, which is 60-80 due to their labor and building slot costs) and I have to pay $50 for ONE copy of Spybot with antivirus, not only am I losing money? I am wasting time. My time. My clients time.</b> And that is not a real figure. The reality is, A company, tech shop, refurbishing warehouse or home user will find the free solutions instead of purchasing ANY product, and that is the bottom-line.<br />
<br />
<b>Farewell old friend, and enjoy the coinage while it lasts. As of today I am permanently removing you from my toolkit.</b></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?4-Spybot">Spybot</category>
			<dc:creator>Steve Staubach</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68603-The-end-of-Spybot</guid>
		</item>
		<item>
			<title>AV questions  accedently put in dutch section sorry</title>
			<link>http://forums.spybot.info/showthread.php?68601-AV-questions-accedently-put-in-dutch-section-sorry&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 15:44:07 GMT</pubDate>
			<description>question about AV 
    1 which AV is it 
    2 can i use this SB w AV WITH my current NORTON AV  or will it nag to take norton out 
    reason i left...</description>
			<content:encoded><![CDATA[<div>question about AV<br />
    1 which AV is it<br />
    2 can i use this SB w AV WITH my current NORTON AV  or will it nag to take norton out<br />
    reason i left ADAWARE w vipre was it nagged me to uinstall norton to install it<br />
    if i say NO it wouldn't continue<br />
    if it forces me choose im staying w 16x</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?4-Spybot">Spybot</category>
			<dc:creator>cootmaster</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68601-AV-questions-accedently-put-in-dutch-section-sorry</guid>
		</item>
		<item>
			<title>Spybot +AV 2.1 ist da!</title>
			<link>http://forums.spybot.info/showthread.php?68600-Spybot-AV-2-1-ist-da!&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 15:26:41 GMT</pubDate>
			<description>Hallo, 
 
ich habe gerade Spybot +AV 2.1 final auf unsere Server hochgeladen. Spybot +AV 2.1 ist somit die aktuelle stabile Version unserer Software!...</description>
			<content:encoded><![CDATA[<div>Hallo,<br />
<br />
ich habe gerade Spybot +AV 2.1 final auf unsere Server hochgeladen. Spybot +AV 2.1 ist somit die aktuelle stabile Version unserer Software!<br />
<br />
Alles Weitere könnt ihr auf unserer <a href="http://www.safer-networking.org/" target="_blank">Webseite</a> nachlesen, dort findet ihr auch die Download-Links.<br />
<br />
In diesem Thread könnt ihr über die neue Version diskutieren!<br />
<br />
daemon</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?15-Spybot-in-deutsch">Spybot in deutsch</category>
			<dc:creator>daemon</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68600-Spybot-AV-2-1-ist-da!</guid>
		</item>
		<item>
			<title>Spybot +AV 2.1 released!</title>
			<link>http://forums.spybot.info/showthread.php?68599-Spybot-AV-2-1-released!&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 15:02:32 GMT</pubDate>
			<description>Spybot +AV 2.1 final just got released! :) 
 
See our web site (http://www.safer-networking.org/) for more information and download links. 
 
daemon</description>
			<content:encoded><![CDATA[<div>Spybot +AV 2.1 final just got released! :)<br />
<br />
See our <a href="http://www.safer-networking.org/" target="_blank">web site</a> for more information and download links.<br />
<br />
daemon</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?4-Spybot">Spybot</category>
			<dc:creator>daemon</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68599-Spybot-AV-2-1-released!</guid>
		</item>
		<item>
			<title>Spybot +AV 2.1 Released!</title>
			<link>http://forums.spybot.info/showthread.php?68598-Spybot-AV-2-1-Released!&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 13:40:09 GMT</pubDate>
			<description>Not only does Spybot +AV version have an award winning antivirus engine but it has many new features and enhancements:- Virus scanning and removal...</description>
			<content:encoded><![CDATA[<div>Not only does Spybot +AV version have an award winning antivirus engine but it has many new features and enhancements:- Virus scanning and removal (Home Edition and above): The inclusion of the anti-virus engine means that we can now &#8230; <a href="http://www.safer-networking.org/2013/spybot-av-2-1-released/" target="_blank">Continue reading &#8594;</a><br />
<br />
<a href="http://www.safer-networking.org/2013/spybot-av-2-1-released/" target="_blank">More...</a></div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?2-Announcements">Announcements</category>
			<dc:creator>PepiMK</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68598-Spybot-AV-2-1-Released!</guid>
		</item>
		<item>
			<title>Spybot 2.1</title>
			<link>http://forums.spybot.info/showthread.php?68597-Spybot-2-1&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 12:59:02 GMT</pubDate>
			<description>Hey... 
 
There will be a little surprise later today... 
Or maybe a big one *g*  
:yahoo: 
 
Best regards 
Sandra 
Team Spybot</description>
			<content:encoded><![CDATA[<div>Hey...<br />
<br />
There will be a little surprise later today...<br />
Or maybe a big one *g* <br />
:yahoo:<br />
<br />
Best regards<br />
Sandra<br />
Team Spybot</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?4-Spybot">Spybot</category>
			<dc:creator>spybotsandra</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68597-Spybot-2-1</guid>
		</item>
		<item>
			<title>Cannot uninstall Spybot 2</title>
			<link>http://forums.spybot.info/showthread.php?68596-Cannot-uninstall-Spybot-2&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 10:33:48 GMT</pubDate>
			<description>Hello, 
I want to uninstall Spybot (version 2.0.1.2) from my windows7 x64 machine. 
When i try to run the uninstall feature, just nothing happens....</description>
			<content:encoded><![CDATA[<div>Hello,<br />
I want to uninstall Spybot (version 2.0.1.2) from my windows7 x64 machine.<br />
When i try to run the uninstall feature, just nothing happens.<br />
When i try to uninstall from windows add\remove software, still nothing happens.<br />
Tried both methods in safe mode, same result.<br />
Tried running CCcleaner first, same result.<br />
Tried terminating S&amp;D processes and services before uninstalling, same result, just NOTHING happens.<br />
<br />
Can anyone help me?<br />
Thanks in advance :)</div>

]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?4-Spybot">Spybot</category>
			<dc:creator>eggiog</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68596-Cannot-uninstall-Spybot-2</guid>
		</item>
		<item>
			<title>Help with sound problem</title>
			<link>http://forums.spybot.info/showthread.php?68595-Help-with-sound-problem&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 07:46:26 GMT</pubDate>
			<description><![CDATA[I hear a sound like 'water dripping' when i log into my internet browser. The sound is random, but persistent and irritating. 
 
Spybot and MBAM...]]></description>
			<content:encoded><![CDATA[<div>I hear a sound like 'water dripping' when i log into my internet browser. The sound is random, but persistent and irritating.<br />
<br />
Spybot and MBAM could not detect any problems, so maybe not a malware issue. Howver any advise would be much appreciated  to resolve this problem.<br />
<br />
Many Thanks<br />
<br />
<br />
logs as requested:<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 10.0.9200.16537<br />
Run by gary at 7:58:42 on 2013-05-21<br />
Microsoft Windows 8  6.2.9200.0.1252.44.2057.18.8075.4445 [GMT 1:00]<br />
.<br />
AV: AVG Anti-Virus 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}<br />
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: AVG Anti-Virus 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe<br />
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\system32\dwm.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Program Files\IDT\WDM\STacSV64.exe<br />
C:\Windows\system32\Hpservice.exe<br />
C:\Windows\System32\WUDFHost.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k WbioSvcGroup<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\svchost.exe -k apphost<br />
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe<br />
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Windows\system32\dashost.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe<br />
C:\Program Files\Intel\iCLS Client\HeciServer.exe<br />
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe<br />
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe<br />
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\Windows\system32\valWBFPolicyService.exe<br />
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\Windows\system32\taskhostex.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe<br />
C:\Program Files\Common Files\AuthenTec\TrueService.exe<br />
C:\Program Files\Common Files\AuthenTec\TrueService.exe<br />
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\System32\RuntimeBroker.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\IDT\WDM\sttray64.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE<br />
C:\Users\gary\AppData\Roaming\uTorrent\uTorrent.exe<br />
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe<br />
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe<br />
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe<br />
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe<br />
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe<br />
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe<br />
C:\Program Files (x86)\AVG\AVG2013\avgui.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe<br />
C:\Users\gary\AppData\Roaming\ViStart\Plugins\MetroProvider.exe<br />
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe<br />
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\explorer.exe<br />
C:\Users\gary\AppData\Roaming\ViStart\ViStart.exe<br />
C:\Users\gary\AppData\Roaming\ViStart\Plugins\SearchProvider.exe<br />
C:\Program Files (x86)\Windows Media Player\wmplayer.exe<br />
C:\Program Files (x86)\HP SimplePass\TouchControl.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\msiexec.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\System32\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
mWinlogon: Userinit = userinit.exe,<br />
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll<br />
uRun: [ViStart] C:\Users\gary\AppData\Roaming\ViStart\ViStart.exe<br />
uRun: [uTorrent] &quot;C:\Users\gary\AppData\Roaming\uTorrent\uTorrent.exe&quot;  /MINIMIZED<br />
uRun: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent<br />
mRun: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
mRun: [CLVirtualDrive] &quot;C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe&quot; /R<br />
mRun: [RemoteControl10] &quot;C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe&quot;<br />
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe<br />
mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey<br />
mRun: [AVG_UI] &quot;C:\Program Files (x86)\AVG\AVG2013\avgui.exe&quot; /TRAYONLY<br />
StartupFolder: C:\Users\gary\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\ISCTSY~1.LNK - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe<br />
IE: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe<br />
.<br />
INFO: HKCU has more than 50 listed domains.<br />
If you wish to scan all of them, select the 'Force scan all domains' option.<br />
.<br />
.<br />
INFO: HKLM has more than 50 listed domains.<br />
   If you wish to scan all of them, select the 'Force scan all domains' option.<br />
.<br />
TCP: NameServer = 192.168.0.1<br />
TCP: Interfaces\{11B2500D-0EDA-41C0-8154-A5D0512BF4E3} : DHCPNameServer = 192.168.0.1<br />
TCP: Interfaces\{ADA4012E-DD59-4E3C-B823-B53527DFB77F} : DHCPNameServer = 100.100.10.24<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe<br />
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe<br />
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe<br />
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe<br />
x64-Run: [BTMTrayAgent] rundll32.exe &quot;C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll&quot;,TrayApp<br />
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe<br />
.<br />
INFO: x64-HKLM has more than 50 listed domains.<br />
   If you wish to scan all of them, select the 'Force scan all domains' option.<br />
.<br />
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - &lt;orphaned&gt;<br />
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - &lt;orphaned&gt;<br />
x64-Notify: igfxcui - igfxdev.dll<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
Hosts: 127.0.0.1	<a href="http://www.spywareinfo.com" target="_blank">www.spywareinfo.com</a><br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\gary\AppData\Roaming\Mozilla\Firefox\Profiles\8ni317tu.default\<br />
FF - plugin: C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll<br />
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll<br />
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll<br />
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll<br />
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll<br />
FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll<br />
FF - ExtSQL: 2013-04-30 17:24; {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}; C:\Users\gary\AppData\Roaming\Mozilla\Firefox\Profiles\8ni317tu.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}<br />
FF - ExtSQL: 2013-04-30 19:12; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\gary\AppData\Roaming\Mozilla\Firefox\Profiles\8ni317tu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 amdkmpfd;AMD PCI Root Bus Lower Filter;C:\Windows\System32\Drivers\amdkmpfd.sys [2012-7-9 35496]<br />
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\Drivers\avgidsha.sys [2012-10-15 63328]<br />
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\Drivers\avgloga.sys [2012-9-21 225120]<br />
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\Drivers\avgmfx64.sys [2012-11-15 111968]<br />
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\Drivers\avgrkx64.sys [2012-9-14 40800]<br />
R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-31 645952]<br />
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\Drivers\avgidsdrivera.sys [2012-10-22 154464]<br />
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\Drivers\avgldx64.sys [2012-10-2 185696]<br />
R1 CLVirtualDrive;CLVirtualDrive;C:\Windows\System32\Drivers\CLVirtualDrive.sys [2012-12-25 92536]<br />
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-8-1 239616]<br />
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-7-17 731688]<br />
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]<br />
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]<br />
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-12-25 1091520]<br />
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-12-25 1112000]<br />
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-5-2 135952]<br />
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [2012-8-10 1641320]<br />
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-8-10 85504]<br />
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2012-8-10 29600]<br />
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-7-31 35232]<br />
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-4-20 635104]<br />
R2 ISCTAgent;ISCT Always Updated Agent;C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2012-7-24 146984]<br />
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-12-25 165760]<br />
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-5-1 418376]<br />
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-5-1 701512]<br />
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-12-25 364416]<br />
R2 valWBFPolicyService;Validity WBF Policy Service;C:\Windows\System32\valWBFPolicyService.exe [2012-9-6 28160]<br />
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2012-7-18 2699568]<br />
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;C:\Windows\System32\Drivers\AmpPal.sys [2012-7-17 162344]<br />
R3 BthLEEnum;Bluetooth Low Energy Driver;C:\Windows\System32\Drivers\BthLEEnum.sys [2012-7-26 202752]<br />
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\Drivers\btmaux.sys [2012-12-25 110592]<br />
R3 btmhsf;btmhsf;C:\Windows\System32\Drivers\btmhsf.sys [2012-12-25 825344]<br />
R3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\Drivers\iBtFltCoex.sys [2012-12-25 55848]<br />
R3 ikbevent;Intel Upper keyboard Class Filter Driver;C:\Windows\System32\Drivers\ikbevent.sys [2012-7-24 20968]<br />
R3 imsevent;Intel Upper Mouse Class Filter Driver;C:\Windows\System32\Drivers\imsevent.sys [2012-7-24 19944]<br />
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\Drivers\IntcDAud.sys [2012-6-19 342528]<br />
R3 intelkmd;intelkmd;C:\Windows\System32\Drivers\igdpmd64.sys [2012-7-25 8982208]<br />
R3 ISCT;Intel(R) Smart Connect Technology Device Driver;C:\Windows\System32\Drivers\ISCTD64.sys [2012-7-24 46016]<br />
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\Drivers\iwdbus.sys [2012-8-9 25568]<br />
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-5-1 25928]<br />
R3 NETwNe64;@oem15.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit;C:\Windows\System32\Drivers\NETwew00.sys [2012-8-7 4273192]<br />
R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\System32\Drivers\RtsBaStor.sys [2012-12-25 294544]<br />
R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-12-25 690832]<br />
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2012-12-25 43832]<br />
R3 TrueService;TrueAPI Service component;C:\Program Files\Common Files\AuthenTec\TrueService.exe [2012-7-16 401256]<br />
R3 WirelessButtonDriver;HP Wireless Button Driver Service;C:\Windows\System32\Drivers\WirelessButtonDriver64.sys [2012-8-3 20288]<br />
R3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);C:\Windows\System32\Drivers\WPRO_41_2001.sys [2012-12-25 34752]<br />
S0 Avgboota;AVG Early Launch Anti-Malware Driver;C:\Windows\System32\Drivers\avgboota.sys [2012-10-26 20912]<br />
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-2-28 161384]<br />
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;C:\Windows\System32\Drivers\AmpPal.sys [2012-7-17 162344]<br />
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]<br />
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\Drivers\intelaud.sys [2012-8-9 35296]<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2012-7-18 272176]<br />
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\Drivers\netr28x.sys [2012-6-2 1737760]<br />
S3 SmbDrv;SmbDrv;C:\Windows\System32\Drivers\Smb_driver_AMDASF.sys [2012-12-25 41272]<br />
S3 usb3Hub;USB-IF USB 3.0 Hub;C:\Windows\System32\Drivers\usb3Hub.sys [2012-8-9 48096]<br />
S3 XHCIPort;USB-IF xHCI USB Host Controller;C:\Windows\System32\Drivers\xHCIPort.sys [2012-8-9 188384]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-21 04:47:56	198320	----a-w-	C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10204.bin<br />
2013-05-20 15:49:36	--------	d-----w-	C:\Users\gary\AppData\Roaming\IDT<br />
2013-05-19 08:07:10	178800	----a-w-	C:\Windows\SysWow64\CmdLineExt_x64.dll<br />
2013-05-19 08:04:02	68104	----a-w-	C:\Windows\System32\XAPOFX1_0.dll<br />
2013-05-19 08:04:02	65032	----a-w-	C:\Windows\SysWow64\XAPOFX1_0.dll<br />
2013-05-19 08:04:02	511496	----a-w-	C:\Windows\System32\XAudio2_1.dll<br />
2013-05-19 08:04:02	507400	----a-w-	C:\Windows\SysWow64\XAudio2_1.dll<br />
2013-05-19 08:04:02	28168	----a-w-	C:\Windows\System32\X3DAudio1_4.dll<br />
2013-05-19 08:04:02	25608	----a-w-	C:\Windows\SysWow64\X3DAudio1_4.dll<br />
2013-05-19 08:04:02	238088	----a-w-	C:\Windows\SysWow64\xactengine3_1.dll<br />
2013-05-19 08:04:02	177672	----a-w-	C:\Windows\System32\xactengine3_1.dll<br />
2013-05-19 08:04:01	540688	----a-w-	C:\Windows\System32\d3dx10_38.dll<br />
2013-05-19 08:04:01	467984	----a-w-	C:\Windows\SysWow64\d3dx10_38.dll<br />
2013-05-19 08:04:01	1941528	----a-w-	C:\Windows\System32\D3DCompiler_38.dll<br />
2013-05-19 08:04:01	1491992	----a-w-	C:\Windows\SysWow64\D3DCompiler_38.dll<br />
2013-05-19 08:02:54	462864	----a-w-	C:\Windows\SysWow64\d3dx10_37.dll<br />
2013-05-19 08:02:54	1420824	----a-w-	C:\Windows\SysWow64\D3DCompiler_37.dll<br />
2013-05-19 08:02:52	3786760	----a-w-	C:\Windows\SysWow64\D3DX9_37.dll<br />
2013-05-19 08:02:50	81768	----a-w-	C:\Windows\SysWow64\xinput1_3.dll<br />
2013-05-19 08:02:37	--------	d-----w-	C:\Windows\SysWow64\xlive<br />
2013-05-19 08:02:37	--------	d-----w-	C:\Program Files (x86)\Microsoft Games for Windows - LIVE<br />
2013-05-19 07:44:53	--------	d-----w-	C:\Users\gary\AppData\Local\Rockstar Games<br />
2013-05-19 07:31:53	78200	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2013-05-19 07:31:52	693112	----a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe<br />
2013-05-19 07:31:24	94656	----a-w-	C:\Windows\System32\WPRO_41_2001woem.tmp<br />
2013-05-19 07:26:44	--------	d-----w-	C:\Users\gary\AppData\Roaming\PowerISO<br />
2013-05-18 15:34:43	--------	d-----w-	C:\Users\gary\AppData\Local\CyberLink<br />
2013-05-18 11:02:07	13648384	----a-w-	C:\Windows\System32\Windows.UI.Xaml.dll<br />
2013-05-18 11:02:05	3552768	----a-w-	C:\Windows\System32\tquery.dll<br />
2013-05-18 11:02:02	2107904	----a-w-	C:\Windows\System32\mssrch.dll<br />
2013-05-18 11:02:02	10789888	----a-w-	C:\Windows\SysWow64\Windows.UI.Xaml.dll<br />
2013-05-18 11:02:01	2767360	----a-w-	C:\Windows\SysWow64\tquery.dll<br />
2013-05-18 11:02:01	1593344	----a-w-	C:\Windows\SysWow64\mssrch.dll<br />
2013-05-18 11:02:00	1829408	----a-w-	C:\Windows\System32\ntdll.dll<br />
2013-05-18 11:02:00	1444864	----a-w-	C:\Windows\System32\MSAudDecMFT.dll<br />
2013-05-18 06:39:57	262552	----a-w-	C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll<br />
2013-05-15 16:44:35	1455368	----a-w-	C:\Windows\System32\drivers\dxgkrnl.sys<br />
2013-05-15 11:28:16	70144	----a-w-	C:\Windows\System32\appinfo.dll<br />
2013-05-15 11:28:16	112872	----a-w-	C:\Windows\System32\consent.exe<br />
2013-05-15 08:22:30	861184	----a-w-	C:\Windows\System32\drivers\http.sys<br />
2013-05-15 07:08:55	2382336	----a-w-	C:\Windows\SysWow64\esent.dll<br />
2013-05-15 07:08:54	2851840	----a-w-	C:\Windows\System32\esent.dll<br />
2013-05-15 06:06:06	6987528	----a-w-	C:\Windows\System32\ntoskrnl.exe<br />
2013-05-13 03:45:05	--------	d-----r-	C:\Program Files (x86)\Skype<br />
2013-05-12 14:42:23	--------	d-----w-	C:\Users\gary\AppData\Local\FullTiltPoker<br />
2013-05-08 03:10:42	11459584	----a-w-	C:\Windows\System32\glcndFilter.dll<br />
2013-05-08 03:09:50	109568	----a-w-	C:\Windows\System32\dskquota.dll<br />
2013-05-08 03:09:48	82944	----a-w-	C:\Windows\SysWow64\dskquota.dll<br />
2013-05-08 03:09:30	929792	----a-w-	C:\Windows\SysWow64\mfnetsrc.dll<br />
2013-05-08 03:09:30	1172992	----a-w-	C:\Windows\System32\mfnetsrc.dll<br />
2013-05-08 03:09:29	677888	----a-w-	C:\Windows\System32\mfnetcore.dll<br />
2013-05-08 03:09:29	673280	----a-w-	C:\Windows\System32\mfmpeg2srcsnk.dll<br />
2013-05-08 03:09:29	568832	----a-w-	C:\Windows\SysWow64\mfnetcore.dll<br />
2013-05-08 03:09:29	513024	----a-w-	C:\Windows\SysWow64\mfmpeg2srcsnk.dll<br />
2013-05-08 03:07:58	368640	----a-w-	C:\Windows\System32\sppwinob.dll<br />
2013-05-08 03:07:27	2367528	----a-w-	C:\Windows\System32\WSService.dll<br />
2013-05-08 03:07:17	3265256	----a-w-	C:\Windows\System32\drivers\evbda.sys<br />
2013-05-08 03:07:06	2397184	----a-w-	C:\Windows\System32\WpcMon.exe<br />
2013-05-08 03:07:04	3847168	----a-w-	C:\Windows\System32\d2d1.dll<br />
2013-05-08 03:07:02	3964416	----a-w-	C:\Windows\System32\WinSAT.exe<br />
2013-05-08 03:05:59	92160	----a-w-	C:\Windows\System32\lpremove.exe<br />
2013-05-04 06:30:14	--------	d-----w-	C:\Users\gary\AppData\Roaming\WildTangent<br />
2013-05-02 18:01:36	--------	d-----w-	C:\Users\gary\AppData\Local\CrashDumps<br />
2013-05-02 03:12:27	--------	d-----r-	C:\Windows\BrowserChoice<br />
2013-05-01 16:21:27	16114176	----a-w-	C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll<br />
2013-05-01 16:21:26	15541248	----a-w-	C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll<br />
2013-05-01 15:41:53	17888	----a-w-	C:\Windows\System32\msvcr100_clr0400.dll<br />
2013-05-01 15:41:50	17888	----a-w-	C:\Windows\SysWow64\msvcr100_clr0400.dll<br />
2013-05-01 15:41:01	1161728	----a-w-	C:\Windows\System32\sppobjs.dll<br />
2013-05-01 15:33:37	94208	----a-w-	C:\Windows\System32\synceng.dll<br />
2013-05-01 15:33:37	72192	----a-w-	C:\Windows\SysWow64\synceng.dll<br />
2013-05-01 15:31:22	2893824	----a-w-	C:\Windows\System32\msmpeg2vdec.dll<br />
2013-05-01 15:31:22	2400256	----a-w-	C:\Windows\SysWow64\msmpeg2vdec.dll<br />
2013-05-01 15:31:01	26624	----a-w-	C:\Windows\System32\ReAgentc.exe<br />
2013-05-01 15:31:01	24064	----a-w-	C:\Windows\SysWow64\ReAgentc.exe<br />
2013-05-01 15:29:58	9216	----a-w-	C:\Windows\System32\dpnhupnp.dll<br />
2013-05-01 08:19:48	--------	d-----w-	C:\Users\gary\AppData\Roaming\Malwarebytes<br />
2013-05-01 08:19:45	25928	----a-w-	C:\Windows\System32\drivers\mbam.sys<br />
2013-05-01 08:19:45	--------	d-----w-	C:\ProgramData\Malwarebytes<br />
2013-05-01 08:19:45	--------	d-----w-	C:\Program Files (x86)\Malwarebytes' Anti-Malware<br />
2013-05-01 08:19:10	--------	d-----w-	C:\Users\gary\AppData\Local\Programs<br />
2013-05-01 08:13:22	--------	d-----w-	C:\Users\gary\AppData\Local\PokerStars<br />
2013-05-01 08:13:13	--------	d-----w-	C:\Program Files (x86)\PokerStars<br />
2013-05-01 07:00:10	50784	----a-w-	C:\ProgramData\Microsoft\windowsfiltering\Sqm\Manifest\Sqm3.bin<br />
2013-05-01 07:00:04	17536	----a-w-	C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin<br />
2013-05-01 05:56:06	--------	d-----w-	C:\Program Files (x86)\FreeStopwatch<br />
2013-04-30 20:03:38	--------	d-----w-	C:\Program Files (x86)\VideoLAN<br />
2013-04-30 18:08:21	--------	d-----w-	C:\Users\gary\AppData\Local\HP<br />
2013-04-30 16:57:01	--------	d-----w-	C:\ProgramData\Licenses<br />
2013-04-30 16:56:58	129872	----a-w-	C:\Windows\SysWow64\MSSTDFMT.DLL<br />
2013-04-30 16:56:58	1070352	----a-w-	C:\Windows\SysWow64\MSCOMCTL.OCX<br />
2013-04-30 16:56:58	--------	d-----w-	C:\Program Files (x86)\SpywareBlaster<br />
2013-04-30 16:32:20	--------	d-----w-	C:\ProgramData\Spybot - Search &amp; Destroy<br />
2013-04-30 16:32:20	--------	d-----w-	C:\Program Files (x86)\Spybot - Search &amp; Destroy<br />
2013-04-30 16:25:00	--------	d-----w-	C:\Users\gary\AppData\Roaming\uTorrent<br />
2013-04-30 16:18:39	--------	d-----w-	C:\Users\gary\AppData\Roaming\AVG2013<br />
2013-04-30 16:17:51	--------	d--h--w-	C:\$AVG<br />
2013-04-30 16:17:51	--------	d-----w-	C:\ProgramData\AVG2013<br />
2013-04-30 16:07:22	--------	d-----w-	C:\Users\gary\AppData\Roaming\TuneUp Software<br />
2013-04-30 16:06:40	--------	d-----w-	C:\Program Files (x86)\AVG<br />
2013-04-30 16:03:37	--------	d-----w-	C:\Users\gary\AppData\Roaming\hpqlog<br />
2013-04-30 16:02:16	--------	d--h--w-	C:\ProgramData\Common Files<br />
2013-04-30 16:02:16	--------	d-----w-	C:\Users\gary\AppData\Local\MFAData<br />
2013-04-30 16:02:16	--------	d-----w-	C:\Users\gary\AppData\Local\Avg2013<br />
2013-04-30 16:02:16	--------	d-----w-	C:\ProgramData\MFAData<br />
2013-04-30 15:50:16	--------	d-----w-	C:\Users\gary\AppData\Roaming\ViStart<br />
2013-04-30 15:50:08	--------	d-----w-	C:\Program Files (x86)\Common Files\Symantec Shared<br />
2013-04-30 15:45:26	--------	d-----w-	C:\Users\gary\AppData\Local\Macromedia<br />
2013-04-30 15:41:06	--------	d-----w-	C:\Users\gary\AppData\Local\Mozilla<br />
2013-04-30 15:40:53	--------	d-----w-	C:\Program Files (x86)\Mozilla Maintenance Service<br />
2013-04-30 15:35:28	--------	d-----w-	C:\ProgramData\TrueSuite<br />
2013-04-30 15:28:34	--------	d-----w-	C:\Users\gary\AppData\Local\Hewlett-Packard<br />
2013-04-30 15:28:34	--------	d-----w-	C:\Users\gary\AppData\Local\ATI<br />
2013-04-30 15:28:00	--------	d-----r-	C:\Users\gary\Searches<br />
2013-04-30 15:28:00	--------	d-----r-	C:\Users\gary\Contacts<br />
2013-04-30 15:26:38	--------	d-----w-	C:\Users\gary\AppData\Local\Power2Go8<br />
2013-04-30 15:26:25	--------	d-----w-	C:\Users\gary\AppData\Roaming\Synaptics<br />
2013-04-30 15:26:24	--------	d-----w-	C:\Users\gary\AppData\Local\AuthenTec<br />
2013-04-30 15:25:17	--------	d-----w-	C:\Users\gary\AppData\Local\VirtualStore<br />
2013-04-30 15:25:03	--------	d-----w-	C:\Users\gary\AppData\Local\Packages<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-19 07:31:24	34752	----a-w-	C:\Windows\System32\drivers\WPRO_41_2001.sys<br />
2013-04-13 05:56:35	444416	----a-w-	C:\Windows\apppatch\AcSpecfc.dll<br />
2013-04-09 23:17:44	2242048	----a-w-	C:\Windows\System32\wininet.dll<br />
2013-04-09 23:17:36	915968	----a-w-	C:\Windows\System32\uxtheme.dll<br />
2013-04-09 23:16:58	3958784	----a-w-	C:\Windows\System32\jscript9.dll<br />
2013-04-09 22:30:26	1767424	----a-w-	C:\Windows\SysWow64\wininet.dll<br />
2013-04-09 22:29:44	2877440	----a-w-	C:\Windows\SysWow64\jscript9.dll<br />
2013-04-09 05:33:02	489576	----a-w-	C:\Windows\System32\AudioEng.dll<br />
2013-04-09 05:33:02	446792	----a-w-	C:\Windows\System32\AudioSes.dll<br />
2013-04-09 05:33:02	253544	----a-w-	C:\Windows\System32\audiodg.exe<br />
2013-04-09 05:27:43	284424	----a-w-	C:\Windows\System32\drivers\spaceport.sys<br />
2013-04-09 05:20:02	86280	----a-w-	C:\Windows\System32\kdnet.dll<br />
2013-04-09 05:20:02	306952	----a-w-	C:\Windows\System32\kd_02_10ec.dll<br />
2013-04-09 05:18:05	77960	----a-w-	C:\Windows\System32\kdvm.dll<br />
2013-04-09 04:52:07	816128	----a-w-	C:\Windows\System32\SearchIndexer.exe<br />
2013-04-09 04:52:07	373760	----a-w-	C:\Windows\System32\SearchProtocolHost.exe<br />
2013-04-09 04:52:07	197120	----a-w-	C:\Windows\System32\SearchFilterHost.exe<br />
2013-04-09 04:52:07	126464	----a-w-	C:\Windows\System32\Robocopy.exe<br />
2013-04-09 04:52:06	804352	----a-w-	C:\Windows\System32\RecoveryDrive.exe<br />
2013-04-09 04:51:51	367616	----a-w-	C:\Windows\System32\conhost.exe<br />
2013-04-09 04:51:45	523264	----a-w-	C:\Windows\System32\XpsGdiConverter.dll<br />
2013-04-09 04:51:41	99840	----a-w-	C:\Windows\System32\wscsvc.dll<br />
2013-04-09 04:51:41	456704	----a-w-	C:\Windows\System32\wpncore.dll<br />
2013-04-09 04:51:17	595456	----a-w-	C:\Windows\System32\Windows.Networking.dll<br />
2013-04-09 04:51:17	391168	----a-w-	C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll<br />
2013-04-09 04:51:05	10116096	----a-w-	C:\Windows\System32\twinui.dll<br />
2013-04-09 04:50:53	414720	----a-w-	C:\Windows\System32\GenuineCenter.dll<br />
2013-04-09 04:50:39	422400	----a-w-	C:\Windows\System32\schannel.dll<br />
2013-04-09 04:50:39	1285632	----a-w-	C:\Windows\System32\schedsvc.dll<br />
2013-04-09 04:50:03	96256	----a-w-	C:\Windows\System32\mssprxy.dll<br />
2013-04-09 04:50:03	745984	----a-w-	C:\Windows\System32\mssvp.dll<br />
2013-04-09 04:50:02	65024	----a-w-	C:\Windows\System32\msscntrs.dll<br />
2013-04-09 04:50:02	435200	----a-w-	C:\Windows\System32\mssph.dll<br />
2013-04-09 04:50:02	13824	----a-w-	C:\Windows\System32\msshooks.dll<br />
2013-04-09 04:49:45	468992	----a-w-	C:\Windows\System32\MFMediaEngine.dll<br />
2013-04-09 04:49:45	281088	----a-w-	C:\Windows\System32\mfreadwrite.dll<br />
2013-04-09 04:49:36	817152	----a-w-	C:\Windows\System32\kerberos.dll<br />
2013-04-09 04:49:33	210432	----a-w-	C:\Windows\System32\iuilp.dll<br />
2013-04-09 04:49:16	50176	----a-w-	C:\Windows\System32\fmifs.dll<br />
2013-04-09 04:49:16	231936	----a-w-	C:\Windows\System32\fhengine.dll<br />
2013-04-09 04:49:09	172544	----a-w-	C:\Windows\System32\dwmredir.dll<br />
2013-04-09 04:49:06	196096	----a-w-	C:\Windows\System32\dmvdsitf.dll<br />
2013-04-09 04:48:43	2303488	----a-w-	C:\Windows\System32\authui.dll<br />
2013-04-09 04:48:42	785408	----a-w-	C:\Windows\System32\audiosrv.dll<br />
2013-04-09 04:48:42	169472	----a-w-	C:\Windows\System32\AudioEndpointBuilder.dll<br />
2013-04-09 04:48:34	419840	----a-w-	C:\Windows\System32\intl.cpl<br />
2013-04-09 02:35:13	4038144	----a-w-	C:\Windows\System32\win32k.sys<br />
2013-04-09 02:34:49	83968	----a-w-	C:\Windows\System32\drivers\hidclass.sys<br />
2013-04-09 02:34:42	27648	----a-w-	C:\Windows\System32\drivers\hidusb.sys<br />
2013-04-09 02:34:30	95744	----a-w-	C:\Windows\System32\drivers\hidbth.sys<br />
2013-04-09 02:33:41	60416	----a-w-	C:\Windows\System32\drivers\ndproxy.sys<br />
2013-04-09 02:33:05	623104	----a-w-	C:\Windows\System32\drivers\srv2.sys<br />
2013-04-09 02:32:02	805376	----a-w-	C:\Windows\System32\drivers\PEAuth.sys<br />
2013-04-09 02:31:14	247808	----a-w-	C:\Windows\System32\drivers\srvnet.sys<br />
2013-04-09 02:31:01	83456	----a-w-	C:\Windows\System32\drivers\wanarp.sys<br />
2013-04-08 23:44:25	123880	----a-w-	C:\Windows\SysWow64\wscapi.dll<br />
2013-04-08 23:39:14	1408896	----a-w-	C:\Windows\SysWow64\ntdll.dll<br />
2013-04-08 23:37:29	426024	----a-w-	C:\Windows\SysWow64\AudioEng.dll<br />
2013-04-08 23:37:29	324368	----a-w-	C:\Windows\SysWow64\AudioSes.dll<br />
2013-04-08 21:52:16	670208	----a-w-	C:\Windows\SysWow64\SearchIndexer.exe<br />
2013-04-08 21:52:16	302592	----a-w-	C:\Windows\SysWow64\SearchProtocolHost.exe<br />
2013-04-08 21:52:16	171008	----a-w-	C:\Windows\SysWow64\SearchFilterHost.exe<br />
2013-04-08 21:52:16	106496	----a-w-	C:\Windows\SysWow64\Robocopy.exe<br />
2013-04-08 21:52:06	364544	----a-w-	C:\Windows\SysWow64\XpsGdiConverter.dll<br />
2013-04-04 23:30:17	503080	----a-w-	C:\Windows\System32\ci.dll<br />
2013-03-30 18:16:05	1403784	----a-w-	C:\Windows\System32\winload.efi<br />
2013-03-30 18:16:05	1267424	----a-w-	C:\Windows\System32\winload.exe<br />
2013-03-28 22:09:09	1093880	----a-w-	C:\Windows\System32\winresume.exe<br />
2013-03-28 22:09:04	1217328	----a-w-	C:\Windows\System32\winresume.efi<br />
2013-03-15 22:05:34	298456	----a-w-	C:\Windows\System32\rsaenh.dll<br />
2013-03-15 22:05:16	252928	----a-w-	C:\Windows\SysWow64\rsaenh.dll<br />
2013-03-02 10:57:48	337128	----a-w-	C:\Windows\System32\drivers\USBXHCI.SYS<br />
2013-03-02 10:57:46	77544	----a-w-	C:\Windows\System32\drivers\storahci.sys<br />
2013-03-02 10:57:46	332520	----a-w-	C:\Windows\System32\drivers\storport.sys<br />
2013-03-02 10:45:20	148712	----a-w-	C:\Windows\System32\drivers\tpm.sys<br />
2013-03-02 10:45:19	194792	----a-w-	C:\Windows\System32\drivers\sdbus.sys<br />
2013-03-02 10:45:10	125160	----a-w-	C:\Windows\System32\drivers\dumpsd.sys<br />
2013-03-02 10:39:39	495336	----a-w-	C:\Windows\System32\drivers\vhdmp.sys<br />
2013-03-02 10:39:38	69864	----a-w-	C:\Windows\System32\drivers\pdc.sys<br />
2013-03-02 10:39:32	327912	----a-w-	C:\Windows\System32\drivers\Classpnp.sys<br />
2013-03-02 09:59:37	2231528	----a-w-	C:\Windows\System32\drivers\tcpip.sys<br />
2013-03-02 09:59:36	411880	----a-w-	C:\Windows\System32\drivers\FWPKCLNT.SYS<br />
2013-03-02 08:24:08	34304	----a-w-	C:\Windows\SysWow64\wuapp.exe<br />
2013-03-02 08:23:43	83968	----a-w-	C:\Windows\SysWow64\wudriver.dll<br />
2013-03-02 08:23:43	125952	----a-w-	C:\Windows\SysWow64\wuwebv.dll<br />
2013-03-02 08:23:30	893952	----a-w-	C:\Windows\SysWow64\winmde.dll<br />
2013-03-02 08:23:30	1338880	----a-w-	C:\Windows\SysWow64\WindowsCodecs.dll<br />
2013-03-02 08:23:28	601088	----a-w-	C:\Windows\SysWow64\Windows.Globalization.dll<br />
2013-03-02 08:23:28	504320	----a-w-	C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll<br />
2013-03-02 08:23:19	246784	----a-w-	C:\Windows\SysWow64\ubpm.dll<br />
2013-03-02 08:23:04	356352	----a-w-	C:\Windows\SysWow64\SettingSync.dll<br />
2013-03-02 08:23:04	100864	----a-w-	C:\Windows\SysWow64\SettingSyncInfo.dll<br />
2013-03-02 08:23:00	375808	----a-w-	C:\Windows\SysWow64\ReAgent.dll<br />
2013-03-02 08:22:36	357888	----a-w-	C:\Windows\SysWow64\netcfgx.dll<br />
2013-03-02 08:22:32	5091840	----a-w-	C:\Windows\SysWow64\mstscax.dll<br />
2013-03-02 08:22:17	850944	----a-w-	C:\Windows\SysWow64\mfasfsrcsnk.dll<br />
2013-03-02 08:21:56	550912	----a-w-	C:\Windows\SysWow64\drvstore.dll<br />
2013-03-02 08:21:52	36352	----a-w-	C:\Windows\SysWow64\DevDispItemProvider.dll<br />
2013-03-02 08:21:40	309760	----a-w-	C:\Windows\SysWow64\BCP47Langs.dll<br />
2013-03-02 08:21:32	145408	----a-w-	C:\Windows\SysWow64\powercfg.cpl<br />
.<br />
============= FINISH:  7:59:01.44 ===============<br />
<br />
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software<br />
Run date: 2013-05-21 08:03:17<br />
-----------------------------<br />
08:03:17.950    OS Version: Windows x64 6.2.9200 <br />
08:03:17.950    Number of processors: 4 586 0x3A09<br />
08:03:17.950    ComputerName: REDMEN  UserName: gary<br />
08:03:18.050    Initialze error 1 <br />
08:04:36.868    AVAST engine defs: 13052001<br />
08:05:58.751    Disk 0 (boot) \Device\Harddisk0\DR0 -&gt; \Device\00000034<br />
08:05:58.761    Disk 0 Vendor: Hitachi_HTS541010A9E680 JA0OA4D0 Size: 953869MB BusType: 8<br />
08:05:58.771    Disk 0 MBR read successfully<br />
08:05:58.771    Disk 0 MBR scan<br />
08:05:58.791    Disk 0 unknown MBR code<br />
08:05:58.801    Disk 0 Partition 1 00     EE          GPT            953869 MB offset 1<br />
08:05:58.801    Disk 0 scanning C:\Windows\system32\drivers<br />
08:05:58.801    Service scanning<br />
08:05:59.401    Modules scanning<br />
08:05:59.401    Disk 0 trace - called modules:<br />
08:05:59.411    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys storport.sys hal.dll iaStorA.sys <br />
08:05:59.421    1 nt!IofCallDriver -&gt; \Device\Harddisk0\DR0[0xfffffa8008b37740]<br />
08:05:59.421    3 CLASSPNP.SYS[fffff8800213cfea] -&gt; nt!IofCallDriver -&gt; [0xfffffa8008b38630]<br />
08:05:59.431    5 hpdskflt.sys[fffff88001fa2339] -&gt; nt!IofCallDriver -&gt; \Device\00000034[0xfffffa8008b297f0]<br />
08:05:59.441    AVAST engine scan C:\Windows<br />
08:05:59.441    AVAST engine scan C:\Windows\system32<br />
08:05:59.451    AVAST engine scan C:\Windows\system32\drivers<br />
08:05:59.461    AVAST engine scan C:\Users\gary<br />
08:05:59.471    AVAST engine scan C:\ProgramData<br />
08:05:59.471    Scan finished successfully<br />
08:06:14.561    Disk 0 MBR has been saved successfully to &quot;C:\Users\gary\Desktop\MBR.dat&quot;<br />
08:06:14.571    The log file has been saved successfully to &quot;C:\Users\gary\Desktop\aswMBR.txt&quot;</div>


	<div style="padding:10px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<ul>
			<li>
	<img class="inlineimg" src="http://forums.spybot.info/images/attach/zip.gif" alt="File Type: zip" />
	<a href="http://forums.spybot.info/attachment.php?attachmentid=10687&amp;d=1369122364">attach.zip</a> 
(3.0 KB)
</li>
			</ul>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.spybot.info/forumdisplay.php?22-Malware-Removal">Malware Removal</category>
			<dc:creator>gpkenny</dc:creator>
			<guid isPermaLink="true">http://forums.spybot.info/showthread.php?68595-Help-with-sound-problem</guid>
		</item>
	</channel>
</rss>
