This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Mystart Incredibar Infection [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone,

My name is Ryan and I have infected my PC with the Mystart Incredibar virus. After a system recovery, I am still infected! Can someone PLEASE HELP ME??!! I'm pretty good at following instructions but no where near as technically savvy.

I have found similar forums on this website with people who have dealt with the same infection. Suggestions were to first run OTL. Here are the logs:


OTL logfile created on: 8/2/2012 11:34:35 AM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Ryan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

9.99 Gb Total Physical Memory | 7.00 Gb Available Physical Memory | 70.03% Memory free
19.98 Gb Paging File | 16.59 Gb Available in Paging File | 83.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1385.37 Gb Total Space | 1345.25 Gb Free Space | 97.10% Space Free | Partition Type: NTFS
Drive D: | 11.51 Gb Total Space | 1.41 Gb Free Space | 12.23% Space Free | Partition Type: NTFS

Computer Name: RYAN-HP | User Name: Ryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/02 11:23:28 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Users\Ryan\Downloads\OTL.exe
PRC - [2012/08/02 10:35:44 | 000,180,648 | —- | M] (Google Inc.) – C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
PRC - [2011/02/01 03:49:44 | 001,127,448 | —- | M] (PDF Complete Inc) – C:\Program Files (x86)\PDF Complete\pdfsvc.exe
PRC - [2011/01/25 19:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2010/11/26 09:09:12 | 000,399,344 | —- | M] (Roxio) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/11/23 22:31:24 | 002,069,504 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
PRC - [2010/03/18 16:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2009/08/24 21:11:16 | 000,656,896 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
PRC - [2009/02/27 21:13:04 | 000,053,248 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
PRC - [2008/11/20 12:47:28 | 000,062,768 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe


========== Modules (No Company Name) ==========

MOD - [2012/07/31 00:36:14 | 000,442,392 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppgooglenaclpluginchrome.dll
MOD - [2012/07/31 00:36:13 | 012,235,288 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
MOD - [2012/07/31 00:36:12 | 003,997,720 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll
MOD - [2012/07/31 00:34:57 | 000,526,872 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\libglesv2.dll
MOD - [2012/07/31 00:34:55 | 000,104,984 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\libegl.dll
MOD - [2012/07/31 00:34:45 | 000,144,424 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\avutil-51.dll
MOD - [2012/07/31 00:34:43 | 000,266,792 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\avformat-54.dll
MOD - [2012/07/31 00:34:42 | 002,480,680 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\avcodec-54.dll
MOD - [2009/02/27 21:13:04 | 000,053,248 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
MOD - [2009/02/19 19:22:50 | 000,028,672 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\WMINPUT.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2011/02/17 00:47:28 | 000,682,040 | —- | M] (Hewlett-Packard) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe – (HPAuto)
SRV:64bit: - [2011/01/14 01:48:22 | 000,354,304 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2011/01/14 01:08:19 | 000,203,776 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2010/10/11 04:48:14 | 000,346,168 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe – (HPClientSvc)
SRV:64bit: - [2010/09/22 20:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/06/17 07:23:36 | 000,194,496 | —- | M] (Advanced Micro Devices) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe – (AMD Reservation Manager)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/02/01 03:49:44 | 001,127,448 | —- | M] (PDF Complete Inc) [Auto | Running] – C:\Program Files (x86)\PDF Complete\pdfsvc.exe – (pdfcDispatcher)
SRV - [2011/01/25 19:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2011/01/25 15:56:32 | 000,241,648 | —- | M] (CyberLink) [Auto | Stopped] – c:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe – (CLKMSVC10_38F51D56)
SRV - [2010/11/26 09:09:12 | 000,399,344 | —- | M] (Roxio) [Auto | Running] – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe – (RoxioNow Service)
SRV - [2010/10/12 12:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/03/18 16:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2011/05/25 17:50:58 | 001,843,712 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HCW723x.sys – (HCW723x)
DRV:64bit: - [2011/01/14 03:19:26 | 008,283,136 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2011/01/14 00:31:00 | 000,293,888 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2010/12/28 14:45:54 | 000,412,776 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010/11/20 22:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 22:23:47 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 22:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/11/20 22:23:47 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/17 09:04:32 | 000,115,216 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2010/11/04 23:57:54 | 001,041,760 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr28x.sys – (netr28x)
DRV:64bit: - [2010/03/10 10:33:52 | 000,016,440 | —- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AtiPcie64.sys – (AtiPcie)
DRV:64bit: - [2010/02/18 11:18:24 | 000,046,136 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\amdiox64.sys – (amdiox64)
DRV:64bit: - [2009/12/22 04:26:36 | 000,038,456 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:47:48 | 000,023,104 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 21:32:26 | 000,231,224 | —- | M] (Advanced Micro Devices, Inc) [Kernel | Boot | Stopped] – C:\Windows\SysNative\drivers\ahcix64s.sys – (ahcix64s)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPDTDF
IE:64bit: - HKLM\..\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPDTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPDTDF
IE - HKLM\..\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPDTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}






IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPDTDF
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPDTDF
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/05/19 02:18:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/05/19 02:18:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/05/19 02:18:09 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe File not found
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe (Hewlett-Packard)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4:64bit: - HKLM..\RunOnce: [NoIE4StubProcessing] C:\Windows\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4067204-96CB-4B7F-AD13-0F5BA948B803}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/08/02 11:22:46 | 000,000,000 | —D | C] – C:\Windows\LastGood
[2012/08/02 11:04:17 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/08/02 10:51:24 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/08/02 10:35:46 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Google
[2012/08/02 10:33:42 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Apps
[2012/08/02 10:33:40 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Deployment
[2012/08/02 10:27:42 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2012/08/02 10:27:41 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2012/08/02 10:16:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2012/08/02 10:16:32 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/08/02 10:11:48 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/08/02 10:11:48 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/08/02 10:11:48 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/08/02 10:11:41 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/08/02 10:11:41 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/08/02 10:11:41 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/08/02 10:10:42 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/08/02 10:10:42 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/08/02 10:04:39 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Adobe
[2012/08/02 10:00:05 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\AMD
[2012/08/02 09:59:57 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\ATI
[2012/08/02 09:59:57 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\ATI
[2012/08/01 22:50:23 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2012/08/01 22:48:59 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\PDFC
[2012/08/01 22:48:43 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/08/01 22:48:43 | 000,000,000 | R–D | C] – C:\Users\Ryan\Searches
[2012/08/01 22:48:43 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/08/01 22:48:43 | 000,000,000 | -H-D | C] – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/08/01 22:48:35 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Identities
[2012/08/01 22:48:32 | 000,000,000 | R–D | C] – C:\Users\Ryan\Contacts
[2012/08/01 22:48:31 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\VirtualStore
[2012/08/01 22:48:06 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\RemEngine
[2012/08/01 22:43:14 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Hewlett-Packard
[2012/08/01 22:43:06 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Hewlett-Packard
[2012/08/01 22:42:51 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Hewlett-Packard_Company
[2012/08/01 22:42:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP User Manuals
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\AppData\Local\Temporary Internet Files
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Templates
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Start Menu
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\SendTo
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Recent
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\PrintHood
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\NetHood
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Documents\My Videos
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Documents\My Pictures
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Documents\My Music
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\My Documents
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Local Settings
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\AppData\Local\History
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Cookies
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Application Data
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\AppData\Local\Application Data
[2012/08/01 22:41:52 | 000,000,000 | –SD | C] – C:\Users\Ryan\AppData\Roaming\Microsoft
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Videos
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Saved Games
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Pictures
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Music
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Links
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Favorites
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Downloads
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Documents
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Desktop
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/08/01 22:41:52 | 000,000,000 | -H-D | C] – C:\Users\Ryan\AppData
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Temp
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Microsoft
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Media Center Programs
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Macromedia
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\HuluDesktop
[2012/08/01 22:41:15 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2012/08/01 15:08:05 | 000,000,000 | —D | C] – C:\ProgramData\Recovery
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/02 11:36:06 | 000,791,672 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/02 11:36:06 | 000,659,626 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/08/02 11:36:06 | 000,120,656 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/08/02 11:20:29 | 000,775,334 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/02 10:40:01 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001UA.job
[2012/08/02 10:40:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001Core.job
[2012/08/02 10:21:28 | 000,024,400 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/02 10:21:28 | 000,024,400 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/02 10:17:17 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/08/02 10:15:14 | 000,000,328 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForRyan.job
[2012/08/02 10:15:13 | 000,276,072 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/02 10:14:53 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/02 10:14:30 | 3751,718,911 | -HS- | M] () – C:\hiberfil.sys
[2012/08/02 10:04:31 | 000,001,439 | —- | M] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/02 00:41:04 | 000,108,227 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2012/08/02 00:41:04 | 000,108,227 | —- | M] () – C:\Windows\SysNative\license.rtf
[2012/08/01 22:42:22 | 000,000,000 | RHS- | M] () – C:\Windows\SysWow64\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK
[2012/08/01 22:42:22 | 000,000,000 | RHS- | M] () – C:\Windows\SysNative\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/02 10:35:53 | 000,000,904 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001UA.job
[2012/08/02 10:35:48 | 000,000,852 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001Core.job
[2012/08/02 10:17:10 | 000,001,917 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/02 10:11:48 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2012/08/02 10:04:30 | 000,001,439 | —- | C] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/01 22:48:52 | 000,001,411 | —- | C] () – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/08/01 22:48:44 | 000,001,445 | —- | C] () – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/08/01 22:48:22 | 000,000,328 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForRyan.job
[2012/08/01 22:42:54 | 000,002,312 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Download Store.lnk
[2012/08/01 22:42:54 | 000,002,278 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Trials for QuickBooks, Quicken and TurboTax.lnk
[2012/08/01 22:42:53 | 000,002,126 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snapfish.lnk
[2012/08/01 22:42:53 | 000,001,858 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Install Rhapsody.lnk
[2012/08/01 22:42:28 | 000,001,787 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warranty.lnk
[2012/08/01 22:42:25 | 3751,718,911 | -HS- | C] () – C:\hiberfil.sys
[2012/08/01 22:42:22 | 000,000,000 | RHS- | C] () – C:\Windows\SysWow64\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK
[2012/08/01 22:42:22 | 000,000,000 | RHS- | C] () – C:\Windows\SysNative\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK
[2012/08/01 22:41:52 | 000,001,974 | —- | C] () – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hulu Desktop.lnk
[2012/08/01 22:41:52 | 000,000,290 | —- | C] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/08/01 22:41:52 | 000,000,272 | —- | C] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/19 01:44:25 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/05/19 01:39:39 | 000,002,975 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/03/03 23:04:58 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2011/02/11 12:15:43 | 000,775,334 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\SoftwareDistribution\Download\71d84967e1e9a8a414d570c6caa8bb08\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\SoftwareDistribution\Download\71d84967e1e9a8a414d570c6caa8bb08\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\SoftwareDistribution\Download\71d84967e1e9a8a414d570c6caa8bb08\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 22:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\SysWOW64\explorer.exe
[2010/11/20 22:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SoftwareDistribution\Download\71d84967e1e9a8a414d570c6caa8bb08\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 22:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\explorer.exe
[2010/11/20 22:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 22:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 22:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 22:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 22:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< End of report >
================================================================================
=================================================================================
=======================================

Extras.txt

OTL Extras logfile created on: 8/2/2012 11:34:35 AM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Ryan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

9.99 Gb Total Physical Memory | 7.00 Gb Available Physical Memory | 70.03% Memory free
19.98 Gb Paging File | 16.59 Gb Available in Paging File | 83.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1385.37 Gb Total Space | 1345.25 Gb Free Space | 97.10% Space Free | Partition Type: NTFS
Drive D: | 11.51 Gb Total Space | 1.41 Gb Free Space | 12.23% Space Free | Partition Type: NTFS

Computer Name: RYAN-HP | User Name: Ryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03BFCDE4-F11C-4F54-BA1A-2384CE329066}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{146A9241-BA44-40DF-B556-A2C9BFAAE58B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{3099B085-5A4D-494A-B9E7-437BA9BDC430}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{511BC695-A748-45B5-A6F8-4C6B4861E9A8}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{54235B99-6E9B-4F18-A35B-44DBE9CF899B}" = rport=138 | protocol=17 | dir=out | app=system |
"{672348EE-108D-45F8-A68F-AF4FBBEAB547}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8B671060-B37C-4958-AFB7-E83B0127DDED}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8C24617C-20CD-4349-AE75-1E7B48A604B2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{91F393F7-1186-4ED4-AB24-FABA16675B1A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{940DDE15-EFC2-4D16-828A-B72BADFD5595}" = lport=139 | protocol=6 | dir=in | app=system |
"{9964557E-D4F7-418F-B1B1-F3F195C515F2}" = lport=137 | protocol=17 | dir=in | app=system |
"{9DDA6CD8-0424-4FB2-9FDD-C072D739188D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9E54D205-46E3-48C2-920D-30C1D1B6DCF4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AA062764-A67A-4460-9BD6-62A2694D0CD2}" = lport=138 | protocol=17 | dir=in | app=system |
"{ABF07D3F-942F-4A6C-B9AD-332B1C258D05}" = lport=445 | protocol=6 | dir=in | app=system |
"{AD4CB13F-15F4-4CAF-9617-DCC4C3368368}" = rport=445 | protocol=6 | dir=out | app=system |
"{B01546FA-802B-4E20-A219-A3621BCDE544}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{BE05498B-D1DA-43CF-BBCA-C5F4276EF8B9}" = rport=139 | protocol=6 | dir=out | app=system |
"{C13FB359-4F9F-4C8C-8D45-F33DDE678837}" = rport=137 | protocol=17 | dir=out | app=system |
"{C58AE5F0-CBD1-4233-A2DC-9075BA854F2A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C636513E-6F47-4482-A7B9-197F61E0E77A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{CE3583DF-5D3C-4A6A-BF58-579CC84F9BC7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D78A3E6D-04FD-4DE6-8590-EDF1FD258AA3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02FED32F-2F49-4930-B38B-189FF69653B9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{043032A8-5408-4561-908E-97C4842C0079}" = protocol=17 | dir=out | app=c:\program files (x86)\hewlett-packard\hp linkup\hp linkup viewer.exe |
"{0DA05F99-66DD-4E2D-9975-0F39A0CD85B3}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\remote graphics receiver\rgreceiver.exe |
"{1BBD20A0-3526-4C2D-AD75-BCB4B52FC4B2}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{2DA5EDEC-6263-489D-92FA-51A96A8037F3}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{3345F198-0420-475B-A504-3CAA967F866C}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{35CB186C-70F8-4139-AC0F-76692F23CFCF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{38EA375B-4F93-44D5-95DA-A4D123648F30}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3B46A9F5-34E3-4530-B7D7-875A0A30C4DD}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{44DDF8E4-9E43-47F2-BC0C-CB12BB970CCA}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\hp linkup\hp linkup viewer.exe |
"{4649CCA4-D7B1-4AA6-BE23-C2DBEA0C44FB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{48DC9BF5-68DB-4FB4-BE6C-0EAEEC2DBF97}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{4A5B3EBE-7845-4B28-9BB7-7F47E4BAD010}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{5C951F31-2E58-4AB1-B000-C036BB1DA7F6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6506A109-D04E-44F7-88F9-9F880237DCA5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6ACA1DD5-992D-4C6F-8608-D1643E6A2113}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{70C220F1-B868-4785-8F52-88D0CB2F28FF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{74E6CAA4-1A84-458D-AEFB-E03EA19EBA3F}" = protocol=6 | dir=out | app=c:\program files (x86)\hewlett-packard\remote graphics receiver\rgreceiver.exe |
"{88A2AC04-9BB4-4BDE-A136-86B3E6AEC459}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9308C6CD-553A-4542-B168-C40FAC256D40}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9A875E70-A19A-466B-BA86-025378A3B8BA}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{9E6EB85D-292C-478C-B567-548934E3FBD6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B8B96FEA-65EB-449E-897A-A86FD6E54095}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BEEA5B1A-DA9F-48C6-ABA5-5E845BDFB97B}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{C20E7C48-4B5A-4CA4-A754-9E6115C2E2E0}" = protocol=6 | dir=out | app=system |
"{CB31AD5F-49CF-45BC-ACE2-4540D89B902D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D909552C-F8CF-4064-B8CE-4D42254D2558}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{DC05055B-3144-452C-9D87-C8FA2A700342}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E6CBC78B-FF76-4480-9F04-6669F8F288C7}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{EFC1D59D-2413-4A69-A4CD-FD8E8A5FDA8D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{FC9DF383-4C55-4603-BF10-F1563F026B68}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FE70042F-053F-451B-AB26-7D6C614F0E2F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6DF9E1C7-03B7-5C47-CB3E-14FE26F64208}" = ccc-utility64
"{80C27FE9-C6C4-F5C8-EAD3-09E7E0102E78}" = ATI Stream SDK v2 Developer
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A6AD916-D45D-1D1C-E2C0-A0402F511999}" = ATI Catalyst Install Manager
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D0F15985-E075-603D-0E57-FE660F5D1641}" = AMD Fuel
"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{09206233-DD78-9A4A-C353-2BB0C929F278}" = CCC Help Dutch
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{16FC3056-90C0-4757-8A68-64D8DA846ADA}" = Remote Graphics Receiver
"{18BBF24A-6D04-4CA4-B6B4-1CF372162EEC}" = Adobe Flash Player 10 ActiveX
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AB0ECE0-6C4E-D1C1-1938-94C71D15048C}" = CCC Help English
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{210A03F5-B2ED-4947-B27E-516F50CBB292}" = HP Setup
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2DDE6358-5FA7-5CBB-61D0-AA2F978C0429}" = CCC Help Chinese Standard
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{338A3DCB-73A0-A5B4-6804-3B86FC813633}" = CCC Help Finnish
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{40891BCF-BECD-85D6-1F39-4673BC6ED83C}" = CCC Help Chinese Traditional
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{465210C4-595A-BD80-44E8-E0457D9D8432}" = Zinio Reader 4
"{4E8A9057-7408-2CCD-8FBC-A6B471168915}" = CCC Help Russian
"{503D2892-F893-FE4D-14CA-E7A85B494E21}" = ccc-core-static
"{558FAB16-D037-8CF6-9BE8-F006EBD7164D}" = CCC Help Portuguese
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5D8F85FF-F8DB-67C6-4B8B-63ABD9941B56}" = CCC Help Norwegian
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{6567B288-1B84-339D-F2AA-9D3B944A3796}" = CCC Help Italian
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71AF3635-8308-2C6B-8E7D-ADF23908FF96}" = CCC Help Polish
"{71F637DF-9F6A-FA63-3F64-F48358FF3C35}" = CCC Help Danish
"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform
"{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}" = HP Support Information
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{912CED74-88D3-4C5B-ACB0-132318649765}" = PressReader
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9368DDD5-CE7F-4BD7-A83A-F00FABE338EC}" = Blio
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BC3E09E-3359-CA32-1EBD-0A6C52F86A16}" = CCC Help French
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B40D7926-AE5F-41EA-8AC6-56C0E2F00E9D}" = HP Keyboard
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{BB760C1D-98F4-4E38-8CC4-3B67329AA981}" = HP MediaSmart/TouchSmart Netflix
"{C1AD9241-3ADD-483F-914D-071F3E50855A}" = HP LinkUp
"{C1F02811-5F08-4C56-EB19-3BC8E35349CE}" = CCC Help German
"{C2B28BD1-31C9-8CF2-6FC4-0DAC190CA60D}" = CCC Help Czech
"{C3F434FD-D18E-3D81-D39E-C90C23B57262}" = CCC Help Korean
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CC3A3FA8-AFF4-FA63-058C-8D7A3770F2F6}" = HydraVision
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D538DDC7-E97A-7B4F-2A7E-06DC0B689E62}" = CCC Help Swedish
"{D73CCCC8-73DE-12E9-BC14-EE228BCFB39F}" = CCC Help Thai
"{D8751CD1-8DDF-18F4-C88A-B649AE688030}" = Catalyst Control Center Localization All
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DFD599F4-A171-4D4A-9859-BC6B076CF9FE}" = Catalyst Control Center - Branding
"{E08D23A3-1BDE-C2EE-816C-979DEF9646AA}" = Catalyst Control Center InstallProxy
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E92D47A1-D27D-430A-8368-0BAFD956507D}" = HP Support Assistant
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED0FF084-670F-ED50-E339-2EABB695E2A8}" = CCC Help Hungarian
"{EFF8D3C7-64F6-2895-7C96-A39DB53FD943}" = CCC Help Japanese
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F61F7CBD-2BCC-E7B1-9567-8784C492F1DB}" = CCC Help Spanish
"{F7E8E188-6112-64EB-9EC6-844DCA3525E3}" = CCC Help Greek
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"HP Remote Solution" = HP Remote Solution
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"Kobo" = Kobo
"PDF Complete" = PDF Complete Special Edition
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087393" = Mah Jong Medley
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087415" = Wheel of Fortune 2
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"WT089453" = Bejeweled 2 Deluxe
"WT089454" = Chuzzle Deluxe
"WT089455" = Zuma Deluxe
"WT089457" = Slingo Supreme
"WT089458" = Plants vs. Zombies - Game of the Year
"WT089470" = FATE - The Traitor Soul
"WT089484" = Namco All-Stars PAC-MAN
"WT089496" = Mystery P.I. - Stolen in San Francisco
"WT089498" = Bejeweled 3
"ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1" = Zinio Reader 4

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1887079324-3387887618-774918653-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/2/2012 11:10:27 AM | Computer Name = Ryan-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 8/2/2012 11:10:27 AM | Computer Name = Ryan-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

Error - 8/2/2012 11:11:49 AM | Computer Name = Ryan-HP | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation
was canceled. You canceled the Security Essentials installation on your computer.
Error code:0x8004FF0A.

Error - 8/2/2012 11:15:33 AM | Computer Name = Ryan-HP | Source = WinMgmt | ID = 10
Description =

Error - 8/2/2012 11:34:23 AM | Computer Name = Ryan-HP | Source = Windows Backup | ID = 4104
Description =

Error - 8/2/2012 11:42:05 AM | Computer Name = Ryan-HP | Source = Microsoft-Windows-Backup | ID = 517
Description = The backup operation that started at '2012-08-02T15:29:32.729049800Z'
has failed with following error code '2147942421' (%%2147942421). Please review
the event details for a solution, and then rerun the backup operation once the
issue is resolved.

Error - 8/2/2012 11:42:07 AM | Computer Name = Ryan-HP | Source = Windows Backup | ID = 4104
Description =

Error - 8/2/2012 11:46:38 AM | Computer Name = Ryan-HP | Source = Windows Backup | ID = 4104
Description =

Error - 8/2/2012 11:54:44 AM | Computer Name = Ryan-HP | Source = Microsoft-Windows-Backup | ID = 517
Description = The backup operation that started at '2012-08-02T15:42:25.479648200Z'
has failed with following error code '2147942421' (%%2147942421). Please review
the event details for a solution, and then rerun the backup operation once the
issue is resolved.

Error - 8/2/2012 11:54:47 AM | Computer Name = Ryan-HP | Source = Windows Backup | ID = 4104
Description =

[ System Events ]
Error - 8/2/2012 11:34:23 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:45:01 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:45:12 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:45:24 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:45:37 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:45:50 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:46:02 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:46:14 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:46:28 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.

Error - 8/2/2012 11:46:38 AM | Computer Name = Ryan-HP | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.


< End of report >
Hello rhull83 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your logs now and will reply with instructions shortly.

Satchfan
Hi Ryan

Ask Toolbar

Uninstall Ask Toolbar if it was not installed on purpose.

See here for more info.

If you choose to follow my recommendation then please uninstall the following programs if present:

Ask Toolbar or anything related to Ask

======================================================

After looking at your log, I'd like you to run another couple of scans as I can see no sign of the problem you are saying exists.

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Please include the following in your next post :

DDS.txt
Attach.txt
aswMBR log


Can you tell me how you think/know Incredibar is on your computer.

Thanks

Satchfan
Satchfan, Thank you for responding to my post. I will try to address you question on how I know I still have the Mystart virus. After getting the virus and being unsuccessful at removing it, I performed a system restore on my HP to reset the computer to factory defaults. All seemed well. Once I downloaded and installed Google Chrome, Mystart kicked back in. Anytime I open Chrome, two tabs open; my home page tab, and the Mystart tab. I changed the settings in Chrome to where it no longer opens both tabs and doesn't use the Mystart search engine. But I am still weary that I may have the virus as anit-malware scans prior to system restoring did not expose the virus. I don't know why my log is showing that the Ask toolbar is installed. It is not in my programs list in Add/Remove Programs. Also, it is not on IE8 or Chrome. I did not install it after system recovery. Here are the logs that you have requested: DDS (Attach.txt zipped and uploaded) . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 Run by [removed] at 20:20:28 on 2012-08-02 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.10232.8630 [GMT -5:00] . AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\PDF Complete\pdfsvc.exe C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\WUDFHost.exe C:\Windows\system32\atieclxx.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Users\Ryan\Downloads\OTL.exe C:\Windows\system32\taskhost.exe C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.115\GoogleCrashHandler.exe C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.115\GoogleCrashHandler64.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\taskhost.exe C:\Users\Ryan\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ mWinlogon: Userinit=userinit.exe BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [Google Update] "C:\Users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe" /c mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [] mRun: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe mRun: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe mRun: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRunOnce: [!BingBar] "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\MUExe\7.1.361.0\BingBarSetup-Partner.EXE" /C:"BBSetup.exe cabLocation=.\BingBarPartnerConfig.cab ismu=2" mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{E4067204-96CB-4B7F-AD13-0F5BA948B803} : DhcpNameServer = 192.168.1.1 Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO-X64: Search Helper - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll TB-X64: @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun-x64: [(Default)] mRun-x64: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe mRun-x64: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe mRun-x64: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe mRun-x64: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRunOnce-x64: [!BingBar] "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\MUExe\7.1.361.0\BingBarSetup-Partner.EXE" /C:"BBSetup.exe cabLocation=.\BingBarPartnerConfig.cab ismu=2" . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-1-14 354304] R2 AMD Reservation Manager;AMD Reservation Manager;C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-6-17 194496] R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040] R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-1-25 92216] R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-5-19 1127448] R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344] R3 amdiox64;AMD IO Driver;C:\Windows\system32\drivers\amdiox64.sys –> C:\Windows\system32\drivers\amdiox64.sys [?] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?] R3 HCW723x;Hauppauge WinTV 723x PCIe Card;C:\Windows\system32\DRIVERS\HCW723x.sys –> C:\Windows\system32\DRIVERS\HCW723x.sys [?] R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys –> C:\Windows\system32\DRIVERS\netr28x.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\drivers\usbfilter.sys –> C:\Windows\system32\drivers\usbfilter.sys [?] S0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys –> C:\Windows\system32\DRIVERS\ahcix64s.sys [?] S2 CLKMSVC10_38F51D56;CyberLink Product - 2011/05/19 00:16:33;C:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe [2011-1-25 241648] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?] S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-08-02 16:39:42 ——– d—–w- C:\Program Files (x86)\MSXML 4.0 2012-08-02 16:00:57 69000 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1FAA1F66-F8E1-406D-B3F2-67284A779923}\offreg.dll 2012-08-02 15:35:46 ——– d—–w- C:\Users\Ryan\AppData\Local\Google 2012-08-02 15:33:42 ——– d—–w- C:\Users\Ryan\AppData\Local\Apps 2012-08-02 15:33:40 ——– d—–w- C:\Users\Ryan\AppData\Local\Deployment 2012-08-02 15:27:42 77312 —-a-w- C:\Windows\System32\packager.dll 2012-08-02 15:27:41 67072 —-a-w- C:\Windows\SysWow64\packager.dll 2012-08-02 15:25:10 927800 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EDE7F9D1-951F-4EFD-9276-1DB4CB552257}\gapaengine.dll 2012-08-02 15:25:07 9133488 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1FAA1F66-F8E1-406D-B3F2-67284A779923}\mpengine.dll 2012-08-02 15:16:44 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client 2012-08-02 15:16:32 ——– d—–w- C:\Program Files\Microsoft Security Client 2012-08-02 15:11:48 2622464 —-a-w- C:\Windows\System32\wucltux.dll 2012-08-02 15:11:41 99840 —-a-w- C:\Windows\System32\wudriver.dll 2012-08-02 15:10:42 36864 —-a-w- C:\Windows\System32\wuapp.exe 2012-08-02 15:10:42 186752 —-a-w- C:\Windows\System32\wuwebv.dll 2012-08-02 15:00:05 ——– d—–w- C:\Users\Ryan\AppData\Local\AMD 2012-08-02 14:59:57 ——– d—–w- C:\Users\Ryan\AppData\Local\ATI 2012-08-02 03:48:59 ——– d—–w- C:\Users\Ryan\AppData\Local\PDFC 2012-08-02 03:48:31 ——– d—–w- C:\Users\Ryan\AppData\Local\VirtualStore 2012-08-02 03:48:06 ——– d—–w- C:\Users\Ryan\AppData\Local\RemEngine 2012-08-02 03:43:06 ——– d—–w- C:\Users\Ryan\AppData\Local\Hewlett-Packard 2012-08-02 03:42:51 ——– d—–w- C:\Users\Ryan\AppData\Local\Hewlett-Packard_Company 2012-08-01 20:08:05 ——– d—–w- C:\ProgramData\Recovery . ==================== Find3M ==================== . . ============= FINISH: 20:20:47.34 =============== ================================================================================ ================================================================================= ==================================== aswMBR Results aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-02 20:43:05 —————————– 20:43:05.139 OS Version: Windows x64 6.1.7601 Service Pack 1 20:43:05.139 Number of processors: 6 586 0xA00 20:43:05.141 ComputerName: RYAN-HP UserName: Ryan 20:43:07.851 Initialize success 20:46:49.348 AVAST engine defs: 12080201 21:08:30.715 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000057 21:08:30.720 Disk 0 Vendor: WDC_____ 51.0 Size: 1430799MB BusType: 8 21:08:30.726 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000058 21:08:30.732 Disk 1 Vendor: Seagate_ 3.AA Size: 305245MB BusType: 8 21:08:30.753 Disk 0 MBR read successfully 21:08:30.760 Disk 0 MBR scan 21:08:30.861 Disk 0 unknown MBR code 21:08:30.863 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 21:08:30.892 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 1418614 MB offset 206848 21:08:30.946 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 11791 MB offset 2905529692 21:08:31.027 Disk 0 scanning C:\Windows\system32\drivers 21:08:39.173 Service scanning 21:08:57.973 Modules scanning 21:08:58.332 Disk 0 trace - called modules: 21:08:58.364 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll amdsbs.sys 21:08:58.376 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8009367790] 21:08:58.388 3 CLASSPNP.SYS[fffff8800195843f] -> nt!IofCallDriver -> \Device\00000057[0xfffffa8008d2a9c0] 21:09:01.090 AVAST engine scan C:\Windows 21:09:04.247 AVAST engine scan C:\Windows\system32 21:11:54.859 AVAST engine scan C:\Windows\system32\drivers 21:12:04.986 AVAST engine scan C:\Users\Ryan 21:12:46.098 AVAST engine scan C:\ProgramData 21:13:16.622 Scan finished successfully 21:13:52.822 Disk 0 MBR has been saved successfully to "C:\Users\Ryan\Desktop\MBR.dat" 21:13:52.828 The log file has been saved successfully to "C:\Users\Ryan\Desktop\aswMBR.txt"

Attachments:

MyStart toolbar is not a virus and is not dangerous. At most it is hijacking adware but certainly doesn’t pose a threat even though it is extremely annoying. We will remove it.


Remove remnants of Norton

You have remnants of Norton on your computer.
  • download the Norton Removal Tool from here and save it to your desktop.
  • double click on Norton_Removal_Tool.exe to run the tool.
  • follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

=============================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o=HPDTDF
    IE:64bit: - HKLM\..\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
    IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPDTDF
    IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
    IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
    IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o=HPDTDF
    IE - HKLM\..\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
    IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPDTDF
    IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
    IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
=============================================

Download Malwarebytes-Anti-Malware

Click here
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Logs to include in the next post:

OTL fix log
New OTL log
Mbam.txt


Thanks

Satchfan
It has been several days since I replied to your request for help with your computer problems. Please let me know if you are having problems and still need help. Thanks Satchfan
Satchfan,

Sorry for the late reply. I was gone for the weekend. Here are the logs that you've requested:


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Ryan
->Temp folder emptied: 317336160 bytes
->Temporary Internet Files folder emptied: 16626338 bytes
->Google Chrome cache emptied: 43520452 bytes
->Flash cache emptied: 42182 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 107552 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4387032 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 364.00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 08052012_202641

Files\Folders moved on Reboot…
C:\Users\Ryan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6AF1EEB6-5634-4CE7-8D36-B49DD4912532}.tmp not found!
File\Folder C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{84C5BAC3-387F-419D-B308-4BC4F8A3373B}.tmp not found!
File\Folder C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{8C8E362E-6BFA-4A34-8AE6-0BA898DBAB60}.tmp not found!
File\Folder C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E1CD905C-5BB1-4EEF-A529-AD767610D8E6}.tmp not found!
File\Folder C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FC8853DF-C8C7-4F61-B0A8-50E9D83ACC3A}.tmp not found!

PendingFileRenameOperations files…
File C:\Users\Ryan\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6AF1EEB6-5634-4CE7-8D36-B49DD4912532}.tmp not found!
File C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{84C5BAC3-387F-419D-B308-4BC4F8A3373B}.tmp not found!
File C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{8C8E362E-6BFA-4A34-8AE6-0BA898DBAB60}.tmp not found!
File C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E1CD905C-5BB1-4EEF-A529-AD767610D8E6}.tmp not found!
File C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FC8853DF-C8C7-4F61-B0A8-50E9D83ACC3A}.tmp not found!

Registry entries deleted on Reboot…

================================================================================
=================================================================================
=====================================

Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.06.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Ryan :: RYAN-HP [administrator]

Protection: Enabled

8/5/2012 9:00:30 PM
mbam-log-2012-08-05 (21-00-30).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 190264
Time elapsed: 6 minute(s), 10 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

================================================================================
=================================================================================
==================================

New OTL Log:


OTL logfile created on: 8/6/2012 5:38:54 PM - Run 2
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Ryan\Documents\Mystart Virus
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

9.99 Gb Total Physical Memory | 8.56 Gb Available Physical Memory | 85.63% Memory free
19.98 Gb Paging File | 17.31 Gb Available in Paging File | 86.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1385.37 Gb Total Space | 1012.92 Gb Free Space | 73.12% Space Free | Partition Type: NTFS
Drive D: | 11.51 Gb Total Space | 1.41 Gb Free Space | 12.23% Space Free | Partition Type: NTFS
Drive E: | 298.08 Gb Total Space | 238.04 Gb Free Space | 79.86% Space Free | Partition Type: NTFS

Computer Name: RYAN-HP | User Name: Ryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/02 23:01:25 | 000,186,832 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Update\1.3.21.115\GoogleCrashHandler.exe
PRC - [2012/08/02 11:41:19 | 000,186,832 | —- | M] (Google Inc.) – C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.115\GoogleCrashHandler.exe
PRC - [2012/08/02 11:23:28 | 000,597,504 | —- | M] (OldTimer Tools) – C:\Users\Ryan\My Documents\Mystart Virus\OTL.exe
PRC - [2012/07/20 15:17:14 | 012,218,904 | —- | M] (Google) – C:\Program Files (x86)\Google\Drive\googledrivesync.exe
PRC - [2012/07/03 13:46:44 | 000,655,944 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/07/03 13:46:44 | 000,462,920 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/07/03 13:46:42 | 000,973,488 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
PRC - [2011/02/01 03:49:44 | 001,127,448 | —- | M] (PDF Complete Inc) – C:\Program Files (x86)\PDF Complete\pdfsvc.exe
PRC - [2011/01/25 19:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2010/11/26 09:09:12 | 000,399,344 | —- | M] (Roxio) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/11/23 22:31:24 | 002,069,504 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
PRC - [2009/08/24 21:11:16 | 000,656,896 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
PRC - [2009/02/27 21:13:04 | 000,053,248 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
PRC - [2008/11/20 12:47:28 | 000,062,768 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/05 20:52:43 | 000,571,392 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\pysqlite2._sqlite.pyd
MOD - [2012/08/05 20:52:43 | 000,096,256 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32api.pyd
MOD - [2012/08/05 20:52:43 | 000,086,016 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\_elementtree.pyd
MOD - [2012/08/05 20:52:43 | 000,040,448 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\_socket.pyd
MOD - [2012/08/05 20:52:42 | 000,792,576 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\wx._gdi_.pyd
MOD - [2012/08/05 20:52:42 | 000,263,168 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32com.shell.shell.pyd
MOD - [2012/08/05 20:52:42 | 000,153,088 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\pyexpat.pyd
MOD - [2012/08/05 20:52:42 | 000,070,656 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\wx._html2.pyd
MOD - [2012/08/05 20:52:42 | 000,011,776 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32crypt.pyd
MOD - [2012/08/05 20:52:41 | 001,018,368 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\windows._cacheinvalidation.pyd
MOD - [2012/08/05 20:52:40 | 000,731,136 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\wx._misc_.pyd
MOD - [2012/08/05 20:52:40 | 000,354,304 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\pythoncom26.dll
MOD - [2012/08/05 20:52:40 | 000,110,592 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\PyWinTypes26.dll
MOD - [2012/08/05 20:52:40 | 000,073,728 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\_ctypes.pyd
MOD - [2012/08/05 20:52:39 | 001,169,408 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\wx._core_.pyd
MOD - [2012/08/05 20:52:39 | 000,645,120 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\_ssl.pyd
MOD - [2012/08/05 20:52:39 | 000,311,808 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\_hashlib.pyd
MOD - [2012/08/05 20:52:39 | 000,036,352 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32process.pyd
MOD - [2012/08/05 20:52:39 | 000,022,528 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32pdh.pyd
MOD - [2012/08/05 20:52:38 | 000,807,424 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\wx._windows_.pyd
MOD - [2012/08/05 20:52:38 | 000,121,856 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\wx._wizard.pyd
MOD - [2012/08/05 20:52:38 | 000,111,104 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32file.pyd
MOD - [2012/08/05 20:52:37 | 001,056,256 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\wx._controls_.pyd
MOD - [2012/08/05 20:52:37 | 000,039,424 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32inet.pyd
MOD - [2012/08/05 20:52:36 | 000,017,920 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\win32event.pyd
MOD - [2012/08/05 20:52:35 | 000,585,728 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\unicodedata.pyd
MOD - [2012/08/05 20:52:35 | 000,011,776 | —- | M] () – C:\Users\Ryan\AppData\Local\Temp\_MEI32282\select.pyd
MOD - [2012/07/31 00:36:14 | 000,442,392 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppgooglenaclpluginchrome.dll
MOD - [2012/07/31 00:36:13 | 012,235,288 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
MOD - [2012/07/31 00:36:12 | 003,997,720 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll
MOD - [2012/07/31 00:34:57 | 000,526,872 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\libglesv2.dll
MOD - [2012/07/31 00:34:55 | 000,104,984 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\libegl.dll
MOD - [2012/07/31 00:34:45 | 000,144,424 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\avutil-51.dll
MOD - [2012/07/31 00:34:43 | 000,266,792 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\avformat-54.dll
MOD - [2012/07/31 00:34:42 | 002,480,680 | —- | M] () – C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\avcodec-54.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/12/21 01:15:30 | 001,041,248 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/02/27 21:13:04 | 000,053,248 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
MOD - [2009/02/19 19:22:50 | 000,028,672 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\WMINPUT.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/04/26 04:50:18 | 000,237,056 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2011/02/17 00:47:28 | 000,682,040 | —- | M] (Hewlett-Packard) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe – (HPAuto)
SRV:64bit: - [2011/01/14 01:48:22 | 000,354,304 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2010/10/11 04:48:14 | 000,346,168 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe – (HPClientSvc)
SRV:64bit: - [2010/09/22 20:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/06/17 07:23:36 | 000,194,496 | —- | M] (Advanced Micro Devices) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe – (AMD Reservation Manager)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/07/03 13:46:44 | 000,655,944 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) [Auto | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE – (BBSvc)
SRV - [2011/02/01 03:49:44 | 001,127,448 | —- | M] (PDF Complete Inc) [Auto | Running] – C:\Program Files (x86)\PDF Complete\pdfsvc.exe – (pdfcDispatcher)
SRV - [2011/01/25 19:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2011/01/25 15:56:32 | 000,241,648 | —- | M] (CyberLink) [Auto | Stopped] – c:\Program Files (x86)\Cyberlink\PowerDVD10\NavFilter\kmsvc.exe – (CLKMSVC10_38F51D56)
SRV - [2010/11/26 09:09:12 | 000,399,344 | —- | M] (Roxio) [Auto | Running] – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe – (RoxioNow Service)
SRV - [2010/10/12 12:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/03/18 16:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/04/26 06:47:20 | 011,172,864 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/04/26 03:32:46 | 000,339,456 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/05/25 17:50:58 | 001,843,712 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HCW723x.sys – (HCW723x)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/12/28 14:45:54 | 000,412,776 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2010/11/20 22:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 22:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/11/17 09:04:32 | 000,115,216 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2010/11/04 23:57:54 | 001,041,760 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netr28x.sys – (netr28x)
DRV:64bit: - [2010/03/10 10:33:52 | 000,016,440 | —- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AtiPcie64.sys – (AtiPcie)
DRV:64bit: - [2010/02/18 11:18:24 | 000,046,136 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\amdiox64.sys – (amdiox64)
DRV:64bit: - [2009/12/22 04:26:36 | 000,038,456 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 21:32:26 | 000,231,224 | —- | M] (Advanced Micro Devices, Inc) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ahcix64s.sys – (ahcix64s)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o=HPDTDF
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{62CB5C0F-744D-4710-8A00-2BF5CD59DDCF}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPDTDF
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-1887079324-3387887618-774918653-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\BATINDICATOR.exe File not found
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1887079324-3387887618-774918653-1001..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4067204-96CB-4B7F-AD13-0F5BA948B803}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/05 20:59:18 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Malwarebytes
[2012/08/05 20:59:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/05 20:59:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/08/05 20:59:02 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/08/05 20:59:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/05 20:26:41 | 000,000,000 | —D | C] – C:\_OTL
[2012/08/05 20:13:53 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\HP Support Assistant
[2012/08/05 19:42:53 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\HpUpdate
[2012/08/03 08:44:14 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\CrashDumps
[2012/08/03 01:34:34 | 000,325,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2012/08/03 01:34:33 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2012/08/03 01:29:31 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Important
[2012/08/03 01:26:39 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2012/08/03 01:26:38 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2012/08/03 01:26:38 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2012/08/03 01:26:38 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2012/08/03 01:26:38 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2012/08/03 01:26:37 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2012/08/03 01:26:37 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2012/08/03 00:01:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Apps Migration
[2012/08/02 23:58:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Apps Sync
[2012/08/02 23:38:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2012/08/02 23:38:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/08/02 23:37:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2012/08/02 23:37:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2012/08/02 23:36:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Sync Framework
[2012/08/02 23:35:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 8
[2012/08/02 23:34:30 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\DIY
[2012/08/02 23:34:28 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\CyberLink
[2012/08/02 23:34:27 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\car
[2012/08/02 23:34:27 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Bluetooth Exchange Folder
[2012/08/02 23:34:27 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Blio
[2012/08/02 23:34:27 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\AnyDVDHD
[2012/08/02 23:34:23 | 012,621,696 | —- | C] (Microsoft Corporation) – C:\Users\Ryan\Documents\mseinstall.exe
[2012/08/02 23:34:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2012/08/02 23:33:59 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\School
[2012/08/02 23:33:50 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Scans
[2012/08/02 23:33:50 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Podcast
[2012/08/02 23:33:50 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Outlook Files
[2012/08/02 23:33:49 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\NPS
[2012/08/02 23:33:45 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\norton anti-virus
[2012/08/02 23:33:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Analysis Services
[2012/08/02 23:33:41 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\NAVY
[2012/08/02 23:33:41 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\My Received Files
[2012/08/02 23:33:41 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\My NPS Files
[2012/08/02 23:33:24 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\My Kindle Content
[2012/08/02 23:33:24 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\My eBooks
[2012/08/02 23:33:19 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Manuals
[2012/08/02 23:33:19 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\House
[2012/08/02 23:33:18 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\FrostWire
[2012/08/02 23:33:15 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Finances
[2012/08/02 23:33:12 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\DVDFab
[2012/08/02 23:32:37 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Downloads
[2012/08/02 23:32:00 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Microsoft Help
[2012/08/02 23:31:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2012/08/02 23:31:00 | 000,000,000 | RH-D | C] – C:\MSOCache
[2012/08/02 23:10:08 | 000,000,000 | –SD | C] – C:\Users\Ryan\Google Drive
[2012/08/02 23:04:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2012/08/02 23:01:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2012/08/02 23:01:10 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2012/08/02 23:01:09 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2012/08/02 21:19:38 | 000,000,000 | —D | C] – C:\Users\Ryan\Documents\Mystart Virus
[2012/08/02 11:39:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2012/08/02 11:30:20 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2012/08/02 11:30:20 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/08/02 11:30:20 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2012/08/02 11:30:20 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2012/08/02 11:30:20 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/08/02 11:30:20 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2012/08/02 11:30:20 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2012/08/02 11:30:20 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2012/08/02 11:30:20 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2012/08/02 11:30:20 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2012/08/02 11:30:20 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2012/08/02 11:30:20 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2012/08/02 11:30:20 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2012/08/02 11:30:20 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2012/08/02 11:30:20 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2012/08/02 11:30:20 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2012/08/02 11:30:20 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2012/08/02 11:30:19 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/08/02 11:30:19 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/08/02 11:30:19 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2012/08/02 11:30:19 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2012/08/02 11:30:19 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2012/08/02 11:30:19 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2012/08/02 11:30:19 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2012/08/02 11:30:19 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/08/02 11:30:19 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2012/08/02 11:30:19 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2012/08/02 11:30:19 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2012/08/02 11:30:19 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2012/08/02 11:30:19 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2012/08/02 11:30:19 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/08/02 11:30:19 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2012/08/02 11:30:19 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2012/08/02 11:30:19 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2012/08/02 11:30:18 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2012/08/02 11:30:18 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/08/02 11:30:18 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/08/02 11:30:18 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/08/02 11:30:18 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2012/08/02 11:30:18 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2012/08/02 11:30:18 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2012/08/02 11:30:18 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2012/08/02 11:30:18 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2012/08/02 11:30:18 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/08/02 11:30:18 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/08/02 11:30:18 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2012/08/02 11:30:18 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/08/02 11:30:18 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2012/08/02 11:30:18 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2012/08/02 11:30:18 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2012/08/02 11:30:18 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2012/08/02 11:30:18 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2012/08/02 11:30:18 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2012/08/02 11:30:18 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2012/08/02 11:30:18 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2012/08/02 11:30:18 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2012/08/02 11:30:18 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2012/08/02 11:30:18 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2012/08/02 11:30:18 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2012/08/02 11:30:18 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2012/08/02 11:30:18 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2012/08/02 11:30:18 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2012/08/02 11:30:18 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2012/08/02 11:30:18 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2012/08/02 11:30:18 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2012/08/02 11:30:17 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/08/02 11:30:17 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/08/02 11:30:17 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2012/08/02 11:30:17 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2012/08/02 11:30:17 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2012/08/02 11:30:17 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/08/02 11:30:17 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2012/08/02 11:09:41 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2012/08/02 11:09:41 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2012/08/02 11:09:40 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/08/02 10:57:25 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2012/08/02 10:57:25 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2012/08/02 10:57:25 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2012/08/02 10:57:25 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2012/08/02 10:57:25 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2012/08/02 10:57:25 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2012/08/02 10:57:25 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2012/08/02 10:57:24 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2012/08/02 10:57:24 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2012/08/02 10:57:19 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2012/08/02 10:57:15 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/08/02 10:57:15 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/08/02 10:56:34 | 002,315,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2012/08/02 10:56:34 | 002,223,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2012/08/02 10:56:34 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2012/08/02 10:56:34 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2012/08/02 10:56:34 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2012/08/02 10:56:33 | 000,778,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2012/08/02 10:56:33 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2012/08/02 10:56:33 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2012/08/02 10:56:33 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2012/08/02 10:56:33 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2012/08/02 10:56:33 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2012/08/02 10:56:33 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2012/08/02 10:56:33 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2012/08/02 10:56:28 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2012/08/02 10:56:28 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2012/08/02 10:56:20 | 002,871,808 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2012/08/02 10:56:20 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2012/08/02 10:56:14 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2012/08/02 10:56:12 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/08/02 10:56:10 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2012/08/02 10:56:10 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2012/08/02 10:55:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2012/08/02 10:55:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2012/08/02 10:55:28 | 001,465,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2012/08/02 10:55:28 | 000,870,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2012/08/02 10:55:25 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42.dll
[2012/08/02 10:55:25 | 001,359,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42u.dll
[2012/08/02 10:55:25 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42u.dll
[2012/08/02 10:55:25 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42.dll
[2012/08/02 10:55:22 | 001,447,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/08/02 10:55:22 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/08/02 10:55:22 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspicli.dll
[2012/08/02 10:55:21 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspisrv.dll
[2012/08/02 10:55:21 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secur32.dll
[2012/08/02 10:55:13 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/08/02 10:55:13 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/08/02 10:55:13 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/08/02 10:55:13 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/08/02 10:55:11 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/08/02 10:55:11 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/08/02 10:55:10 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/08/02 10:55:04 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2012/08/02 10:55:04 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2012/08/02 10:55:00 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2012/08/02 10:55:00 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2012/08/02 10:54:16 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2012/08/02 10:54:16 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2012/08/02 10:54:16 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2012/08/02 10:54:16 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2012/08/02 10:54:05 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2012/08/02 10:54:04 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2012/08/02 10:53:54 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/08/02 10:53:54 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/08/02 10:53:54 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/08/02 10:53:32 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2012/08/02 10:53:32 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnscacheugc.exe
[2012/08/02 10:53:32 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dnscacheugc.exe
[2012/08/02 10:53:25 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2012/08/02 10:51:24 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/08/02 10:49:30 | 000,027,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2012/08/02 10:35:46 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Google
[2012/08/02 10:33:42 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Apps
[2012/08/02 10:33:40 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Deployment
[2012/08/02 10:29:47 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/08/02 10:29:37 | 000,421,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012/08/02 10:29:36 | 001,162,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/08/02 10:29:36 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012/08/02 10:29:36 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012/08/02 10:29:36 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/08/02 10:29:35 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012/08/02 10:29:35 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012/08/02 10:29:35 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012/08/02 10:29:35 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012/08/02 10:29:35 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012/08/02 10:29:35 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012/08/02 10:29:35 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/02 10:29:35 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/08/02 10:29:34 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/08/02 10:29:34 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/08/02 10:29:34 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/08/02 10:29:34 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012/08/02 10:29:34 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/08/02 10:29:34 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/08/02 10:29:34 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/08/02 10:29:33 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/08/02 10:29:32 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/08/02 10:29:32 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/08/02 10:29:32 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/08/02 10:29:32 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/08/02 10:29:32 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/08/02 10:29:32 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/08/02 10:29:32 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012/08/02 10:29:22 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/08/02 10:29:22 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/08/02 10:29:15 | 000,566,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2012/08/02 10:29:14 | 000,642,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2012/08/02 10:29:14 | 000,605,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2012/08/02 10:29:14 | 000,518,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2012/08/02 10:29:14 | 000,020,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdusb.dll
[2012/08/02 10:29:14 | 000,019,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kd1394.dll
[2012/08/02 10:29:14 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdcom.dll
[2012/08/02 10:29:06 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2012/08/02 10:29:03 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvinst.exe
[2012/08/02 10:29:03 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\devrtl.dll
[2012/08/02 10:29:02 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FXSCOVER.exe
[2012/08/02 10:29:01 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2012/08/02 10:29:01 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2012/08/02 10:28:07 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2012/08/02 10:28:07 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2012/08/02 10:27:55 | 000,861,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2012/08/02 10:27:55 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2012/08/02 10:27:50 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2012/08/02 10:27:49 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2012/08/02 10:27:43 | 001,731,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2012/08/02 10:27:42 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2012/08/02 10:27:41 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2012/08/02 10:20:06 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2012/08/02 10:20:06 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2012/08/02 10:16:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2012/08/02 10:16:32 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/08/02 10:11:48 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/08/02 10:11:48 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/08/02 10:11:48 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/08/02 10:11:41 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/08/02 10:11:41 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/08/02 10:11:41 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/08/02 10:10:42 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/08/02 10:10:42 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/08/02 10:04:39 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Adobe
[2012/08/02 10:00:05 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\AMD
[2012/08/02 09:59:57 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\ATI
[2012/08/02 09:59:57 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\ATI
[2012/08/01 22:50:23 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2012/08/01 22:48:59 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\PDFC
[2012/08/01 22:48:43 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/08/01 22:48:43 | 000,000,000 | R–D | C] – C:\Users\Ryan\Searches
[2012/08/01 22:48:43 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/08/01 22:48:43 | 000,000,000 | -H-D | C] – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/08/01 22:48:35 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Identities
[2012/08/01 22:48:32 | 000,000,000 | R–D | C] – C:\Users\Ryan\Contacts
[2012/08/01 22:48:31 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\VirtualStore
[2012/08/01 22:48:06 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\RemEngine
[2012/08/01 22:43:14 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Hewlett-Packard
[2012/08/01 22:43:06 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Hewlett-Packard
[2012/08/01 22:42:51 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Hewlett-Packard_Company
[2012/08/01 22:42:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP User Manuals
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\AppData\Local\Temporary Internet Files
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Templates
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Start Menu
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\SendTo
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Recent
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\PrintHood
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\NetHood
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Documents\My Videos
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Documents\My Pictures
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Documents\My Music
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\My Documents
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Local Settings
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\AppData\Local\History
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Cookies
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\Application Data
[2012/08/01 22:41:58 | 000,000,000 | -HSD | C] – C:\Users\Ryan\AppData\Local\Application Data
[2012/08/01 22:41:52 | 000,000,000 | –SD | C] – C:\Users\Ryan\AppData\Roaming\Microsoft
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Videos
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Saved Games
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Pictures
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Music
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Links
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Favorites
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Downloads
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Documents
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\Desktop
[2012/08/01 22:41:52 | 000,000,000 | R–D | C] – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/08/01 22:41:52 | 000,000,000 | -H-D | C] – C:\Users\Ryan\AppData
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Temp
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\Microsoft
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Media Center Programs
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Macromedia
[2012/08/01 22:41:52 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\HuluDesktop
[2012/08/01 22:41:15 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2012/08/01 15:08:05 | 000,000,000 | —D | C] – C:\ProgramData\Recovery

========== Files - Modified Within 30 Days ==========

[2012/08/06 17:18:09 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001UA.job
[2012/08/06 17:18:09 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/06 17:16:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/06 11:49:13 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/06 11:46:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001Core.job
[2012/08/06 11:41:04 | 000,782,206 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/06 11:41:04 | 000,662,168 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/08/06 11:41:04 | 000,121,996 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/08/05 20:59:41 | 000,024,400 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/05 20:59:41 | 000,024,400 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/05 20:59:08 | 000,001,111 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/05 20:51:09 | 3751,718,911 | -HS- | M] () – C:\hiberfil.sys
[2012/08/03 09:12:51 | 000,001,133 | —- | M] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2012/08/03 03:39:38 | 000,415,744 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/02 23:10:09 | 000,001,697 | —- | M] () – C:\Users\Ryan\Desktop\Google Drive.lnk
[2012/08/02 22:55:38 | 000,001,439 | —- | M] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/02 11:48:23 | 000,775,914 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/02 11:30:21 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2012/08/02 11:30:20 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2012/08/02 11:30:20 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/08/02 11:30:20 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2012/08/02 11:30:20 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2012/08/02 11:30:20 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/08/02 11:30:20 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2012/08/02 11:30:20 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2012/08/02 11:30:20 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2012/08/02 11:30:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2012/08/02 11:30:20 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2012/08/02 11:30:20 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2012/08/02 11:30:20 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2012/08/02 11:30:20 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2012/08/02 11:30:20 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2012/08/02 11:30:20 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2012/08/02 11:30:20 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2012/08/02 11:30:20 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2012/08/02 11:30:20 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2012/08/02 11:30:19 | 001,427,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/08/02 11:30:19 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/08/02 11:30:19 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2012/08/02 11:30:19 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2012/08/02 11:30:19 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2012/08/02 11:30:19 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2012/08/02 11:30:19 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2012/08/02 11:30:19 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/08/02 11:30:19 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2012/08/02 11:30:19 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2012/08/02 11:30:19 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2012/08/02 11:30:19 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2012/08/02 11:30:19 | 000,073,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/08/02 11:30:19 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2012/08/02 11:30:19 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2012/08/02 11:30:19 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2012/08/02 11:30:18 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2012/08/02 11:30:18 | 002,311,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/08/02 11:30:18 | 001,494,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/08/02 11:30:18 | 000,818,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/08/02 11:30:18 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2012/08/02 11:30:18 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2012/08/02 11:30:18 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2012/08/02 11:30:18 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2012/08/02 11:30:18 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2012/08/02 11:30:18 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/08/02 11:30:18 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/08/02 11:30:18 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2012/08/02 11:30:18 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/08/02 11:30:18 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2012/08/02 11:30:18 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2012/08/02 11:30:18 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2012/08/02 11:30:18 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2012/08/02 11:30:18 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2012/08/02 11:30:18 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2012/08/02 11:30:18 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2012/08/02 11:30:18 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2012/08/02 11:30:18 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2012/08/02 11:30:18 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2012/08/02 11:30:18 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2012/08/02 11:30:18 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2012/08/02 11:30:18 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2012/08/02 11:30:18 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2012/08/02 11:30:18 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2012/08/02 11:30:18 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2012/08/02 11:30:18 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2012/08/02 11:30:18 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2012/08/02 11:30:18 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2012/08/02 11:30:17 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/08/02 11:30:17 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/08/02 11:30:17 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2012/08/02 11:30:17 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2012/08/02 11:30:17 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2012/08/02 11:30:17 | 000,096,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/08/02 11:30:17 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2012/08/02 10:17:17 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/08/02 10:15:14 | 000,000,328 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForRyan.job
[2012/08/02 00:41:04 | 000,108,227 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2012/08/02 00:41:04 | 000,108,227 | —- | M] () – C:\Windows\SysNative\license.rtf
[2012/08/01 22:42:22 | 000,000,000 | RHS- | M] () – C:\Windows\SysWow64\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK
[2012/08/01 22:42:22 | 000,000,000 | RHS- | M] () – C:\Windows\SysNative\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK

========== Files Created - No Company Name ==========

[2012/08/05 20:59:08 | 000,001,111 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/02 23:52:26 | 000,001,133 | —- | C] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2012/08/02 23:34:23 | 119,120,896 | —- | C] () – C:\Users\Ryan\Documents\Outlook Backup 5-25-12.pst
[2012/08/02 23:10:09 | 000,001,697 | —- | C] () – C:\Users\Ryan\Desktop\Google Drive.lnk
[2012/08/02 23:01:45 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/02 23:01:41 | 000,000,890 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/02 11:30:20 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2012/08/02 11:30:18 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2012/08/02 10:35:53 | 000,000,904 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001UA.job
[2012/08/02 10:35:48 | 000,000,852 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1887079324-3387887618-774918653-1001Core.job
[2012/08/02 10:17:10 | 000,001,917 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/02 10:11:48 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2012/08/02 10:04:30 | 000,001,439 | —- | C] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/01 22:48:52 | 000,001,411 | —- | C] () – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/08/01 22:48:44 | 000,001,445 | —- | C] () – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/08/01 22:48:22 | 000,000,328 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForRyan.job
[2012/08/01 22:42:54 | 000,002,312 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Download Store.lnk
[2012/08/01 22:42:54 | 000,002,278 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Trials for QuickBooks, Quicken and TurboTax.lnk
[2012/08/01 22:42:53 | 000,002,126 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snapfish.lnk
[2012/08/01 22:42:53 | 000,001,858 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Install Rhapsody.lnk
[2012/08/01 22:42:28 | 000,001,787 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warranty.lnk
[2012/08/01 22:42:25 | 3751,718,911 | -HS- | C] () – C:\hiberfil.sys
[2012/08/01 22:42:22 | 000,000,000 | RHS- | C] () – C:\Windows\SysWow64\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK
[2012/08/01 22:42:22 | 000,000,000 | RHS- | C] () – C:\Windows\SysNative\drivers\103C_HP_cPC_h8-1030_Y53316J_0U_QMXX123_E11NA2MRW603_4A_I2A92_SFOXCONN_V1.01_B6.12_T110504_W73-1_L409_M10232_J320_7AMD_8FA0_93.20_#110803_N18145390;10EC8168_Z_G10026758_Ohp BDDVDRW CH20L SCSI CdRom Device.MRK
[2012/08/01 22:41:52 | 000,001,974 | —- | C] () – C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hulu Desktop.lnk
[2012/08/01 22:41:52 | 000,000,290 | —- | C] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/08/01 22:41:52 | 000,000,272 | —- | C] () – C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/04/26 03:52:40 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/04/26 03:52:40 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2011/09/12 22:06:18 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/05/19 01:44:25 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/03/03 23:04:58 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2011/02/11 12:15:43 | 000,775,914 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

< End of report >
I still see no signs of it but some settings I got fixed have returned so we may have to look at that,

This has also suddenly appeared:

C:\Users\Ryan\Documents\FrostWire

We are not here to pass judgment on file-sharing as a concept. However, we will warn you that if you engage in P2P activity and if you have this kind of software installed on your machine it will always make you more susceptible to re-infection.

Please note: even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

===================================================

Let’s see if we can find anything using a different tool.

Please download SystemLook from here and save it to your Desktop.
  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield - please make sure you include the colon, (:), at the beginning.

    :filefind
    *MyStart*
    *Incredibar*
    
    :folderfind
    *MyStart*
    *Incredibar*
    
    :Regfind
    MyStart
    Incredibar

  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Are you still having the same problem?

Satchfan
Satchfan, Here are the results. I created the folder that is shown existing on the C:\ drive. It looks as though the virus is gone! SystemLook 30.07.11 by jpshortstuff Log created at 11:28 on 07/08/2012 by Ryan Administrator - Elevation successful ========== filefind ========== Searching for "*MyStart*" No files found. Searching for "*Incredibar*" No files found. ========== folderfind ========== Searching for "*MyStart*" C:\Users\Ryan\Documents\Mystart Virus d—— [02:19 03/08/2012] Searching for "*Incredibar*" No folders found. ========== Regfind ========== Searching for "MyStart" No data found. Searching for "Incredibar" No data found. -= EOF =-

It looks as though the virus is gone!

Here’s hoping.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

NOTE. If Eset doesn't find any threats, it won't produce a log.

Satchfan
Satchfan, Scan performed, no threats found. It seems as though the reformatting worked but the Mystart changed some settings in Chrome that Google saved and were still applied after I reinstalled Chrome. Are there anymore steps to follow to make certain that the virus is gone? I feel confident that it is, but I'm not the expert. Ryan
As I said previously, MyStart toolbar is not a virus and is not dangerous so it was never a problem, just a nuisance.


Your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

You can delete the DDS and aswMBR logs and programs from your desktop.

Uninstall OTL
  • double-click OTL.exe
  • click the CleanUp! button.
  • select Yes when the Begin cleanup Process? prompt appears.
  • if you are prompted to reboot during the cleanup, select Yes.
  • the tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

===================================================

Create a Restore Point
  • click Start, right-click Computer, and then Properties.
  • in the left pane, click System protection. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • click the System Protection tab, and then click Create.
  • in the System Protection dialog box, type a description, and then click Create.
Remove old restore points
  • click the Start button and in the search box, type Disk Cleanup, and then, in the list of results, click Disk Cleanup.
  • if prompted, select the drive that you want to clean up, and then click OK.
  • in the Disk Cleanup for (drive letter) dialog box, click Clean up system files. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • if prompted, select the drive that you want to clean up, and then click OK.
  • click the More Options tab, under System Restore and Shadow Copies, click Clean up.
  • in the Disk Cleanup dialog box, click Delete.
  • click Delete Files, and then click OK.
===================================================

Windows updates

I notice that Windows updates are waiting to be installed. Click here for information on how to get the latest Windows updates:

===================================================

Set your computer to automatically check for Windows updates.

Click here for information on how to set your computer to automatically check for and install Windows updates.

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

===================================================

Install Spybot - Search and Destroy - Download and install Spybot Search and Destroy which provides real time spyware and hijacker protection .

You should scan your computer with the program on a regular basis as you would with your anti-virus software.

A tutorial on installing and using SS&D can be found here

===================================================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI