This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cleaned Malware On Boyfriends Computer - Now Its Buggy [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I recently cleaned up my boyfriends computer using: Avast Malwarebytes Spybot S&D CCleaner Well now it is spyware, adware and malware free but it is quite buggy and keeps lagging. I feel like I missed some malware or it corrupted something,if someone can please help <3 BTW I am not not a novice I have used these programs hundreds of times to fix computers and this is the first time it was ever buggy after I fixed it.
Oh sorry I forgot to say: He has a laptop with Win7 Home Premium and 3gb of RAM and I am currently running OTL like the "Are you infected post says to"
OTL logfile created on: 7/11/2012 3:10:05 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Anthony Moore\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 58.18% Memory free
5.92 Gb Paging File | 4.81 Gb Available in Paging File | 81.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 21.08 Gb Free Space | 9.66% Space Free | Partition Type: NTFS

Computer Name: ANTHONYMOORE-PC | User Name: Anthony Moore | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Anthony Moore\Desktop\OTL.exe (OldTimer Tools)


========== Modules (No Company Name) ==========

MOD - C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\pdf.dll ()
MOD - C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\avutil-51.dll ()
MOD - C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\avformat-54.dll ()
MOD - C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\avcodec-54.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DAZContentManagementService) – C:\Program Files\DAZ 3D\Content Management Service\ContentManagementServer.exe ()
SRV:64bit: - (DisplayLinkService) – C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe (DisplayLink Corp.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV:64bit: - (TabletServicePen) – C:\Windows\SysNative\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (DSUDiskOptimizer) – C:\Program Files (x86)\Disk Speedup\DSUDefragSrv64.exe (Systweak Inc., (www.systweak.com))
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe (IDT, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (MotioninJoyXFilter) – C:\Windows\SysNative\drivers\MijXfilt.sys (MotioninJoy)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (DisplayLinkUsbPort) – C:\Windows\SysNative\drivers\DisplayLinkUsbPort_5.6.31854.0.sys (http://libusb-win32.sourceforge.net)
DRV:64bit: - (dlkmd) – C:\Windows\SysNative\drivers\dlkmd.sys (DisplayLink Corp.)
DRV:64bit: - (dlkmdldr) – C:\Windows\SysNative\drivers\dlkmdldr.sys (DisplayLink Corp.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RMCAST) – C:\Windows\SysNative\drivers\rmcast.sys (Microsoft Corporation)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (DCamUSBNovatek) – C:\Windows\SysNative\drivers\nvtcam.sys (Hewlett-Packard)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (ManyCam) – C:\Windows\SysNative\drivers\ManyCam_x64.sys (ManyCam LLC.)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (WacomVKHid) – C:\Windows\SysNative\drivers\WacomVKHid.sys (Wacom Technology)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {ACF3F28D-177F-4E12-A348-47B907121FF9}
IE:64bit: - HKLM\..\SearchScopes\{ACF3F28D-177F-4E12-A348-47B907121FF9}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\..\SearchScopes,DefaultScope = {AC153DD4-32EA-443A-BF42-D3EE4410897B}
IE - HKLM\..\SearchScopes\{AC153DD4-32EA-443A-BF42-D3EE4410897B}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 79 9E CD 7C 21 6C CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {AC153DD4-32EA-443A-BF42-D3EE4410897B}
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…D2-518A23437EC0
IE - HKCU\..\SearchScopes\{AC153DD4-32EA-443A-BF42-D3EE4410897B}: "URL" = http://www.bing.com/search?FORM=IEFM1&…ferrer:source?}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========



FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.4: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Anthony Moore\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Anthony Moore\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Anthony Moore\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Anthony Moore\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Anthony Moore\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Anthony Moore\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.7.1: C:\Users\Anthony Moore\AppData\Local\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll (Yahoo! Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files (x86)\Google\Google Gears\Firefox\ [2010/07/21 22:36:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/21 19:11:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/01/19 14:54:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/07/05 19:50:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/07/09 01:31:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/18 01:05:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/28 15:19:28 | 000,000,000 | —D | M]

[2010/10/26 20:56:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Anthony Moore\AppData\Roaming\Mozilla\Extensions
[2010/06/03 11:30:05 | 000,000,000 | —D | M] (No name found) – C:\Users\Anthony Moore\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/07/05 17:16:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Anthony Moore\AppData\Roaming\Mozilla\Firefox\Profiles\58blyo8k.default\extensions
[2011/11/07 14:35:28 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Anthony Moore\AppData\Roaming\Mozilla\Firefox\Profiles\58blyo8k.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/03/05 02:54:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/05 21:59:46 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/11/27 05:10:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2012/03/05 02:54:11 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2011/08/04 16:44:52 | 000,608,840 | —- | M] () (No name found) – C:\USERS\ANTHONY MOORE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\58BLYO8K.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/08/04 16:47:04 | 000,016,647 | —- | M] () (No name found) – C:\USERS\ANTHONY MOORE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\58BLYO8K.DEFAULT\EXTENSIONS\[removed]
[2011/07/08 00:16:28 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/05/18 01:04:58 | 000,129,144 | —- | M] (RealPlayer) – C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\Application\21.0.1180.15\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Anthony Moore\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Anthony Moore\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Anthony Moore\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.7.1 (Enabled) = C:\Users\Anthony Moore\AppData\Local\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Anthony Moore\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Ocean Pacific = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecaabliejjdikjnkahhikeelbblahgoi\3_0\
CHR - Extension: AdBlock = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.38_0\
CHR - Extension: avast! WebRep = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: FA Previewer = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbdmbjljdmkaefooomifpmmallfgdbec\2.0.0_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Users\Anthony Moore\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/07/09 01:01:51 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - HKCU..\Run: [SanDisk_ImageVault_Manager.exe] C:\Users\Anthony Moore\AppData\Roaming\SanDisk\SanDisk_ImageVault_Manager.exe (Dmailer S.A.)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe (Softthinks)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{29F7C550-9219-4278-8B67-734C00AADEAB}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{832EDF2A-FDC2-4540-80B9-76D67B49E385}: DhcpNameServer = 192.168.222.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084

========== Files/Folders - Created Within 30 Days ==========

[2012/07/11 14:50:53 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Users\Anthony Moore\Desktop\OTL.exe
[2012/07/10 20:40:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2012/07/10 20:40:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2012/07/10 20:40:34 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/07/10 20:40:25 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2012/07/10 20:40:21 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2012/07/09 01:30:05 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/07/09 01:04:45 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/07/09 00:51:23 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/07/09 00:51:23 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/07/09 00:51:23 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/07/09 00:45:11 | 000,000,000 | —D | C] – C:\Qoobox
[2012/07/09 00:44:36 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/07/07 14:25:09 | 000,000,000 | —D | C] – C:\Users\Anthony Moore\AppData\Roaming\join.me
[2012/07/06 20:40:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/07/06 20:39:43 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/07/06 20:39:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2012/07/06 02:25:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/07/05 17:04:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
[2012/07/05 17:04:23 | 000,000,000 | —D | C] – C:\Program Files\Defraggler
[2012/07/04 18:56:17 | 000,000,000 | —D | C] – C:\Windows\pss
[2012/07/04 18:51:24 | 000,000,000 | —D | C] – C:\Users\Anthony Moore\AppData\Roaming\Malwarebytes
[2012/07/04 18:51:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/04 18:51:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/07/04 18:51:07 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/07/04 18:51:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/04 18:40:00 | 000,355,856 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/07/04 18:40:00 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/07/04 18:40:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012/07/04 18:39:59 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/07/04 18:39:59 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/07/04 18:39:57 | 000,958,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/07/04 18:39:55 | 000,071,064 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/07/04 18:39:54 | 000,285,328 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/07/04 18:39:28 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/07/04 18:39:27 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/07/04 18:39:12 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012/07/04 18:39:12 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012/06/28 15:19:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Oracle
[2012/06/28 15:19:28 | 000,772,504 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2012/06/28 15:19:28 | 000,227,720 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/06/28 15:18:47 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/06/28 15:18:47 | 000,174,064 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/06/24 23:13:28 | 000,000,000 | —D | C] – C:\Users\Anthony Moore\AppData\Local\Apps
[2012/06/21 11:12:46 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/21 11:12:46 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/21 11:12:45 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/21 11:12:23 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/21 11:12:23 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/21 11:12:23 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/21 11:12:07 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/21 11:12:07 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/19 21:19:50 | 000,044,032 | —- | C] (Research in Motion Ltd) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys
[2012/06/19 21:18:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\XCPCSync.OEM
[2012/06/14 08:32:02 | 000,918,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/14 08:32:02 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/14 08:31:50 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/06/14 08:31:46 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/14 08:31:45 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/14 08:31:42 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/14 08:31:42 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/14 08:31:40 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/14 08:31:39 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/14 08:29:13 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/14 08:29:12 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/14 08:29:12 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/14 08:29:02 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/14 08:29:00 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/14 08:29:00 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/14 08:28:43 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/14 08:28:32 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/14 08:28:31 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/11 14:50:43 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Anthony Moore\Desktop\OTL.exe
[2012/07/11 14:40:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/11 14:40:13 | 2384,744,448 | -HS- | M] () – C:\hiberfil.sys
[2012/07/11 14:33:54 | 000,729,944 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/11 14:33:54 | 000,626,540 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/07/11 14:33:54 | 000,107,784 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/07/11 14:31:42 | 000,001,946 | —- | M] () – C:\Users\Anthony Moore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Photosmart 5510 series (Network).lnk
[2012/07/11 14:31:20 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/11 14:31:14 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/11 14:15:57 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/11 14:15:57 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/11 14:10:00 | 000,000,940 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4227348043-2089238777-2656959782-1001UA.job
[2012/07/11 14:10:00 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4227348043-2089238777-2656959782-1001Core.job
[2012/07/11 14:07:51 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2012/07/11 14:01:00 | 000,000,272 | —- | M] () – C:\Windows\tasks\HP Photo Creations Messager.job
[2012/07/11 13:45:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/11 13:44:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4227348043-2089238777-2656959782-501UA.job
[2012/07/11 04:00:21 | 004,914,056 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/10 17:44:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4227348043-2089238777-2656959782-501Core.job
[2012/07/09 01:31:36 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/07/09 01:01:51 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/07/06 21:11:02 | 000,006,120 | —- | M] () – C:\Windows\wininit.ini
[2012/07/03 09:21:52 | 000,958,400 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/07/03 09:21:52 | 000,355,856 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/07/03 09:21:52 | 000,071,064 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/07/03 09:21:52 | 000,059,728 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/07/03 09:21:52 | 000,054,072 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/07/03 09:21:51 | 000,025,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/07/03 09:21:32 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/07/03 09:21:28 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/07/03 09:21:18 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/07/02 10:50:25 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/06/28 15:18:20 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/06/28 15:18:19 | 000,174,064 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/06/28 14:22:25 | 000,000,973 | —- | M] () – C:\Users\Anthony Moore\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/06/23 00:46:05 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 00:46:05 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/19 21:20:33 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
[2012/06/19 21:20:11 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
[2012/06/19 21:13:53 | 000,051,712 | —- | M] () – C:\Users\Anthony Moore\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/13 23:22:59 | 000,025,790 | —- | M] () – C:\Users\Anthony Moore\Desktop\ACBADGES.odt
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/09 00:51:23 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/07/09 00:51:23 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/07/09 00:51:23 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/07/09 00:51:23 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/07/09 00:51:23 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/07/07 14:25:13 | 000,001,133 | —- | C] () – C:\Users\Anthony Moore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk
[2012/07/06 21:10:50 | 000,006,120 | —- | C] () – C:\Windows\wininit.ini
[2012/07/05 19:35:00 | 004,914,056 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/05 19:34:21 | 000,001,946 | —- | C] () – C:\Users\Anthony Moore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Photosmart 5510 series (Network).lnk
[2012/07/04 18:39:54 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2012/06/19 21:20:33 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
[2012/06/19 21:20:11 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
[2012/01/27 21:01:57 | 000,000,855 | —- | C] () – C:\Users\Anthony Moore\.recently-used.xbel
[2012/01/24 02:50:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\dlumd9.dll
[2012/01/24 02:50:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\dlumd11.dll
[2012/01/24 02:50:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\dlumd10.dll
[2011/11/02 14:37:36 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2011/08/04 16:40:52 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/05/06 00:34:45 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2011/04/07 12:37:17 | 001,634,297 | —- | C] () – C:\Windows\SysWow64\libvorbisenc-2.dll
[2011/04/07 12:37:17 | 000,897,536 | —- | C] () – C:\Windows\SysWow64\libx264-102.dll
[2011/04/07 12:37:17 | 000,286,053 | —- | C] () – C:\Windows\SysWow64\libtheoraenc-1.dll
[2011/04/07 12:37:17 | 000,201,230 | —- | C] () – C:\Windows\SysWow64\swscale-0.dll
[2011/04/07 12:37:17 | 000,183,339 | —- | C] () – C:\Windows\SysWow64\libvorbis-0.dll
[2011/04/07 12:37:17 | 000,111,345 | —- | C] () – C:\Windows\SysWow64\libtheoradec-1.dll
[2011/04/07 12:37:16 | 005,593,102 | —- | C] () – C:\Windows\SysWow64\avcodec-52.dll
[2011/04/07 12:37:16 | 000,795,150 | —- | C] () – C:\Windows\SysWow64\avformat-52.dll
[2011/04/07 12:37:16 | 000,345,447 | —- | C] () – C:\Windows\SysWow64\libmp3lame-0.dll
[2011/04/07 12:37:16 | 000,082,958 | —- | C] () – C:\Windows\SysWow64\avutil-50.dll
[2011/04/07 12:37:16 | 000,068,091 | —- | C] () – C:\Windows\SysWow64\libogg-0.dll
[2011/04/07 12:37:16 | 000,016,398 | —- | C] () – C:\Windows\SysWow64\avdevice-52.dll
[2011/02/02 11:41:31 | 000,000,432 | —- | C] () – C:\Users\Anthony Moore\AppData\Roaming\.backup.dm
[2011/01/25 23:17:02 | 000,744,030 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/02 00:01:06 | 013,041,702 | —- | C] () – C:\Users\Anthony Moore\FINAL BEATDOWN.WAV
[2010/06/04 01:59:45 | 000,051,712 | —- | C] () – C:\Users\Anthony Moore\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/28 17:31:21 | 000,000,196 | —- | C] () – C:\Users\Anthony Moore\AppData\Roaming\wklnhst.dat

========== LOP Check ==========

[2010/12/29 21:58:26 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\AnvSoft
[2011/08/21 01:15:23 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2010/08/23 23:23:53 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\com.adobe.ExMan
[2011/12/20 11:46:32 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1
[2010/06/13 14:53:38 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2011/10/10 14:08:06 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\DAZ 3D
[2012/01/19 00:22:56 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Dropbox
[2010/06/01 18:26:17 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Facebook
[2012/06/01 22:28:01 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\FrostWire
[2012/01/27 21:01:57 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\gtk-2.0
[2012/06/04 05:04:47 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\IcoFX2X
[2012/07/07 14:25:09 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\join.me
[2010/05/28 19:05:15 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\ManyCam
[2012/03/05 17:54:25 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\MotioninJoy
[2010/07/29 22:40:17 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\NCH Swift Sound
[2010/06/24 16:36:08 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\NetMedia Providers
[2010/07/21 23:48:35 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\OpenOffice.org
[2011/03/07 23:30:32 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\PCDr
[2010/06/24 16:36:08 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Publish Providers
[2010/07/29 22:40:25 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Recordpad
[2011/07/14 16:33:09 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Research In Motion
[2011/09/04 23:14:55 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Rovio
[2011/05/23 14:50:53 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\SanDisk
[2010/05/28 23:32:28 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\SecondLife
[2010/06/24 16:48:19 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Sony
[2010/06/11 02:00:25 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\SYSTEMAX Software Development
[2012/06/11 17:49:22 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Systweak
[2010/05/28 20:06:54 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Template
[2011/05/08 11:51:25 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\UB
[2012/07/05 17:10:12 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\uTorrent
[2010/07/21 23:11:13 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\WeatherBug
[2010/11/18 10:43:45 | 000,000,000 | —D | M] – C:\Users\Anthony Moore\AppData\Roaming\Windows Live Writer
[2012/07/02 10:50:25 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012/01/14 04:17:01 | 000,032,572 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/07/11 14:07:51 | 000,000,506 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/07/09 01:04:44 | 000,022,066 | —- | M] () – C:\ComboFix.txt
[2010/02/19 13:03:36 | 000,003,205 | RH– | M] () – C:\dell.sdr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/07/11 14:40:13 | 2384,744,448 | -HS- | M] () – C:\hiberfil.sys
[2012/06/04 04:51:22 | 000,001,128 | —- | M] () – C:\IcoFX.log
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/12/09 01:09:27 | 000,000,360 | -H– | M] () – C:\IPH.PH
[2012/07/11 14:40:19 | 3179,663,360 | -HS- | M] () – C:\pagefile.sys
[2011/06/22 01:48:16 | 000,651,644 | —- | M] () – C:\ProcasterInstaller.log
[2011/08/28 18:19:38 | 000,000,445 | —- | M] () – C:\SoftUpdate.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/07/03 09:21:32 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/03/08 16:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/21 23:11:17 | 000,000,205 | —- | M] () – C:\Users\Anthony Moore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\1000 Free Songs!.url
[2010/05/28 17:23:57 | 000,000,221 | -HS- | M] () – C:\Users\Anthony Moore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/21 23:11:17 | 000,000,209 | —- | M] () – C:\Users\Anthony Moore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FREE GAMES!.url

< %USERPROFILE%\Desktop\*.exe >
[2012/07/11 14:50:43 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Anthony Moore\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 176 bytes -> C:\ProgramData\TEMP:661DFA1C

< End of report >
OTL Extras logfile created on: 7/11/2012 3:10:05 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Anthony Moore\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 58.18% Memory free
5.92 Gb Paging File | 4.81 Gb Available in Paging File | 81.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 21.08 Gb Free Space | 9.66% Space Free | Partition Type: NTFS

Computer Name: ANTHONYMOORE-PC | User Name: Anthony Moore | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{007A7CDD-FAFF-42D9-BCAB-DF0AA012C8DF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{06E63E44-7395-4987-9CD0-43F4C770A3E0}" = lport=138 | protocol=17 | dir=in | app=system |
"{0C33FB8D-ACA0-465F-A0EA-423DCCD7A2DA}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{2E1F011A-ED99-4F94-9DDC-D9C366BCE315}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{2EC4F531-8E88-4FD1-88AF-9A9BEB17825F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3210A18B-547A-4C6A-B573-88F74B004305}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3349EF40-4E8F-45CF-8B2C-7C9E38CCE70F}" = rport=137 | protocol=17 | dir=out | app=system |
"{3550797A-B5B6-4AB7-9FAD-2E1443D8B63A}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{36B0C72D-B6D0-4B30-B3E2-35441867645D}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{3C87A83A-189B-46B8-8D1E-7C7FAA027F37}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4CD8F9A5-3FB3-476E-82AF-53E6640514B4}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{4F0FB103-B598-4659-851F-8E264BE59628}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5CF7D003-6576-4D91-B9E0-27010ECBC0D6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5DCCCF59-46F0-413C-B23D-06175AB4FD8D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5E57BBF4-299F-4E75-9F8A-33869D36CE05}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6172185C-4904-4D5C-A39C-2429DAE15959}" = lport=10243 | protocol=6 | dir=in | app=system |
"{6206CDDD-E75D-47C1-831A-F141526218EE}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{682FE7AB-3277-422E-996B-98B966B59530}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{696DC390-3427-46D8-89E8-82335B2FAA20}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{7075B530-B2B7-43D2-B94F-67BA1C2A4EA4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{74CE2665-9D81-4367-89F9-8CC9F9F11710}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{74DAD6AA-93CB-49B4-90FC-7AA39F436CEF}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{76981A0C-1E02-44E5-9732-A1EB9C2A09DC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{794CA82E-4D96-4A94-A6E8-3422F8C4D565}" = lport=137 | protocol=17 | dir=in | app=system |
"{852EFA57-04B6-40DC-8041-4D3E420F5AB9}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{856328AD-8A59-4363-9352-62DC9088E70E}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{8B001BEA-BD17-4360-A640-650B65B32080}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{94A4ABB2-8FB5-42C5-BC21-85E220CED1B9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9D578920-CF37-4D09-A102-262986DA6BA4}" = lport=139 | protocol=6 | dir=in | app=system |
"{AC764799-6683-42D7-9DE3-6272FF96EC42}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B10941D0-CD9E-4A6F-B3E6-3D349E2093D9}" = rport=139 | protocol=6 | dir=out | app=system |
"{B224E128-740A-41DF-8175-EC25049D2329}" = rport=138 | protocol=17 | dir=out | app=system |
"{B61E2149-0456-4475-AFF1-52337D103003}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B6F4E743-B34E-4CE9-94E9-5FDD062BE836}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C86456B1-934A-437D-B2D9-7AEDE96F447A}" = lport=445 | protocol=6 | dir=in | app=system |
"{C937C1AA-D514-490D-A6F9-F2120D3FB9F1}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{D64CDC7A-2DB8-42AD-8217-82CC0C990A13}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DBB6C5DE-EA70-429E-A77C-11D97412A6C5}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DE8E7784-4F4B-4768-A88E-56C21707F146}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DEEC938B-0138-4A30-A88C-0B2CCC354D48}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E40E2DD3-772C-4B57-825A-C1E061E07410}" = rport=445 | protocol=6 | dir=out | app=system |
"{EDD1615C-7429-4E91-9B7D-9EF30B701964}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F6C8962D-252A-42B6-8155-3345C88C7E0A}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0847CD82-3ECE-4ECA-9F20-D7D9DB601B1E}" = protocol=6 | dir=in | app=c:\users\anthony moore\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{08BC066D-F34C-43B6-9E0C-85E54BC39372}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{0D14EEBE-14AC-4891-93AC-69798E9F3143}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{11F6B6A3-B9F0-4A25-8E24-FE597951907A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{25361E4E-2A4F-4E7D-ADF8-73EB6A22941B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2C98B899-8B9D-4F46-98C2-E977F322524C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{30F81B94-4636-4DAC-B8E9-613D8E2C98D6}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{38FF45DA-F758-4862-89B4-07912508BA4D}" = protocol=6 | dir=out | app=system |
"{3B11BD2D-E4D9-4BB4-A4A9-765D72B6196E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{404E586B-AA3F-46FC-9F4F-FAC0083A79ED}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{40BBB1C3-148C-49B3-ACFA-D46874A8F1DD}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{459B31BB-1274-4ABE-9D2F-F62447F17CBC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{45A51711-5DA2-42F6-86C0-00EF3834FC33}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{491E4CFB-3720-4276-858A-CE1BB0AB7EBF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{50550B42-1419-456A-9155-2E05C8295C8F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{51E3CD92-8BD7-4DDA-BA33-1777548D29DD}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{57D5F33D-E9C1-48CC-81F5-34759D6CFD1D}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{5A71B756-A298-4C28-843B-4EB795309C0A}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{6267736D-D6D5-4171-9148-E90655820F57}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{62E39F95-7266-49F1-A9AD-7D584F843890}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{668EC480-4C72-4748-B166-517E3AD5152F}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{6D2529E8-7854-42A2-B354-1EC7CD4BB497}" = dir=in | app=c:\program files\hp\hp photosmart 5510 series\bin\devicesetup.exe |
"{6E387F29-747E-4E42-A292-B94A2F317176}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8024D718-996F-4FA8-A152-5799EEA78838}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{80BB9C2A-D510-42D7-9440-1F09C2B6CB2D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{816FA92C-39A3-4EE5-A7B7-5C0F64F81B18}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{8463A3EC-FF3F-4DF3-B79C-01ECA0F08961}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{85201BE6-8518-4F66-9913-E684407C8BC5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{8D943B2E-75DF-4A29-AD64-BF8A2A01C62A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{946E8035-8236-4C15-A594-0682183D57C0}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9789BF2F-C050-4A2E-8838-6CBB680F72C7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9AD93C59-032C-4315-ABC0-DCF1E6A663EF}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{A084A05D-D3A9-440B-9D0C-34AAACBEA18A}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{ACA6DE1D-5803-487B-823A-FE229EA34F13}" = dir=in | app=c:\program files\hp\hp photosmart 5510 series\bin\hpnetworkcommunicator.exe |
"{ADB5E268-88CB-413E-92B8-20C263780A91}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B7405DB9-5557-4BC7-B3FB-EA3545401F76}" = protocol=17 | dir=in | app=c:\users\anthony moore\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{BE6363D8-15A7-4A10-8771-1D44456CD405}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C6F7527F-D225-4AE0-9C92-53127814AA08}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{CA169EBC-086E-456B-93C7-B20392F568B2}" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"{CF982D2B-AB2F-42A4-9C61-01D897C36171}" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"{CFFB259E-8286-4744-822D-1C5323126108}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{D53CDD83-1AE1-45A6-B265-3CAB9A34082C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D9CF7889-CDC1-4D30-8613-20B539004404}" = dir=in | app=c:\users\anthony moore\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{DC226B10-9377-41C2-8E6E-0293030F5F2B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E88B10FD-497A-4260-AE9D-1FACF5738F20}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{ECD5A992-0974-43F2-ACE8-FF9D58D254C6}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{F0960CB7-17BC-4EC2-8831-8E59327A8934}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F16B4793-09CA-4E8F-AB6A-FBA837E0174A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{F648FDAD-FCD6-464B-99D9-5F8722A0D788}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FBF3101D-FA5B-403F-A799-752895B0033A}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{FF610325-27D3-4464-8B1E-4FFA3FC7F3FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{2473F011-6993-40A3-A01A-7B2461DA85A9}C:\program files (x86)\virtualdj\virtualdj_home.exe" = protocol=6 | dir=in | app=c:\program files (x86)\virtualdj\virtualdj_home.exe |
"TCP Query User{4373AFDF-46FF-4BF1-9DE2-CD7D6BFAFDB8}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"TCP Query User{93B0748C-8832-43E5-A590-BCF54E1AAF45}C:\program files (x86)\frostwire\frostwire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"TCP Query User{94F81C33-C6B4-4374-AC0A-E7E224D46656}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{0DCC73E1-0CCD-4790-90E9-0E0FBCF966E5}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"UDP Query User{4C16CFCA-569B-483B-B557-2C8B8763F34E}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{8E0112E7-AC10-4A39-90F7-AAA53BC01EE6}C:\program files (x86)\frostwire\frostwire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"UDP Query User{DF2C8BCD-CDE2-432A-BCD1-1BAD63F9B7FE}C:\program files (x86)\virtualdj\virtualdj_home.exe" = protocol=17 | dir=in | app=c:\program files (x86)\virtualdj\virtualdj_home.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4807" = CanoScan LiDE 200 Scanner Driver
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{29E6A126-BB06-41CF-B12D-E6A56261328D}" = DisplayLink Core Software
"{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy DS3 driver version 0.6.0005
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}" = MobileMe Control Panel
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9174E097-FF65-4733-AA1E-E3067D3BF379}" = HP Photosmart 5510 series Product Improvement Study
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{EBF97BCD-7BA6-44B6-A8A7-358BA3592B09}" = HP Photosmart 5510 series Basic Device Software
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF426C13-3D2B-4FA3-A8ED-64F0597CBDE5}" = DisplayLink Graphics
"8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D" = Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"Dell Support Center" = Dell Support Center
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CA72D12-F6C6-4D43-A2A0-41F5AA17E2B6}" = Netflix in Windows Media Center
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{137EA7E1-D30B-4373-B8B6-CB7E85107F6D}" = Angry Birds Rio
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{23767F5D-A80C-4264-B8EA-ED4085FC332A}" = Adobe Illustrator CS5.1
"{2515EAA9-AE9F-4F0A-8301-B40034838B8A}" = Livestream Procaster
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{415FA9AD-DA10-4ABE-97B6-5051D4795C90}" = HP FWUpdateEDO2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5E1375CB-6792-4464-8715-CC3EC83D48FA}" = VirtualDJ Home FREE
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{75AE638F-750A-11DF-96D5-005056806466}" = Google Earth Plug-in
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79872596-B887-E700-8D56-CADBC78BA5DE}" = Adobe Download Assistant
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7FB413C8-3CAD-49F7-A67C-6EFEB4B04050}" = LogMeIn Hamachi
"{81F1814D-8658-72CC-D370-A08E1014EF03}" = Pandora
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9262B08F-E183-4FED-A2BD-23FF1A84EB67}" = HPDiagnosticCoreDll
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{975C3A93-2491-3D44-A071-F6CBF153E46D}" = Google Talk Plugin
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D3D1D696-84A8-465A-BC61-CDAC852B24CD}_is1" = Pod to PC 4.004
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA94A899-F439-44D1-90B6-DB02A7341170}" = BlackBerry Desktop Software 7.0
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E02964EA-0E1B-4620-A26E-CBAB0341B1BB}" = HP Photosmart 5510 series Help
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}" = Windows Media Center Add-in for Flash
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E6015AB2-13D1-4136-819B-51874DC307F5}" = ITCH
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FC7E771F-8170-4573-825D-EDB6723C804F}_is1" = Disk Speedup
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Any Video Converter Professional_is1" = Any Video Converter Professional 3.4.0
"avast" = avast! Free Antivirus
"BlackBerry_Desktop" = BlackBerry Desktop Software 7.0
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1" = Pandora
"DAZ Content Management Service [removed]" = DAZ Content Management Service
"Dell Webcam Central" = Dell Webcam Central
"DivX Setup" = DivX Setup
"DS4 Default Content [removed]" = DS4 Default Content
"GoToAssist" = GoToAssist 8.0.0.514
"HP Photo Creations" = HP Photo Creations
"IcoFX 2_is1" = IcoFX 2.2.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Mozilla Firefox 5.0.1 (x86 en-US)" = Mozilla Firefox 5.0.1 (x86 en-US)
"Pen Tablet Driver" = Pen Tablet
"RealPlayer 15.0" = RealPlayer
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"StepMania" = StepMania 3.9a (remove only)
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.11
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{C8B70875-4FEF-4830-A147-D160833FB097}SanDisk_ImageVault_Manager.exe" = SanDisk_ImageVault_Manager.exe
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/18/2011 4:05:14 PM | Computer Name = AnthonyMoore-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/18/2011 4:05:46 PM | Computer Name = AnthonyMoore-PC | Source = Google Update | ID = 20
Description =

Error - 11/18/2011 4:16:46 PM | Computer Name = AnthonyMoore-PC | Source = Google Update | ID = 20
Description =

Error - 11/18/2011 4:18:26 PM | Computer Name = AnthonyMoore-PC | Source = Google Update | ID = 20
Description =

Error - 11/18/2011 4:28:46 PM | Computer Name = AnthonyMoore-PC | Source = Microsoft-Windows-EapHost | ID = 2002
Description = Skipping: Eap method DLL path validation failed. Error: typeId=17,
authorId=9, vendorId=0, vendorType=0

Error - 11/18/2011 4:28:46 PM | Computer Name = AnthonyMoore-PC | Source = Microsoft-Windows-EapHost | ID = 2002
Description = Skipping: Eap method DLL path validation failed. Error: typeId=25,
authorId=9, vendorId=0, vendorType=0

Error - 11/18/2011 4:28:46 PM | Computer Name = AnthonyMoore-PC | Source = Microsoft-Windows-EapHost | ID = 2002
Description = Skipping: Eap method DLL path validation failed. Error: typeId=43,
authorId=9, vendorId=0, vendorType=0

Error - 11/18/2011 4:28:46 PM | Computer Name = AnthonyMoore-PC | Source = Microsoft-Windows-EapHost | ID = 2002
Description = Skipping: Eap method DLL path validation failed. Error: typeId=17,
authorId=9, vendorId=0, vendorType=0

Error - 11/18/2011 4:28:46 PM | Computer Name = AnthonyMoore-PC | Source = Microsoft-Windows-EapHost | ID = 2002
Description = Skipping: Eap method DLL path validation failed. Error: typeId=25,
authorId=9, vendorId=0, vendorType=0

Error - 11/18/2011 4:28:46 PM | Computer Name = AnthonyMoore-PC | Source = Microsoft-Windows-EapHost | ID = 2002
Description = Skipping: Eap method DLL path validation failed. Error: typeId=43,
authorId=9, vendorId=0, vendorType=0

[ Broadcom Wireless LAN Events ]
Error - 7/5/2012 11:27:40 PM | Computer Name = AnthonyMoore-PC | Source = WLAN-Tray | ID = 0
Description = 20:24:02, Thu, Jul 05, 12 Error - Unable to gain access to user store


Error - 7/9/2012 4:27:44 AM | Computer Name = AnthonyMoore-PC | Source = WLAN-Tray | ID = 0
Description = 01:27:43, Mon, Jul 09, 12 Error - Unable to gain access to user store


Error - 7/11/2012 5:31:09 PM | Computer Name = AnthonyMoore-PC | Source = WLAN-Tray | ID = 0
Description = 14:28:30, Wed, Jul 11, 12 Error - Unable to gain access to user store


[ Dell Events ]
Error - 1/20/2011 2:25:12 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/20/2011 2:28:51 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 1/20/2011 2:28:51 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/24/2011 2:50:00 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/24/2011 2:50:00 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/24/2011 4:51:58 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/24/2011 4:51:58 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/2/2011 8:19:56 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 3/2/2011 8:19:56 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 6/3/2011 3:23:15 PM | Computer Name = AnthonyMoore-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

[ Media Center Events ]
Error - 6/4/2011 12:15:32 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 9:15:26 AM - Error connecting to the internet. 9:15:26 AM - Unable
to contact server..

Error - 6/5/2011 1:28:24 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 10:28:23 AM - Error connecting to the internet. 10:28:24 AM - Unable
to contact server..

Error - 6/5/2011 1:28:59 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 10:28:32 AM - Error connecting to the internet. 10:28:32 AM - Unable
to contact server..

Error - 6/20/2011 4:00:36 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 1:00:31 PM - Error connecting to the internet. 1:00:31 PM - Unable
to contact server..

Error - 8/15/2011 3:10:24 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 12:10:24 PM - Error connecting to the internet. 12:10:24 PM - Unable
to contact server..

Error - 8/15/2011 3:10:31 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 12:10:29 PM - Error connecting to the internet. 12:10:29 PM - Unable
to contact server..

Error - 8/16/2011 6:29:31 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 3:29:31 PM - Error connecting to the internet. 3:29:31 PM - Unable
to contact server..

Error - 8/16/2011 6:29:45 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 3:29:36 PM - Error connecting to the internet. 3:29:36 PM - Unable
to contact server..

Error - 9/3/2011 3:31:51 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 12:31:46 PM - Error connecting to the internet. 12:31:46 PM - Unable
to contact server..

Error - 9/3/2011 4:33:24 PM | Computer Name = AnthonyMoore-PC | Source = MCUpdate | ID = 0
Description = 1:33:00 PM - Error connecting to the internet. 1:33:00 PM - Unable
to contact server..

[ System Events ]
Error - 7/11/2012 6:09:37 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:01 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:01 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:01 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:01 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:01 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:01 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:44 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:44 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 7/11/2012 6:11:44 PM | Computer Name = AnthonyMoore-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068


< End of report >
Hello tehgreyghost and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your logs now and will reply with instructions shortly.

Satchfan
Hello again tehgreyghost

A couple of things before we start:

Running multiple antivirus programs

The computer is probably behaving a bit “buggy” because there are 2 antivirus programs running.

You can not run two real-time antiviruses at the same time. Although many have different methods of searching for and recognising threats, they will all be 'fighting' in memory to kick each other out, rendering them all ineffective.

Uninstall either Microsoft Security Essentials or Avast.

===================================================

P2P - I see P2P software, (UTorrent), installed on the machine and although we are not here to pass judgment on file-sharing as a concept, you should be aware that engaging in this activity and having this kind of software installed on the machine will always make it more susceptible to re-infection. If the computer is/was infected, it almost certainly contributed to the current situation.

Please note: Even if it is a "safe" P2P program, it is only the program that is safe. Sharing files from uncertified sources are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {ACF3F28D-177F-4E12-A348-47B907121FF9}
    IE:64bit: - HKLM\..\SearchScopes\{ACF3F28D-177F-4E12-A348-47B907121FF9}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
    IE - HKLM\..\SearchScopes,DefaultScope = {AC153DD4-32EA-443A-BF42-D3EE4410897B}
    IE - HKLM\..\SearchScopes\{AC153DD4-32EA-443A-BF42-D3EE4410897B}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
    IE - HKCU\..\SearchScopes,DefaultScope = {AC153DD4-32EA-443A-BF42-D3EE4410897B}
    IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…D2-518A23437EC0
    IE - HKCU\..\SearchScopes\{AC153DD4-32EA-443A-BF42-D3EE4410897B}: "URL" = http://www.bing.com/search?FORM=IEFM1&…ferrer:source?}
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678
    IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
    O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found
    O2 - BHO: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===================================================

Run Farbar Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.
  • make sure the following options are checked:
    • Internet Services
    • Windows Firewallsfc
    • System Restore
    • Security Center
    • Windows Update
  • press "Scan".
  • it will create a log (FSS.txt) in the same directory the tool is run.
  • please copy and paste the log to your reply.
===================================================

I see that you have run ComboFix which is not recommended. While you may see ComboFix being used quite often without incident, the tool should not be run unsupervised (as stated in the Disclaimer that is first displayed by ComboFix when you run the tool).

It is a very powerful tool which, when improperly used, may render your machine a doorstop.

Please send the log from when you ran it. ComboFix logs are located at c:\combofix.txt, older logs are at c:\qoobox\combofix2.txt, c:\qoobox\ComboFix3.txt etc

Logs to also include in the next post:

OTL fix log
New OTL log
FSS.txt


Thanks

Satchfan
It has been several days since I replied to your request for help with your computer problems. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI