This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unable to access certain websites [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Recently I got the "Blekko search" virus through a download at "Cnet" and you folks helped me find and remove it. During that time we went through many searches/fixes that didn't work…until I found the file that needed removed by accident. At that time the person I was working with suggested I do something to secure the "hosts" file (change it to MVPS?) and since that time I'm unable to access a certain group of sites. It as though a certain function shared by all is being blocked on all my browsers. It's not my router because I can access these site from my other computer so the block is only on the formerly infected computer. How do I remove this block??? Thanks, John
:welcome:

OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thanks for your help!!! Here are the files you asked for:


OTL logfile created on: 6/7/2012 5:26:05 AM - Run 1
OTL by OldTimer - Version 3.2.46.2 Folder = C:\Users\John-Sandi 1\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 5.72 Gb Available Physical Memory | 71.49% Memory free
15.99 Gb Paging File | 13.25 Gb Available in Paging File | 82.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 857.05 Gb Free Space | 92.01% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 931.01 Gb Free Space | 99.95% Space Free | Partition Type: NTFS

Computer Name: JOHN-SANDI1-PC | User Name: John-Sandi 1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\John-Sandi 1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\John-Sandi 1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
PRC - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\TurboV EVO\TurboVHelp.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe ()
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe (
ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\EPU\EPU.exe (
ASUSTeK Computer Inc.)
PRC - C:\Windows\DAODx.exe ()
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtscript4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtgui4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtnetwork4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtsql4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtdeclarative4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtcore4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\flashobj.dll ()
MOD - C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\HookKey32.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\AsSpindownTimeout.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\AsusService.dll ()
MOD - C:\Windows\DAODx.exe ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\gs_encryption.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GSLogging.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (Mcx2Svc) – C:\Windows\SysNative\Mcx2Svc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (RemoteAccess) – C:\Windows\SysNative\mprdim.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (KSS) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (ThreatFire) – C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (AsSysCtrlService) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RemoteAccess) – C:\Windows\SysWOW64\mprdim.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (TfSysMon) – C:\Windows\SysNative\drivers\TfSysMon.sys (PC Tools)
DRV:64bit: - (TfNetMon) – C:\Windows\SysNative\drivers\TfNetMon.sys (PC Tools)
DRV:64bit: - (TfFsMon) – C:\Windows\SysNative\drivers\TfFsMon.sys (PC Tools)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (udfs) – C:\Windows\SysNative\drivers\udfs.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (crcdisk) – C:\Windows\SysNative\drivers\crcdisk.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (cdfs) – C:\Windows\SysNative\drivers\cdfs.sys (Microsoft Corporation)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (MREMP50) – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (Cardex) – C:\Windows\SysWOW64\drivers\TBPanelx64.sys (Windows ® Server 2003 DDK provider)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify…=us&.src=ym
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 62 06 0A 79 36 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{E66F2FCE-5E45-48E2-ABE4-DA04163E15B9}: "URL" = http://search.avg.com/route/?d=4e3da8b4&am;…y=&ychte=us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://login.yahoo.com/config/login_verify2?.src=ym&.done=http%3A%2F%2Fca.mc886.mail.yahoo.com%2Fmc%2Fwelcome%3Fswitch%3D1"
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.50
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.7
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/06/04 08:01:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/06/04 07:59:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]

[2011/03/05 11:34:24 | 000,000,000 | —D | M] (No name found) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Extensions
[2012/06/05 20:09:59 | 000,000,000 | —D | M] (No name found) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions
[2012/04/21 06:33:22 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/06/07 04:55:01 | 000,005,472 | —- | M] () – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\searchplugins\startpage-https.xml
[2012/05/20 14:19:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/04 07:59:53 | 000,000,000 | —D | M] (AVG Do Not Track) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/06/04 08:01:24 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4
[2011/07/27 12:41:28 | 000,079,135 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{1A2D0EC4-75F5-4C91-89C4-3656F6E44B68}.XPI
[2011/09/09 07:22:40 | 000,164,858 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.XPI
[2012/03/08 17:01:32 | 000,081,156 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{6D96BB5E-1175-4EBF-8AB5-5F56F1C79F65}.XPI
[2012/06/05 20:09:59 | 000,525,079 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012/01/05 09:28:20 | 000,634,964 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/01/22 06:30:28 | 000,138,614 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
[2012/04/20 21:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/20 21:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 21:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Google Update (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll

O1 HOSTS File: ([2012/06/03 07:03:13 | 001,038,049 | R— | M]) - C:\Windows\SysNative\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #[IPv6]
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 31164 more lines…
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [itype] c:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKLM..\Run: [Info Center] C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [Six Engine] C:\Program Files (x86)\ASUS\EPU\EPU.exe (
ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [TurboV EVO] C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKCU..\Run: [KSS] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
O4 - HKCU..\Run: [SkyDrive] C:\Users\John-Sandi 1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStartupSound = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableThumbnailsOnNetworkFolders = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32B7E865-2EF3-446B-BC3C-9143C51800FE}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/07 05:16:18 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\John-Sandi 1\Desktop\OTL.exe
[2012/06/06 06:36:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Belarc
[2012/06/04 09:24:39 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/06/04 09:23:40 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\Google
[2012/06/04 08:10:13 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
[2012/06/04 08:09:41 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2012/06/04 08:09:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2012/06/04 08:01:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/06/04 07:59:42 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/05/29 12:05:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
[2012/05/22 18:36:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012/05/22 18:34:10 | 001,451,840 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420103.dll
[2012/05/22 18:34:10 | 000,188,736 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2012/05/22 18:34:10 | 000,031,040 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2012/05/22 18:34:09 | 008,105,280 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/05/22 18:34:08 | 025,743,168 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/05/22 18:34:08 | 019,607,872 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/05/22 18:34:06 | 025,248,064 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/05/22 18:34:06 | 018,044,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/05/22 18:34:06 | 017,551,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/05/22 18:34:06 | 015,322,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/05/22 18:34:06 | 008,139,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/05/22 18:34:06 | 005,982,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/05/22 18:34:06 | 002,881,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/05/22 18:34:06 | 002,681,664 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/05/22 18:34:06 | 002,524,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/05/22 18:34:06 | 002,445,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/05/22 18:34:06 | 002,368,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/05/22 18:34:06 | 001,738,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/05/22 18:34:06 | 001,468,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/05/21 18:27:24 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\Apps
[2012/05/20 13:33:20 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Malwarebytes
[2012/05/20 13:33:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/05/19 06:07:16 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/05/19 06:01:14 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/05/19 05:44:09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/05/17 07:07:09 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\adawarebp
[2012/05/17 07:07:06 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012/05/17 07:05:18 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Ad-Aware Antivirus
[2012/05/15 07:23:51 | 004,894,432 | —- | C] (Microsoft Corporation) – C:\Users\John-Sandi 1\Desktop\SkyDriveSetup.exe
[2012/05/10 07:26:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/10 07:25:18 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/05/10 07:25:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012/05/10 07:09:16 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/10 07:09:13 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/10 07:09:13 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/05/10 07:08:54 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll

========== Files - Modified Within 30 Days ==========

[2012/06/07 05:28:00 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000UA.job
[2012/06/07 05:16:21 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\John-Sandi 1\Desktop\OTL.exe
[2012/06/07 04:59:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/07 02:50:00 | 000,000,524 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/06/06 18:05:29 | 099,869,056 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/06 09:28:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000Core.job
[2012/06/06 06:36:47 | 000,002,092 | —- | M] () – C:\Users\John-Sandi 1\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,068 | —- | M] () – C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/06/06 03:00:00 | 000,000,524 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job
[2012/06/04 18:04:47 | 000,285,119 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/04 09:53:55 | 000,858,125 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\census.cache
[2012/06/04 09:53:47 | 000,118,095 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\ars.cache
[2012/06/04 09:46:20 | 000,000,036 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\housecall.guid.cache
[2012/06/04 09:24:40 | 000,002,357 | —- | M] () – C:\Users\John-Sandi 1\Desktop\Google Chrome.lnk
[2012/06/04 09:04:34 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/04 09:04:34 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/04 08:11:20 | 000,015,184 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/04 08:11:20 | 000,015,184 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/04 08:09:27 | 000,783,418 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/04 08:09:27 | 000,663,222 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/04 08:09:27 | 000,122,090 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/04 08:03:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/04 08:03:58 | 2146,050,047 | -HS- | M] () – C:\hiberfil.sys
[2012/06/04 08:01:24 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/04 07:51:11 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/03 07:03:13 | 001,038,049 | R— | M] () – C:\Windows\SysNative\drivers\etc\HOSTS
[2012/06/01 04:15:10 | 000,000,466 | —- | M] () – C:\Windows\tasks\GBM - Easy Layout Backup Job-Full.job
[2012/05/22 07:14:40 | 001,038,088 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20120603-070313.backup
[2012/05/21 05:52:41 | 000,601,715 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.20120522-071440.backup
[2012/05/20 14:20:00 | 000,001,134 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/20 12:44:32 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.old
[2012/05/18 20:37:24 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/05/18 20:37:24 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/05/15 06:48:00 | 025,743,168 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/05/15 06:48:00 | 025,248,064 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/05/15 06:48:00 | 019,607,872 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/05/15 06:48:00 | 018,044,224 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/05/15 06:48:00 | 017,551,680 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/05/15 06:48:00 | 015,322,432 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/05/15 06:48:00 | 010,194,752 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2012/05/15 06:48:00 | 008,139,072 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/05/15 06:48:00 | 008,105,280 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/05/15 06:48:00 | 005,982,528 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/05/15 06:48:00 | 002,881,856 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/05/15 06:48:00 | 002,741,568 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2012/05/15 06:48:00 | 002,681,664 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/05/15 06:48:00 | 002,524,992 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/05/15 06:48:00 | 002,445,120 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/05/15 06:48:00 | 002,368,832 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/05/15 06:48:00 | 001,738,048 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/05/15 06:48:00 | 001,468,224 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/05/15 06:48:00 | 000,068,928 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2012/05/15 06:48:00 | 000,061,248 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2012/05/15 06:48:00 | 000,014,324 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[2012/05/15 05:29:46 | 000,118,080 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2012/05/15 05:29:46 | 000,063,296 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2012/05/15 05:29:25 | 003,149,632 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2012/05/15 05:28:42 | 006,151,488 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2012/05/15 02:21:50 | 000,423,744 | —- | M] () – C:\Windows\SysWow64\nvStreaming.exe
[2012/05/10 07:19:55 | 000,895,848 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/06/06 06:36:47 | 000,002,092 | —- | C] () – C:\Users\John-Sandi 1\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,080 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,068 | —- | C] () – C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/06/04 09:53:55 | 000,858,125 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\census.cache
[2012/06/04 09:53:47 | 000,118,095 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\ars.cache
[2012/06/04 09:46:20 | 000,000,036 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\housecall.guid.cache
[2012/06/04 09:24:40 | 000,002,357 | —- | C] () – C:\Users\John-Sandi 1\Desktop\Google Chrome.lnk
[2012/06/04 09:23:44 | 000,000,936 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000UA.job
[2012/06/04 09:23:43 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000Core.job
[2012/06/04 08:01:24 | 000,000,965 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/20 14:20:00 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/05/20 14:20:00 | 000,001,134 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/15 02:21:50 | 000,423,744 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2012/05/08 16:48:21 | 000,000,524 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/05/08 16:48:20 | 000,000,524 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job
[2012/02/11 20:25:04 | 000,000,000 | —- | C] () – C:\Windows\iplayer.INI
[2011/12/05 13:14:06 | 000,777,142 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/25 08:35:44 | 000,002,544 | —- | C] () – C:\Windows\SysWow64\EasyRedirect.ini
[2011/09/25 08:35:44 | 000,001,248 | —- | C] () – C:\Windows\SysWow64\EasyRedirectOff.ini
[2011/05/01 12:27:23 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/05/01 12:27:23 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/03/07 15:26:43 | 000,007,600 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\Resmon.ResmonCfg
[2011/03/01 13:12:18 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2011/03/01 13:12:18 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2011/03/01 13:11:56 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/03/01 13:11:56 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/03/01 13:10:58 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2011/03/01 13:10:58 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2011/03/01 13:10:58 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2011/02/28 12:56:12 | 000,027,019 | —- | C] () – C:\Windows\maxlink.ini
[2011/02/23 15:46:51 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2011/02/23 15:46:51 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2011/02/23 15:46:50 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011/02/23 15:46:50 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011/02/23 15:22:08 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011/02/23 15:22:03 | 000,032,217 | —- | C] () – C:\Windows\Ascd_tmp.ini

========== LOP Check ==========

[2012/05/17 15:54:46 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Ad-Aware Antivirus
[2011/03/15 16:04:39 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Auslogics
[2011/08/07 09:48:00 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\AVG
[2011/09/26 12:29:03 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\AVG2012
[2012/04/08 18:07:16 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Encore
[2011/08/22 17:55:34 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Garmin
[2011/05/12 08:09:09 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Genie-Soft
[2011/03/01 14:38:27 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\ImgBurn
[2012/04/03 20:42:05 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\OfficeRecovery
[2011/02/27 17:41:21 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Opera
[2012/04/03 21:35:28 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\PandoraRecovery
[2011/03/01 12:36:00 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Temp
[2011/02/27 11:54:00 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\WinPatrol
[2011/11/30 08:23:48 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Zoner
[2012/06/01 04:15:10 | 000,000,466 | —- | M] () – C:\Windows\Tasks\GBM - Easy Layout Backup Job-Full.job
[2012/04/18 18:05:03 | 000,032,540 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/06/07 02:50:00 | 000,000,524 | —- | M] () – C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/06/06 03:00:00 | 000,000,524 | —- | M] () – C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
and the second one….


OTL Extras logfile created on: 6/7/2012 5:26:05 AM - Run 1
OTL by OldTimer - Version 3.2.46.2 Folder = C:\Users\John-Sandi 1\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 5.72 Gb Available Physical Memory | 71.49% Memory free
15.99 Gb Paging File | 13.25 Gb Available in Paging File | 82.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 857.05 Gb Free Space | 92.01% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 931.01 Gb Free Space | 99.95% Space Free | Partition Type: NTFS

Computer Name: JOHN-SANDI1-PC | User Name: John-Sandi 1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – "C:\Program Files (x86)\Opera\Opera.exe" "%1"
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] – "C:\Program Files (x86)\Opera\Opera.exe" "%1"

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
https [open] – "C:\Program Files (x86)\Opera\Opera.exe" "%1"
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
https [open] – "C:\Program Files (x86)\Opera\Opera.exe" "%1"
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{039321A6-4914-415C-856C-F0E230595857}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{047B0F73-0903-4A5E-9D59-587C33BC012F}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{06365F86-9428-42FC-BC5A-3EFFB9EA176A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{31B999CD-9744-4F02-B8CE-E3A9C049EFE9}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{40B6F76B-B307-41D1-88D6-69C82621D198}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{443AF4DD-6A2A-4888-9580-3F5B9E2E20E9}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4933CD35-D6E9-4AF6-BB6E-8B0CAB70217D}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{4E1F1B13-0C5D-429B-BD03-9831B1D2E96B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{4E21A516-BC2C-428E-A64F-B4E86FD2A285}" = lport=445 | protocol=6 | dir=in | app=system |
"{528F3703-6E1C-4101-BE56-047CA2FB7AEE}" = rport=137 | protocol=17 | dir=out | app=system |
"{56DE3F8E-B83D-4BFD-ABBD-B3D52F09B2FA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{62DA85FD-6409-416E-A6BB-A3E12CE9581E}" = lport=138 | protocol=17 | dir=in | app=system |
"{6D55EB7C-1E36-41FB-BDE0-14B771BAE826}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6DAE00CA-9746-4C22-A446-EEEF9D0D2FD7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{6F03C11B-1A61-42C1-BBD5-8B410297CCB9}" = lport=139 | protocol=6 | dir=in | app=system |
"{740932B6-7D85-4172-8487-0DF9438874D1}" = lport=137 | protocol=17 | dir=in | app=system |
"{75E0AB4D-F9B1-4419-8D5C-1FFD1B17D95B}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7C1A9968-4E68-44C3-A997-E1C7F08916A3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7F65AD97-F6E7-4970-A38B-209316B296AE}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{87FB8789-5726-4EC4-A42C-17CFD73ED163}" = rport=445 | protocol=6 | dir=out | app=system |
"{95ACCCD1-295F-4AC4-A4BE-74343D02A686}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B68E2BEE-2B50-47DD-BA2E-DC3801CFFCAC}" = rport=139 | protocol=6 | dir=out | app=system |
"{CCA1B678-3DF4-4B64-88A2-F615BE4F8F0C}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{D5C37862-A862-47CB-804F-1C487400F61D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DC05426B-B003-466F-88E8-FCAC7D4EE4A7}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{EAEA3C3D-6681-45E1-AFC9-6EB0899F5196}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F6C0BDA8-984A-48BD-A711-B469FA985988}" = rport=138 | protocol=17 | dir=out | app=system |
"{FE017094-71CE-436B-A0B1-528D7A133BD1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{FE7106FE-B4AA-45CA-9C05-32BD073BE579}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00BDFAB4-C46B-4F1C-A28F-59B9D3589961}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{087F02F2-F075-43E7-9AA9-57F2C5074486}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{0B48AAC5-2C82-4DB5-B601-05A57B796109}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{2DC9EE4C-33B3-4D10-8B02-397728368D25}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{381109A5-871F-4FD3-9B33-5FC15BDBA7B0}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{38D39A63-58D5-4A10-A0F9-ADE144A5A71A}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{41534830-08EF-467C-9CCD-246362E9E871}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{420A8EA2-6364-44B0-B62B-E7A8E0AE1318}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{4659840A-D230-4119-823E-6C72EA161050}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4EA797C0-61B8-49AD-A26F-9C1B90A6D8B7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{54A5B399-7D3A-458A-84D5-3388AEC1B889}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{556281DC-3809-4890-93A0-559A52287814}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5CECF4F9-D0B6-47D6-B035-ECDEDBD7D60F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6C1EC2CF-730C-4A82-8396-368F3EE9BB86}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{71CA602F-CE17-472D-8F41-F0EBF1F73C38}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{796A6C28-4267-4774-9BA7-F6265456E8F2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{79BA28C2-6280-4869-8A15-6AE992D3772D}" = protocol=6 | dir=out | app=system |
"{79DEA9C3-D1F5-4497-94BF-67D75784014F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8209EB7F-CCBB-43DB-96DF-B2587B269E98}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8F4E7AE7-4274-49E1-996C-376D5B7C7CBB}" = protocol=6 | dir=in | app=c:\program files (x86)\electric quilt company\eq6\eq6.exe |
"{9AA7A9D3-FAB3-43D6-8AC8-6DFDC9E182D4}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{9BFAA8E8-B87A-4E9E-9D11-C952FFCBA8E8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{9D8DEAD2-6BE8-4F78-A26F-C9D12A624539}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A03C4A93-CACF-4CFB-98FD-E6B26B5FA03E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A6B503E7-8D21-462A-8AAD-E4D9CDA8C27B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B261112F-6208-41A3-9084-170BB8F7A74D}" = protocol=17 | dir=in | app=c:\program files (x86)\electric quilt company\eq6\eq6.exe |
"{BCD79B83-BDC2-4188-997C-039A870DBA34}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{BFBC976A-FF58-47D0-9C56-BE62356CEA67}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{C5219971-39C5-46E8-B7D3-F6A04600D19F}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{CF2CE366-5419-4967-A51F-959D0EF614FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CFE0C752-D4F6-419B-AF41-9945F44980FC}" = protocol=6 | dir=in | app=c:\users\john-sandi 1\appdata\local\microsoft\skydrive\skydrive.exe |
"{D29C1ECE-5CF8-4CC5-B41D-8FC2487EC124}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{DAE91020-D70A-4657-A199-422F65ED2B0C}" = protocol=17 | dir=in | app=c:\users\john-sandi 1\appdata\local\microsoft\skydrive\skydrive.exe |
"{E9C0A420-C47F-4802-ADE5-1AF4F94AEF68}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{EA946695-1628-416A-9D1D-BC5B218CCE20}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EFD14F64-5B8D-44E1-A470-CC1FEF43A738}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{FB6F3AC3-AEBF-4B7B-86F3-A7F496DC100C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
"{446EE0D9-1F6B-42BF-8278-8D0B172BA15D}" = Microsoft IntelliType Pro 8.1
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{64555D45-1F57-BF1D-1A5E-BFD4C8C0ADB4}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{857B32C1-7C87-40B5-B2A5-D06F49B80002}" = AVG 2012
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.SingleImage_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.SingleImage_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.SingleImage_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.SingleImage_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-1000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.SingleImage_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.8.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B821CDAA-34DE-46FD-87C9-E6EE7158DB5D}" = Microsoft Image Composite Editor
"{BFF4A9FB-75F3-4162-84CD-16CE48C19173}" = AVG 2012
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft IntelliType Pro 8.1" = Microsoft IntelliType Pro 8.1
"Office14.SingleImage" = Microsoft Office Professional 2010

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0FABBA-6F8D-4087-B0FB-BF8AB57A0FEF}" = BackupManager
"{1A22A15D-E88A-427A-90E2-137245143239}" = Garmin Lifetime Updater
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2C3060F6-F0DC-4F63-A70F-2070BE57EEDC}" = The Print Shop 3.0 Fonts
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater
"{491D92A9-69CA-4EB4-81D3-0106F9337957}" = TurboV EVO
"{49B3B2D8-3429-492D-BAB5-5542048D5030}" = The Print Shop 3.0 Deluxe
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{987B04C4-B5AC-4AD6-A7E9-8D681085B850}" = AMD USB Filter Driver
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2AC00C-0C06-4B7E-97A4-A833808D54D6}" = EPU
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AFECFED6-0A43-488F-8511-1DC6B52F31C3}_is1" = Fast Duplicate File Finder 3.0.0.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B8887E02-C910-4498-A7C0-186ABFDCD110}" = GPU Boost Driver
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
"{C2530D63-B66B-48B5-BB50-7C6281FE7AA6}" = Brother MFL-Pro Suite MFC-7220
"{C9A162C1-031F-4EBF-A3E6-C45F7FCCBB9E}_is1" = Genie Backup Assistant
"{CDFC8F9A-79A7-4438-A090-B07C5A9739E9}" = EQ6
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Software
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF2A5498-4EFE-430F-A138-7EB365DBEBAD}" = Adobe Shockwave Player 11.6
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"Ad-Aware Browsing Protection" = Ad-Aware Browsing Protection
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Belarc Advisor" = Belarc Advisor 8.2
"ImgBurn" = ImgBurn
"Info Center_is1" = Info Center 1.0.0.7
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{CDFC8F9A-79A7-4438-A090-B07C5A9739E9}" = EQ6
"InstallWIX_{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MySSID_is1" = Vtune 7.12
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PandoraRecovery" = PandoraRecovery (Remove Only)
"Secunia PSI" = Secunia PSI (2.0.0.3001)
"SpywareBlaster_is1" = SpywareBlaster 4.6

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"SkyDriveSetup.exe" = Microsoft SkyDrive

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

Error - 6/4/2012 2:57:12 PM | Computer Name = John-Sandi1-PC | Source = ESENT | ID = 902
Description = Windows (4624) Windows: The database engine detected multiple threads
illegally using the same database session to perform database operations. SessionId:
0x0000000001351220 Session-context: 0x00000000 Session-context ThreadId: 0x00000000000013B4

Current
ThreadId: 0x00000000000013B8

[ System Events ]
Error - 5/21/2012 5:37:58 AM | Computer Name = John-Sandi1-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:36:21 AM on ?5/?21/?2012 was unexpected.

Error - 5/21/2012 5:37:59 AM | Computer Name = John-Sandi1-PC | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2

Error - 5/21/2012 6:22:02 PM | Computer Name = John-Sandi1-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:20:47 PM on ?5/?21/?2012 was unexpected.

Error - 5/21/2012 6:22:03 PM | Computer Name = John-Sandi1-PC | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2

Error - 5/27/2012 1:00:40 AM | Computer Name = John-Sandi1-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Kodak AiO Network Discovery Service service.

Error - 5/27/2012 1:01:11 AM | Computer Name = John-Sandi1-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Kodak AiO Network Discovery Service service.

Error - 5/27/2012 9:09:01 AM | Computer Name = John-Sandi1-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:06:19 AM on ?5/?27/?2012 was unexpected.

Error - 5/27/2012 9:09:03 AM | Computer Name = John-Sandi1-PC | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2

Error - 5/29/2012 12:07:56 PM | Computer Name = John-Sandi1-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:05:46 PM on ?5/?29/?2012 was unexpected.

Error - 5/29/2012 12:07:57 PM | Computer Name = John-Sandi1-PC | Source = Service Control Manager | ID = 7000
Description = The TBPanel service failed to start due to the following error: %%2


< End of report >
Good morning,

This fix will remove old hosts file backups that could be infected and reset the hosts file back to Microsoft defaults, let me know if it helped.


Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    [2012/05/22 07:14:40 | 001,038,088 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20120603-070313.backup
    [2012/05/21 05:52:41 | 000,601,715 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.20120522-071440.backup
    [2012/05/20 12:44:32 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.old
    @Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4
    @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Here's the log from the "Run Fix," I will be back shortly with the results of the fresh scan and to let you know if the fix worked.

All processes killed
========== PROCESSES ==========
========== OTL ==========
C:\Windows\SysNative\drivers\etc\hosts.20120603-070313.backup moved successfully.
C:\Windows\SysNative\drivers\etc\hosts.20120522-071440.backup moved successfully.
C:\Windows\SysNative\drivers\etc\hosts.old moved successfully.
ADS C:\ProgramData\TEMP:0B4227B4 deleted successfully.
ADS C:\ProgramData\TEMP:5C321E34 deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\John-Sandi 1\Desktop\cmd.bat deleted successfully.
C:\Users\John-Sandi 1\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: John-Sandi 1
->Temp folder emptied: 104714248 bytes
->Temporary Internet Files folder emptied: 5908726 bytes
->FireFox cache emptied: 51447274 bytes
->Google Chrome cache emptied: 2026580 bytes
->Opera cache emptied: 240 bytes

User: Public
->Temp folder emptied: 0 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 490 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 157.00 mb


OTL by OldTimer - Version 3.2.46.2 log created on 06072012_160628

Files\Folders moved on Reboot…
C:\Users\John-Sandi 1\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…
Here's the final scan…everything works perfect! Thanks a bunch!!!

John


OTL logfile created on: 6/7/2012 4:14:01 PM - Run 2
OTL by OldTimer - Version 3.2.46.2 Folder = C:\Users\John-Sandi 1\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 5.79 Gb Available Physical Memory | 72.37% Memory free
15.99 Gb Paging File | 13.61 Gb Available in Paging File | 85.11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 857.23 Gb Free Space | 92.03% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 931.01 Gb Free Space | 99.95% Space Free | Partition Type: NTFS

Computer Name: JOHN-SANDI1-PC | User Name: John-Sandi 1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\John-Sandi 1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\John-Sandi 1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
PRC - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\TurboV EVO\TurboVHelp.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe ()
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe (
ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\EPU\EPU.exe (
ASUSTeK Computer Inc.)
PRC - C:\Windows\DAODx.exe ()
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtscript4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtgui4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtnetwork4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtsql4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtdeclarative4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtcore4.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\flashobj.dll ()
MOD - C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\HookKey32.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\AsSpindownTimeout.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\AsusService.dll ()
MOD - C:\Windows\DAODx.exe ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\gs_encryption.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GSLogging.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (Mcx2Svc) – C:\Windows\SysNative\Mcx2Svc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (RemoteAccess) – C:\Windows\SysNative\mprdim.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (KSS) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (ThreatFire) – C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (AsSysCtrlService) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RemoteAccess) – C:\Windows\SysWOW64\mprdim.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (TfSysMon) – C:\Windows\SysNative\drivers\TfSysMon.sys (PC Tools)
DRV:64bit: - (TfNetMon) – C:\Windows\SysNative\drivers\TfNetMon.sys (PC Tools)
DRV:64bit: - (TfFsMon) – C:\Windows\SysNative\drivers\TfFsMon.sys (PC Tools)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (udfs) – C:\Windows\SysNative\drivers\udfs.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (crcdisk) – C:\Windows\SysNative\drivers\crcdisk.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (cdfs) – C:\Windows\SysNative\drivers\cdfs.sys (Microsoft Corporation)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (MREMP50) – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (Cardex) – C:\Windows\SysWOW64\drivers\TBPanelx64.sys (Windows ® Server 2003 DDK provider)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify…=us&.src=ym
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 62 06 0A 79 36 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{E66F2FCE-5E45-48E2-ABE4-DA04163E15B9}: "URL" = http://search.avg.com/route/?d=4e3da8b4&am;…y=&ychte=us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://login.yahoo.com/config/login_verify2?.src=ym&.done=http%3A%2F%2Fca.mc886.mail.yahoo.com%2Fmc%2Fwelcome%3Fswitch%3D1"
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.50
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.7
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/06/04 08:01:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/06/04 07:59:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]

[2011/03/05 11:34:24 | 000,000,000 | —D | M] (No name found) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Extensions
[2012/06/05 20:09:59 | 000,000,000 | —D | M] (No name found) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions
[2012/04/21 06:33:22 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/06/07 04:55:01 | 000,005,472 | —- | M] () – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\searchplugins\startpage-https.xml
[2012/05/20 14:19:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/04 07:59:53 | 000,000,000 | —D | M] (AVG Do Not Track) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/06/04 08:01:24 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4
[2011/07/27 12:41:28 | 000,079,135 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{1A2D0EC4-75F5-4C91-89C4-3656F6E44B68}.XPI
[2011/09/09 07:22:40 | 000,164,858 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.XPI
[2012/03/08 17:01:32 | 000,081,156 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{6D96BB5E-1175-4EBF-8AB5-5F56F1C79F65}.XPI
[2012/06/05 20:09:59 | 000,525,079 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012/01/05 09:28:20 | 000,634,964 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/01/22 06:30:28 | 000,138,614 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
[2012/04/20 21:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/20 21:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 21:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Google Update (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll

O1 HOSTS File: ([2012/06/07 16:06:30 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:64bit: - HKLM..\Run: [itype] c:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKLM..\Run: [Info Center] C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [Six Engine] C:\Program Files (x86)\ASUS\EPU\EPU.exe (
ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [TurboV EVO] C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKCU..\Run: [KSS] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
O4 - HKCU..\Run: [SkyDrive] C:\Users\John-Sandi 1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStartupSound = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableThumbnailsOnNetworkFolders = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32B7E865-2EF3-446B-BC3C-9143C51800FE}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/07 16:06:28 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/07 05:16:18 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\John-Sandi 1\Desktop\OTL.exe
[2012/06/06 06:36:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Belarc
[2012/06/04 09:24:39 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/06/04 09:23:40 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\Google
[2012/06/04 08:10:13 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
[2012/06/04 08:09:41 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2012/06/04 08:09:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2012/06/04 08:01:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/06/04 07:59:42 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/05/29 12:05:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
[2012/05/22 18:36:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012/05/22 18:34:10 | 001,451,840 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420103.dll
[2012/05/22 18:34:10 | 000,188,736 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2012/05/22 18:34:10 | 000,031,040 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2012/05/22 18:34:09 | 008,105,280 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/05/22 18:34:08 | 025,743,168 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/05/22 18:34:08 | 019,607,872 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/05/22 18:34:06 | 025,248,064 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/05/22 18:34:06 | 018,044,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/05/22 18:34:06 | 017,551,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/05/22 18:34:06 | 015,322,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/05/22 18:34:06 | 008,139,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/05/22 18:34:06 | 005,982,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/05/22 18:34:06 | 002,881,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/05/22 18:34:06 | 002,681,664 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/05/22 18:34:06 | 002,524,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/05/22 18:34:06 | 002,445,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/05/22 18:34:06 | 002,368,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/05/22 18:34:06 | 001,738,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/05/22 18:34:06 | 001,468,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/05/21 18:27:24 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\Apps
[2012/05/20 13:33:20 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Malwarebytes
[2012/05/20 13:33:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/05/19 06:07:16 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/05/19 06:01:14 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/05/19 05:44:09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/05/17 07:07:09 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\adawarebp
[2012/05/17 07:07:06 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012/05/17 07:05:18 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Ad-Aware Antivirus
[2012/05/15 07:23:51 | 004,894,432 | —- | C] (Microsoft Corporation) – C:\Users\John-Sandi 1\Desktop\SkyDriveSetup.exe
[2012/05/10 07:26:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/10 07:25:18 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/05/10 07:25:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012/05/10 07:09:16 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/10 07:09:13 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/10 07:09:13 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/05/10 07:08:54 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll

========== Files - Modified Within 30 Days ==========

[2012/06/07 16:16:21 | 000,015,184 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/07 16:16:21 | 000,015,184 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/07 16:13:27 | 000,783,418 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/07 16:13:27 | 000,663,222 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/07 16:13:27 | 000,122,090 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/07 16:09:09 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/07 16:09:07 | 2146,050,047 | -HS- | M] () – C:\hiberfil.sys
[2012/06/07 16:06:30 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2012/06/07 15:59:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/07 15:28:00 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000UA.job
[2012/06/07 10:50:00 | 000,000,524 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/06/07 09:36:34 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000Core.job
[2012/06/07 09:15:36 | 099,938,241 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/07 05:16:21 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\John-Sandi 1\Desktop\OTL.exe
[2012/06/06 06:36:47 | 000,002,092 | —- | M] () – C:\Users\John-Sandi 1\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,068 | —- | M] () – C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/06/06 03:00:00 | 000,000,524 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job
[2012/06/04 18:04:47 | 000,285,119 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/04 09:53:55 | 000,858,125 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\census.cache
[2012/06/04 09:53:47 | 000,118,095 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\ars.cache
[2012/06/04 09:46:20 | 000,000,036 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\housecall.guid.cache
[2012/06/04 09:24:40 | 000,002,357 | —- | M] () – C:\Users\John-Sandi 1\Desktop\Google Chrome.lnk
[2012/06/04 09:04:34 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/04 09:04:34 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/04 08:01:24 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/04 07:51:11 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/01 04:15:10 | 000,000,466 | —- | M] () – C:\Windows\tasks\GBM - Easy Layout Backup Job-Full.job
[2012/05/20 14:20:00 | 000,001,134 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/18 20:37:24 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/05/18 20:37:24 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/05/15 06:48:00 | 025,743,168 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/05/15 06:48:00 | 025,248,064 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/05/15 06:48:00 | 019,607,872 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/05/15 06:48:00 | 018,044,224 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/05/15 06:48:00 | 017,551,680 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/05/15 06:48:00 | 015,322,432 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/05/15 06:48:00 | 010,194,752 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2012/05/15 06:48:00 | 008,139,072 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/05/15 06:48:00 | 008,105,280 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/05/15 06:48:00 | 005,982,528 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/05/15 06:48:00 | 002,881,856 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/05/15 06:48:00 | 002,741,568 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2012/05/15 06:48:00 | 002,681,664 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/05/15 06:48:00 | 002,524,992 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/05/15 06:48:00 | 002,445,120 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/05/15 06:48:00 | 002,368,832 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/05/15 06:48:00 | 001,738,048 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/05/15 06:48:00 | 001,468,224 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/05/15 06:48:00 | 000,068,928 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2012/05/15 06:48:00 | 000,061,248 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2012/05/15 06:48:00 | 000,014,324 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[2012/05/15 05:29:46 | 000,118,080 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2012/05/15 05:29:46 | 000,063,296 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2012/05/15 05:29:25 | 003,149,632 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2012/05/15 05:28:42 | 006,151,488 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2012/05/15 02:21:50 | 000,423,744 | —- | M] () – C:\Windows\SysWow64\nvStreaming.exe
[2012/05/10 07:19:55 | 000,895,848 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/06/06 06:36:47 | 000,002,092 | —- | C] () – C:\Users\John-Sandi 1\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,080 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,068 | —- | C] () – C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/06/04 09:53:55 | 000,858,125 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\census.cache
[2012/06/04 09:53:47 | 000,118,095 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\ars.cache
[2012/06/04 09:46:20 | 000,000,036 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\housecall.guid.cache
[2012/06/04 09:24:40 | 000,002,357 | —- | C] () – C:\Users\John-Sandi 1\Desktop\Google Chrome.lnk
[2012/06/04 09:23:44 | 000,000,936 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000UA.job
[2012/06/04 09:23:43 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000Core.job
[2012/06/04 08:01:24 | 000,000,965 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/20 14:20:00 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/05/20 14:20:00 | 000,001,134 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/15 02:21:50 | 000,423,744 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2012/05/08 16:48:21 | 000,000,524 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/05/08 16:48:20 | 000,000,524 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job
[2012/02/11 20:25:04 | 000,000,000 | —- | C] () – C:\Windows\iplayer.INI
[2011/12/05 13:14:06 | 000,777,142 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/25 08:35:44 | 000,002,544 | —- | C] () – C:\Windows\SysWow64\EasyRedirect.ini
[2011/09/25 08:35:44 | 000,001,248 | —- | C] () – C:\Windows\SysWow64\EasyRedirectOff.ini
[2011/05/01 12:27:23 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/05/01 12:27:23 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/03/07 15:26:43 | 000,007,600 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\Resmon.ResmonCfg
[2011/03/01 13:12:18 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2011/03/01 13:12:18 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2011/03/01 13:11:56 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/03/01 13:11:56 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/03/01 13:10:58 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2011/03/01 13:10:58 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2011/03/01 13:10:58 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2011/02/28 12:56:12 | 000,027,019 | —- | C] () – C:\Windows\maxlink.ini
[2011/02/23 15:46:51 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2011/02/23 15:46:51 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2011/02/23 15:46:50 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011/02/23 15:46:50 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011/02/23 15:22:08 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011/02/23 15:22:03 | 000,032,217 | —- | C] () – C:\Windows\Ascd_tmp.ini

< End of report >
Wonderful :thumbup:

Since you may have been infected before, it would be in your best interest to run a couple of scans to make sure your system is clean.



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please







ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
I ran Malwarebytes just a few days ago, I kept the trial version on my system after the last time I came here for help. The trial period ran out but I will download it again to see if I can run it for you. Also…I have several Antispyware programs running in the background and I'm not certain how to turn them all off, they aren't all that simple to shut down!
Hi, Sometimes having to many anti virus and spyware programs running is a bit of overkill, you have Ad Aware and Spybot, I would keep Spybot and uninstall Ad Aware, on the AV side you have both AVG and Kaspersky , you need to uninstall one of them as running more than one can hamper system performance. It looks like you also have SuperAntiSpyware, your call on this one but I prefer Malwarebytes.
The Kaspersky program you see is their virus/trojan scanner, it only runs online on command. I no longer have Ad-Aware, that's the download (update) that handed me the virus! I also have SpywareBlaster, all 3 have found differing "issues" when I scan with them so I would prefer to keep them if they won't cause issues??? I have plenty of processor and memory. Would you like me to run the ESET scanner still???
OK…as soon as I have the time to shut down all my security (maybe tomorrow evening) I will run the scan and post the file. Thanks, John
Sorry…had to go out of town on a family emergency and had no access to either the computer or internet! I'll try to run that scan in the next night or so as I get caught back up on everything. John

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI