Thanks for your help!!! Here are the files you asked for:
OTL logfile created on: 6/7/2012 5:26:05 AM - Run 1
OTL by OldTimer - Version 3.2.46.2 Folder = C:\Users\John-Sandi 1\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 5.72 Gb Available Physical Memory | 71.49% Memory free
15.99 Gb Paging File | 13.25 Gb Available in Paging File | 82.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 857.05 Gb Free Space | 92.01% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 931.01 Gb Free Space | 99.95% Space Free | Partition Type: NTFS
Computer Name: JOHN-SANDI1-PC | User Name: John-Sandi 1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\John-Sandi 1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\John-Sandi 1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
PRC - C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
PRC - C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
PRC - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\TurboV EVO\TurboVHelp.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe ()
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\ASUS\GPU Boost Driver\GpuBoostServer.exe (
ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\EPU\EPU.exe (
ASUSTeK Computer Inc.)
PRC - C:\Windows\DAODx.exe ()
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtscript4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtgui4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtnetwork4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtsql4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtdeclarative4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\qtcore4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\flashobj.dll ()
MOD - C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\Program Files (x86)\ASUS\TurboV EVO\HookKey32.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\AsSpindownTimeout.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU\AsusService.dll ()
MOD - C:\Windows\DAODx.exe ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\gs_encryption.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GSLogging.dll ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:
64bit: - (Mcx2Svc) – C:\Windows\SysNative\Mcx2Svc.dll (Microsoft Corporation)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (RemoteAccess) – C:\Windows\SysNative\mprdim.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (KSS) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)
SRV - (ThreatFire) – C:\Program Files (x86)\ThreatFire\TFService.exe (PC Tools)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (AsSysCtrlService) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.05\AsSysCtrlService.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RemoteAccess) – C:\Windows\SysWOW64\mprdim.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:
64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:
64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:
64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:
64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:
64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:
64bit: - (TfSysMon) – C:\Windows\SysNative\drivers\TfSysMon.sys (PC Tools)
DRV:
64bit: - (TfNetMon) – C:\Windows\SysNative\drivers\TfNetMon.sys (PC Tools)
DRV:
64bit: - (TfFsMon) – C:\Windows\SysNative\drivers\TfFsMon.sys (PC Tools)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (udfs) – C:\Windows\SysNative\drivers\udfs.sys (Microsoft Corporation)
DRV:
64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:
64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:
64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:
64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:
64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:
64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (crcdisk) – C:\Windows\SysNative\drivers\crcdisk.sys (Microsoft Corporation)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (cdfs) – C:\Windows\SysNative\drivers\cdfs.sys (Microsoft Corporation)
DRV:
64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (MREMP50) – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (Cardex) – C:\Windows\SysWOW64\drivers\TBPanelx64.sys (Windows ® Server 2003 DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/login_verify…=us&.src=ym
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9A 62 06 0A 79 36 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{E66F2FCE-5E45-48E2-ABE4-DA04163E15B9}: "URL" =
http://search.avg.com/route/?d=4e3da8b4&am;…y=&ychte=us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
https://login.yahoo.com/config/login_verify2?.src=ym&.done=http%3A%2F%2Fca.mc886.mail.yahoo.com%2Fmc%2Fwelcome%3Fswitch%3D1"
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.50
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.7
FF - prefs.js..keyword.URL: "
http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/06/04 08:01:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/06/04 07:59:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/20 20:17:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/12 06:44:10 | 000,000,000 | —D | M]
[2011/03/05 11:34:24 | 000,000,000 | —D | M] (No name found) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Extensions
[2012/06/05 20:09:59 | 000,000,000 | —D | M] (No name found) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions
[2012/04/21 06:33:22 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/06/07 04:55:01 | 000,005,472 | —- | M] () – C:\Users\John-Sandi 1\AppData\Roaming\Mozilla\Firefox\Profiles\p3z1nlo0.default\searchplugins\startpage-https.xml
[2012/05/20 14:19:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/04 07:59:53 | 000,000,000 | —D | M] (AVG Do Not Track) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/06/04 08:01:24 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX4
[2011/07/27 12:41:28 | 000,079,135 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{1A2D0EC4-75F5-4C91-89C4-3656F6E44B68}.XPI
[2011/09/09 07:22:40 | 000,164,858 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.XPI
[2012/03/08 17:01:32 | 000,081,156 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{6D96BB5E-1175-4EBF-8AB5-5F56F1C79F65}.XPI
[2012/06/05 20:09:59 | 000,525,079 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012/01/05 09:28:20 | 000,634,964 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/01/22 06:30:28 | 000,138,614 | —- | M] () (No name found) – C:\USERS\JOHN-SANDI 1\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3Z1NLO0.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
[2012/04/20 21:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/20 21:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 21:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Google Update (Enabled) = C:\Users\John-Sandi 1\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
O1 HOSTS File: ([2012/06/03 07:03:13 | 001,038,049 | R— | M]) - C:\Windows\SysNative\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost #[IPv6]
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 abcstats.com
O1 - Hosts: 127.0.0.1 a.abv.bg
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 ca.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 31164 more lines…
O2:
64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:
64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4:
64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4:
64bit: - HKLM..\Run: [itype] c:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKLM..\Run: [Info Center] C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [Six Engine] C:\Program Files (x86)\ASUS\EPU\EPU.exe (
ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
O4 - HKLM..\Run: [TurboV EVO] C:\Program Files (x86)\ASUS\TurboV EVO\TurboV_EVO.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKCU..\Run: [KSS] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
O4 - HKCU..\Run: [SkyDrive] C:\Users\John-Sandi 1\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStartupSound = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableThumbnailsOnNetworkFolders = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:
64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32B7E865-2EF3-446B-BC3C-9143C51800FE}: DhcpNameServer = 10.0.0.1
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/06/07 05:16:18 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\John-Sandi 1\Desktop\OTL.exe
[2012/06/06 06:36:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Belarc
[2012/06/04 09:24:39 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/06/04 09:23:40 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\Google
[2012/06/04 08:10:13 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
[2012/06/04 08:09:41 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2012/06/04 08:09:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2012/06/04 08:01:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/06/04 07:59:42 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/05/29 12:05:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
[2012/05/22 18:36:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2012/05/22 18:34:10 | 001,451,840 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420103.dll
[2012/05/22 18:34:10 | 000,188,736 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2012/05/22 18:34:10 | 000,031,040 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2012/05/22 18:34:09 | 008,105,280 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/05/22 18:34:08 | 025,743,168 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/05/22 18:34:08 | 019,607,872 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/05/22 18:34:06 | 025,248,064 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/05/22 18:34:06 | 018,044,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/05/22 18:34:06 | 017,551,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/05/22 18:34:06 | 015,322,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/05/22 18:34:06 | 008,139,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/05/22 18:34:06 | 005,982,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/05/22 18:34:06 | 002,881,856 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/05/22 18:34:06 | 002,681,664 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/05/22 18:34:06 | 002,524,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/05/22 18:34:06 | 002,445,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/05/22 18:34:06 | 002,368,832 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/05/22 18:34:06 | 001,738,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/05/22 18:34:06 | 001,468,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/05/21 18:27:24 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\Apps
[2012/05/20 13:33:20 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Malwarebytes
[2012/05/20 13:33:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/05/19 06:07:16 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/05/19 06:01:14 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/05/19 05:44:09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/05/17 07:07:09 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Local\adawarebp
[2012/05/17 07:07:06 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012/05/17 07:05:18 | 000,000,000 | —D | C] – C:\Users\John-Sandi 1\AppData\Roaming\Ad-Aware Antivirus
[2012/05/15 07:23:51 | 004,894,432 | —- | C] (Microsoft Corporation) – C:\Users\John-Sandi 1\Desktop\SkyDriveSetup.exe
[2012/05/10 07:26:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/10 07:25:18 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/05/10 07:25:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012/05/10 07:09:16 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/10 07:09:13 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/10 07:09:13 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/05/10 07:08:54 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
========== Files - Modified Within 30 Days ==========
[2012/06/07 05:28:00 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000UA.job
[2012/06/07 05:16:21 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\John-Sandi 1\Desktop\OTL.exe
[2012/06/07 04:59:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/07 02:50:00 | 000,000,524 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/06/06 18:05:29 | 099,869,056 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/06 09:28:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000Core.job
[2012/06/06 06:36:47 | 000,002,092 | —- | M] () – C:\Users\John-Sandi 1\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,068 | —- | M] () – C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/06/06 03:00:00 | 000,000,524 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job
[2012/06/04 18:04:47 | 000,285,119 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/04 09:53:55 | 000,858,125 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\census.cache
[2012/06/04 09:53:47 | 000,118,095 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\ars.cache
[2012/06/04 09:46:20 | 000,000,036 | —- | M] () – C:\Users\John-Sandi 1\AppData\Local\housecall.guid.cache
[2012/06/04 09:24:40 | 000,002,357 | —- | M] () – C:\Users\John-Sandi 1\Desktop\Google Chrome.lnk
[2012/06/04 09:04:34 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/04 09:04:34 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/04 08:11:20 | 000,015,184 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/04 08:11:20 | 000,015,184 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/04 08:09:27 | 000,783,418 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/04 08:09:27 | 000,663,222 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/04 08:09:27 | 000,122,090 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/04 08:03:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/04 08:03:58 | 2146,050,047 | -HS- | M] () – C:\hiberfil.sys
[2012/06/04 08:01:24 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/04 07:51:11 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/03 07:03:13 | 001,038,049 | R— | M] () – C:\Windows\SysNative\drivers\etc\HOSTS
[2012/06/01 04:15:10 | 000,000,466 | —- | M] () – C:\Windows\tasks\GBM - Easy Layout Backup Job-Full.job
[2012/05/22 07:14:40 | 001,038,088 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20120603-070313.backup
[2012/05/21 05:52:41 | 000,601,715 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.20120522-071440.backup
[2012/05/20 14:20:00 | 000,001,134 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/20 12:44:32 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.old
[2012/05/18 20:37:24 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/05/18 20:37:24 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/05/15 06:48:00 | 025,743,168 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/05/15 06:48:00 | 025,248,064 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/05/15 06:48:00 | 019,607,872 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/05/15 06:48:00 | 018,044,224 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/05/15 06:48:00 | 017,551,680 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/05/15 06:48:00 | 015,322,432 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/05/15 06:48:00 | 010,194,752 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2012/05/15 06:48:00 | 008,139,072 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/05/15 06:48:00 | 008,105,280 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/05/15 06:48:00 | 005,982,528 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/05/15 06:48:00 | 002,881,856 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/05/15 06:48:00 | 002,741,568 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2012/05/15 06:48:00 | 002,681,664 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/05/15 06:48:00 | 002,524,992 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/05/15 06:48:00 | 002,445,120 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/05/15 06:48:00 | 002,368,832 | —- | M] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/05/15 06:48:00 | 001,738,048 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/05/15 06:48:00 | 001,468,224 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/05/15 06:48:00 | 000,068,928 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2012/05/15 06:48:00 | 000,061,248 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2012/05/15 06:48:00 | 000,014,324 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[2012/05/15 05:29:46 | 000,118,080 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2012/05/15 05:29:46 | 000,063,296 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2012/05/15 05:29:25 | 003,149,632 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2012/05/15 05:28:42 | 006,151,488 | —- | M] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2012/05/15 02:21:50 | 000,423,744 | —- | M] () – C:\Windows\SysWow64\nvStreaming.exe
[2012/05/10 07:19:55 | 000,895,848 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2012/06/06 06:36:47 | 000,002,092 | —- | C] () – C:\Users\John-Sandi 1\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,080 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2012/06/06 06:36:47 | 000,002,068 | —- | C] () – C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/06/04 09:53:55 | 000,858,125 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\census.cache
[2012/06/04 09:53:47 | 000,118,095 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\ars.cache
[2012/06/04 09:46:20 | 000,000,036 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\housecall.guid.cache
[2012/06/04 09:24:40 | 000,002,357 | —- | C] () – C:\Users\John-Sandi 1\Desktop\Google Chrome.lnk
[2012/06/04 09:23:44 | 000,000,936 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000UA.job
[2012/06/04 09:23:43 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4149017224-2307168478-2718211766-1000Core.job
[2012/06/04 08:01:24 | 000,000,965 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/05/20 14:20:00 | 000,001,146 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/05/20 14:20:00 | 000,001,134 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/15 02:21:50 | 000,423,744 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2012/05/08 16:48:21 | 000,000,524 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/05/08 16:48:20 | 000,000,524 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job
[2012/02/11 20:25:04 | 000,000,000 | —- | C] () – C:\Windows\iplayer.INI
[2011/12/05 13:14:06 | 000,777,142 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/25 08:35:44 | 000,002,544 | —- | C] () – C:\Windows\SysWow64\EasyRedirect.ini
[2011/09/25 08:35:44 | 000,001,248 | —- | C] () – C:\Windows\SysWow64\EasyRedirectOff.ini
[2011/05/01 12:27:23 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/05/01 12:27:23 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/03/07 15:26:43 | 000,007,600 | —- | C] () – C:\Users\John-Sandi 1\AppData\Local\Resmon.ResmonCfg
[2011/03/01 13:12:18 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2011/03/01 13:12:18 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2011/03/01 13:11:56 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/03/01 13:11:56 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/03/01 13:10:58 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2011/03/01 13:10:58 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2011/03/01 13:10:58 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2011/02/28 12:56:12 | 000,027,019 | —- | C] () – C:\Windows\maxlink.ini
[2011/02/23 15:46:51 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2011/02/23 15:46:51 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2011/02/23 15:46:50 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011/02/23 15:46:50 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011/02/23 15:22:08 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011/02/23 15:22:03 | 000,032,217 | —- | C] () – C:\Windows\Ascd_tmp.ini
========== LOP Check ==========
[2012/05/17 15:54:46 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Ad-Aware Antivirus
[2011/03/15 16:04:39 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Auslogics
[2011/08/07 09:48:00 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\AVG
[2011/09/26 12:29:03 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\AVG2012
[2012/04/08 18:07:16 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Encore
[2011/08/22 17:55:34 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Garmin
[2011/05/12 08:09:09 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Genie-Soft
[2011/03/01 14:38:27 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\ImgBurn
[2012/04/03 20:42:05 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\OfficeRecovery
[2011/02/27 17:41:21 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Opera
[2012/04/03 21:35:28 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\PandoraRecovery
[2011/03/01 12:36:00 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Temp
[2011/02/27 11:54:00 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\WinPatrol
[2011/11/30 08:23:48 | 000,000,000 | —D | M] – C:\Users\John-Sandi 1\AppData\Roaming\Zoner
[2012/06/01 04:15:10 | 000,000,466 | —- | M] () – C:\Windows\Tasks\GBM - Easy Layout Backup Job-Full.job
[2012/04/18 18:05:03 | 000,032,540 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/06/07 02:50:00 | 000,000,524 | —- | M] () – C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 1f7551e3-d253-488a-926d-44e29d7bb744.job
[2012/06/06 03:00:00 | 000,000,524 | —- | M] () – C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b0987a63-dfee-4766-933f-4ace86b3c42d.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >