This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Disk Error and other messeges [Solved]

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

THree times in the last two days I've been stopped from logging into my computer by error messeges. The first time the computer went straight into a full disk check and even though all seemed to be okay the next day when I attempted to log in I got a blue screen telling me that there was a page loading error and some other error that may mean my system is compromised in some way. I've run Malware bytes and SAS and both came back with several infections. All were deleted but then today I got the blue screen error saying that something is wrong with my page loading and possible other problems. I really need to find out just what it is that is wrong here. Also Secunia no longer works correctly, I know that the new 3.0 version is very poor so I went back to version 2.0 and even that no longer works right. I cannot download the fixes because I keep getting an error saying that the system cannot access the correct ISP. Its problems like these that have me very worried.
Hi and Welcome!! Bryan A :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
Hi Bryan A ;)

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true /fp
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
On your next reply please post :
  • OTL.txt
  • Extras.txt
  • aswMBR log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Robybel, Thank You for responding so quickly. Here are the logs you requested.

OTL logfile created on: 11/18/2012 1:39:57 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 52.46% Memory free
7.50 Gb Paging File | 4.91 Gb Available in Paging File | 65.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 547.20 Gb Free Space | 79.90% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Bryan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Coupon Companion\Coupon Companion-bg.exe (215 Apps)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\clarosrv.exe (Montera Technologeis LTD)
PRC - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe (Oberon Media )
PRC - C:\Windows\SysWOW64\schtasks.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
PRC - C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\spext.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avutil-51.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avformat-54.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avcodec-54.dll ()
MOD - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\escortShld.dll ()
MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\Program Files (x86)\WOT\WOT.dll ()
MOD - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:64bit: - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Browser Manager) – C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (IDriveE Service) – C:\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (nvsvc) – C:\Windows\SysWOW64\nvvsvc.exe ()
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (GameConsoleService) – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswNdis2) – C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (aswFW) – C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswNdis) – C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:64bit: - (pneteth) – C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (GIDv2) – C:\Windows\SysNative\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadserd) – C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Uim_IM) – C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (UimBus) – C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:64bit: - (hotcore3) – C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sscdserd) – C:\Windows\SysNative\drivers\sscdserd.sys (MCCI Corporation)
DRV:64bit: - (sscdmdm) – C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) – C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) – C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (PCGenFam) – C:\Windows\SysNative\drivers\PCGenFAM.sys (Soluto LTD.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiKF622) – C:\Windows\SysNative\drivers\SaiKF622.sys (Saitek)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (VaneFltr) – C:\Windows\SysNative\drivers\Lachesis.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV - (GEARAspiWDM) – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\URLSearchHook: {a8a9d26a-734f-467a-8907-176f9c5bdf56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {fe337d7b-1447-4780-9a52-48bdac438235} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT1259247

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C8 E7 16 3F C0 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshareus.my-quick-search.com/search…s}&srch;=dsp
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerm…000002637bd3942
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…56-0F484A5B109E
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" = http://search.comcast.net/search/?cat=Web&…q={searchTerms}
IE - HKCU\..\SearchScopes\{281534E3-35BD-4B33-B445-24865046DE66}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{4A88F9EE-674B-46AE-9562-34F23715B388}: "URL" = http://www.bing.com/search?FORM=UP09DF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{53AD41BF-FFF3-49EB-89DF-C13AFED99786}: "URL" = http://websearch.shopathome.com?user_id=%g…q={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{6AB6D437-7F6D-4345-9B6C-E2D711B76132}: "URL" = http://www.google.com/search?sourceid=ie7&…;rlz=1I7ACZZ_en
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={8E35D18…mp;d=2012-06-17 23:22:47&v;=11.1.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{D5AC17B8-504C-41C5-9BF1-492AE1D6F4D7}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{EF1EE071-9EAD-44DD-A0C9-8C51EA637D51}: "URL" = http://search.yahoo.com/search?p={searchte…42,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Claro Search"
FF - prefs.js..browser.search.selectedEngine: "Claro Search"
FF - prefs.js..keyword.URL: "http://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=KW_ss&mntrId;=e075d4f6000000000000002637bd3942&q;="
FF - prefs.js..browser.search.order.1: "Claro Search"
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=HP_ss&mntrId;=e075d4f6000000000000002637bd3942"
FF - prefs.js..browser.search.selectedEngine: "XFINITY"
FF - prefs.js..browser.search.defaultenginename: "XFINITY"


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@GamingWonderland.com/Plugin: C:\Program Files (x86)\GamingWonderland\bar\1.bin\NPgtStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.91: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\npDisplayEngine: C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll ( )
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/08/06 10:55:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\GamingWonderland\bar\1.bin [2012/11/16 16:05:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Components: C:\Program Files (x86)\Minefield\components [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Plugins: C:\Program Files (x86)\Minefield\plugins [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/11/18 01:26:39 | 000,000,000 | —D | M]

[2012/07/04 22:52:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions
[2010/06/10 20:24:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/04 22:52:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/11/18 01:26:53 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions
[2012/11/18 01:26:54 | 000,000,000 | —D | M] ("Coupon Companion") – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/18 01:26:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/18 01:26:36 | 000,000,000 | —D | M] (Claro Toolbar) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/07/04 22:53:08 | 000,000,000 | —D | M] (Songbird Toolbar, Powered by Ask.com) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2011/11/29 23:56:34 | 000,000,000 | —D | M] (We-Care Reminder) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\wecarereminder@bryan
[2012/11/18 01:26:53 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]\chrome\content\extensionCode
[2012/10/14 08:56:22 | 000,214,127 | —- | M] () (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/07/04 22:53:08 | 000,002,335 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\askcom.xml
[2012/11/18 01:26:39 | 000,002,514 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\browsemngr.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.claro-search.com/?affID=116695&…000002637bd3942
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\background/registryAccess.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U35 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Display Engine v2 (Enabled) = C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Songbird Toolbar = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\
CHR - Extension: FreeHDSport.TV = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok\1.1_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl\1.1_0\
CHR - Extension: avast! WebRep = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: We-Care Reminder Lite = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: Yontoo = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.20.40\crossrider
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.20.40\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\

O1 HOSTS File: ([2012/07/12 17:16:43 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2:64bit: - BHO: (Reg Error: Value error.) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Reg Error: Value error. File not found
O2:64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O2 - BHO: (Claro LTD Helper Object) - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll (Montera Technologeis LTD)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Coupon Companion) - {11111111-1111-1111-1111-110011441193} - C:\Program Files (x86)\Coupon Companion\Coupon Companion.dll (215 Apps)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Reg Error: Value error.) - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - Reg Error: Value error. File not found
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Claro LTD Toolbar) - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\claroTlbr.dll (Montera Technologeis LTD)
O3 - HKLM\..\Toolbar: (GamingWonderland) - {a899079d-206f-43a6-be6a-07e0fa648ea0} - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Gospel Internet Radio Toolbar) - {A8A9D26A-734F-467A-8907-176F9C5BDF56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PLD_FrameworkRun] C:\Windows\SysNative\OEM\_NowIntoDT.vbs ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [HostsServer] C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWOW64\StikyNot.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O15 - HKCU\..Trusted Domains: bleacherreport.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hoptoadapp.com ([]https in Trusted sites)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://gamesville.worldwinner.com/games/v4…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} http://www.worldwinner.com/games/v68/clue/clue.cab (Clue Control)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} http://www.worldwinner.com/games/v42/tilecity/tilecity.cab (Tilecity Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} http://www.worldwinner.com/games/v43/paint/paint.cab (Paint Control)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab (SysInfo Class)
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab (CPlayFirstSweetopiaControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\rebinfo - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\rebinfo - No CLSID value found
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/11/18 01:37:00 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:26:55 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Coupon Companion
[2012/11/18 01:26:50 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Claro
[2012/11/18 01:26:49 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
[2012/11/18 01:26:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Coupon Companion
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Claro LTD
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012/11/16 17:46:35 | 000,000,000 | —D | C] – C:\Users\Bryan\.idlerc
[2012/11/16 03:52:29 | 000,132,864 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/11/16 03:52:14 | 000,262,656 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/11/16 03:52:13 | 000,012,368 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswNdis.sys
[2012/11/16 03:38:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012/11/16 02:06:30 | 000,370,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/11/16 02:06:30 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/11/16 02:06:25 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/11/16 02:06:23 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/11/16 02:06:21 | 000,984,144 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/11/16 02:06:20 | 000,071,600 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/11/16 02:05:55 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/11/16 02:05:54 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/11/16 01:07:04 | 000,000,000 | —D | C] – C:\ProgramData\GID
[2012/11/14 22:18:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2012/11/14 10:39:30 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Secunia PSI
[2012/11/14 08:29:21 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/11/14 08:29:21 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2012/11/14 08:28:38 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2012/11/14 08:28:37 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2012/11/14 08:28:37 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2012/11/14 08:28:36 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2012/11/14 08:28:36 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2012/11/14 08:28:36 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2012/11/14 08:28:36 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2012/11/14 08:28:36 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2012/11/14 08:28:36 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2012/11/14 08:28:35 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2012/11/14 08:28:35 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2012/11/14 08:28:35 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2012/11/14 08:28:35 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2012/11/14 08:28:35 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2012/11/14 08:28:35 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2012/11/14 08:28:35 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2012/11/14 08:28:35 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2012/11/14 08:28:35 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2012/11/14 08:28:35 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2012/11/14 08:28:35 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2012/11/14 08:28:35 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2012/11/14 08:28:34 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2012/11/14 08:20:10 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/11/14 08:20:10 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/11/14 08:20:09 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/11/14 08:20:09 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/11/14 08:20:09 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/11/14 08:20:09 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/11/14 08:20:09 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/11/14 08:20:09 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/11/14 08:20:08 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/11/14 08:20:08 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/11/14 08:20:08 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/11/14 08:20:08 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/11/14 08:20:07 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/11/14 08:20:07 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/11/14 08:20:07 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/11/14 08:15:34 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2012/11/14 08:15:33 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2012/11/14 08:15:33 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2012/11/14 08:15:33 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/11/14 08:14:38 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2012/11/14 08:14:15 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2012/11/14 08:14:15 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2012/11/14 08:14:15 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2012/11/14 08:14:14 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2012/11/14 08:14:04 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/11/14 08:14:04 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/11/14 08:14:01 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2012/11/14 08:14:01 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2012/11/13 21:03:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderland
[2012/11/10 21:31:14 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/11/10 21:30:41 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpiderOak
[2012/11/10 21:30:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpiderOak
[2012/11/01 22:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\bSaving
[2012/10/25 20:56:30 | 000,000,000 | —D | C] – C:\Users\Bryan\Documents\Aimersoft Video Studio Express
[2012/10/25 20:56:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2012/10/25 20:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Aimersoft
[2012/10/25 03:12:26 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:40:00 | 000,108,008 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/10/19 19:00:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/10/19 18:59:38 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/10/19 18:59:38 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/10/19 18:59:38 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/10/19 18:58:12 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/07/12 09:14:08 | 003,405,744 | —- | C] (ESET) – C:\Users\Bryan\OnlineScanner.ocx
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/18 01:39:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/18 01:37:00 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:29:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/18 01:28:23 | 000,001,346 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | M] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | M] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/18 00:53:55 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/18 00:50:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/17 10:52:07 | 000,003,084 | —- | M] () – C:\Windows\Sandboxie.ini
[2012/11/16 22:03:47 | 000,779,306 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/16 22:03:47 | 000,660,296 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/11/16 22:03:47 | 000,121,224 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/11/16 18:29:57 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 18:29:57 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 18:21:05 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2012/11/16 16:36:34 | 000,002,120 | —- | M] () – C:\scu.dat
[2012/11/16 09:41:54 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/11/16 03:38:39 | 000,001,962 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/16 03:09:36 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/11/16 03:09:36 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/11/16 03:07:02 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:31 | 000,001,110 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 10:30:05 | 000,002,439 | —- | M] () – C:\Users\Bryan\Desktop\Advanced Uninstaller PRO 11.lnk
[2012/11/14 09:40:39 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 08:43:02 | 000,334,096 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/05 13:30:02 | 005,770,487 | —- | M] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/10/30 15:51:56 | 000,059,728 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/10/30 15:51:55 | 000,984,144 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/10/30 15:51:55 | 000,370,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/10/30 15:51:55 | 000,262,656 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/10/30 15:51:55 | 000,071,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/10/30 15:51:55 | 000,021,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2012/10/30 15:51:53 | 000,132,864 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/10/30 15:51:53 | 000,025,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/10/30 15:51:07 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/10/30 15:50:59 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/10/30 15:50:30 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/10/29 14:46:59 | 000,344,696 | —- | M] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/29 14:42:02 | 000,001,021 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/10/29 10:11:08 | 000,001,121 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.net.lnk
[2012/10/29 10:11:06 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\PokerStars.net.lnk
[2012/10/27 08:07:03 | 000,001,430 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:03 | 000,001,406 | —- | M] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | M] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/10/25 03:12:26 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:39:53 | 000,108,008 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/10/23 07:39:52 | 001,034,216 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npdeployJava1.dll
[2012/10/23 07:39:52 | 000,916,456 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/18 01:28:23 | 000,001,346 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | C] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | C] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:05:06 | 000,002,120 | —- | C] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | C] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:30 | 000,001,110 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 21:55:30 | 000,001,073 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/11/14 08:29:23 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 08:15:33 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/05 12:34:15 | 005,770,487 | —- | C] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/10/29 14:46:53 | 000,344,696 | —- | C] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/27 08:07:03 | 000,001,430 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:02 | 000,001,406 | —- | C] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | C] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/09/14 17:11:09 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/07/12 13:48:22 | 000,000,839 | —- | C] () – C:\Users\Bryan\AppData\Roaming\result.db
[2012/07/12 09:14:18 | 000,000,172 | —- | C] () – C:\Users\Bryan\OnlineScanner.inf
[2012/05/20 21:59:25 | 000,000,000 | —- | C] () – C:\Users\Bryan\cd
[2012/02/15 02:14:35 | 000,000,000 | —- | C] () – C:\Users\Bryan\NetStat
[2012/02/08 03:10:36 | 000,003,084 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/12/28 13:15:52 | 000,000,151 | —- | C] () – C:\Users\Bryan\AppData\Roaming\burnaware.ini
[2011/12/23 14:46:15 | 000,005,632 | —- | C] () – C:\Users\Bryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 22:33:11 | 000,000,000 | —- | C] () – C:\Windows\Ransom.INI
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/07/27 02:20:24 | 000,000,000 | —- | C] () – C:\Users\Bryan\AppData\Local\{E6301488-4DE8-441E-9F4B-23956CD1A782}
[2011/05/18 11:08:35 | 000,148,936 | —- | C] () – C:\Windows\hpoins19.dat
[2011/04/05 08:40:01 | 000,026,032 | —- | C] () – C:\Windows\SysWow64\IDriveEXceedCryReg.exe
[2011/04/05 08:39:57 | 000,055,808 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2011/01/14 21:10:47 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/01/02 21:40:04 | 000,776,466 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/13 18:08:49 | 000,000,036 | —- | C] () – C:\Users\Bryan\AppData\Local\housecall.guid.cache
[2010/05/08 09:16:55 | 000,007,594 | —- | C] () – C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg
[2010/05/03 12:09:55 | 000,000,632 | RHS- | C] () – C:\Users\Bryan\ntuser.pol
[2010/05/02 13:44:28 | 000,001,102 | —- | C] () – C:\Users\Bryan\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011/05/09 20:03:26 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Reels
[2011/05/09 19:55:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Spins
[2010/08/12 19:25:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\abelhadigital.com
[2011/04/17 10:17:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Absolute Poker
[2010/05/01 21:39:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Acer
[2012/03/03 11:35:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\AdamOutler
[2012/09/01 13:26:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Amazon
[2011/12/22 15:52:32 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Auslogics
[2012/06/07 09:25:37 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Azureus
[2012/03/14 13:24:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Babylon
[2012/11/18 01:26:51 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Claro
[2011/05/27 02:43:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DiamondVipClub
[2011/03/18 22:52:47 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Diceland
[2012/11/18 01:28:27 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Digiarty
[2011/04/04 14:14:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DriverCure
[2012/11/14 10:20:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Dropbox
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Easy Duplicate Finder
[2012/09/07 09:51:08 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Expert PDF 7
[2011/12/23 19:26:48 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\FrostWire
[2012/11/16 01:16:53 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ID Vault
[2011/12/28 14:57:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ImgBurn
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Jaangle
[2010/05/01 21:39:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Leadertech
[2010/05/12 10:46:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Locate32
[2010/05/10 11:07:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Masque
[2011/05/20 20:10:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Mayflower
[2011/12/23 14:43:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\MusicNet
[2010/11/12 14:55:41 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Oberon Media
[2010/07/14 17:01:02 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\OpenDNS Updater
[2012/11/14 22:21:29 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Opera
[2010/07/22 11:00:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Panda Security
[2011/04/04 14:14:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ParetoLogic
[2010/12/28 17:39:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Pogo
[2010/12/20 13:04:13 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Razer
[2010/12/25 13:19:33 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Returnil
[2011/05/06 18:53:12 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\RomeCasino
[2011/11/23 17:23:44 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SecondLife
[2011/06/11 17:14:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Software Inspection Library
[2012/07/04 22:52:11 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Songbird2
[2012/11/10 23:05:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/03/25 07:02:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Spotify
[2012/01/04 19:59:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\streamWriter
[2011/12/18 22:58:00 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SystemNucleus
[2010/05/02 13:44:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Template
[2010/06/10 20:24:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Thunderbird
[2011/06/11 14:41:16 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Vegascasino21
[2011/05/06 18:54:35 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\VTExtra
[2011/12/14 00:47:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\wargaming.net
[2010/05/02 13:46:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WildTangent
[2010/10/27 17:24:01 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Windows Live Writer
[2012/07/31 18:32:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WinPatrol
[2012/01/21 09:22:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wise Registry Cleaner
[2012/08/06 14:31:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wondershare
[2010/06/25 11:03:34 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\X-Setup Pro
[2012/07/22 22:10:40 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\YourFileDownloader

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe

< MD5 for: EXPLORER.EXE >
[2011/02/25 22:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 21:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 17:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 21:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 21:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\ERDNT\cache86\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 22:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 04:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 22:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 22:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 21:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 05:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 22:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 21:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 17:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 22:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 22:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 22:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\ERDNT\cache64\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\ERDNT\cache86\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 17:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 17:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\ERDNT\cache64\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\ERDNT\cache64\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 17:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/27 23:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 22:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST375052 8AS SCSI Disk Device
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- SM/xD/SD/MMC/MS USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 14.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 14681112576
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 685.00GB
Starting Offset: 14785970176
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:6DCFAD3B
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:987CE5C8
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:25FF8A61
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:B7910E41
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:3E996AD9
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FD80436E
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:DC3A4904
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D822654B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:C966DE9F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:5304CF6F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:11590865
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C1C705A1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B84EF836
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:9B7E8561
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:5095D8B1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:30C74695
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:7C3E753C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F36D7549
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2E81DAB7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0256104B
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:9373B271
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:54997B77
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:1960DAF2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C5B78274
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3B3A302E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F54781BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F3AB0B43
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E0648389
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ABCD2B94
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:962FBFE7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2A8CD561
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:2881AFC0
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3F3BEF8F
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:F3239111
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

OTL Extras logfile created on: 11/18/2012 1:39:57 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 52.46% Memory free
7.50 Gb Paging File | 4.91 Gb Available in Paging File | 65.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 547.20 Gb Free Space | 79.90% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{065ABD98-F5B7-4A5E-9F32-C470E8CFE382}" = rport=10243 | protocol=6 | dir=out | app=system |
"{09C3AD09-2DE4-43FE-8960-6B5672570DFC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{13661FAA-49B2-42E0-875A-599ED504E92F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1A52733A-27F1-497E-8319-75C23620B1F6}" = lport=139 | protocol=6 | dir=in | app=system |
"{1F6D207D-AAC9-4F8F-B7CB-24712CE1AF9B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1FD35719-8649-4DD6-95AC-0B62A9D193AB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{531ED8DA-0EEC-426D-A57F-A60BEE904626}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{584774FE-733B-498A-B235-2CFA9EA05DFA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{683C4E01-A4CC-41EC-9A81-2FF4A864D6EB}" = lport=138 | protocol=17 | dir=in | app=system |
"{6D0D193C-12FB-48C1-AF5F-FB53BC34500B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6EC57AFE-CAF4-461B-B793-DE2BE4D5934E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7242F2F1-4E72-4318-97E3-4D29EE44B976}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{82314B2C-F18A-4E5E-838D-0381DFBC1A36}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{90F7B26B-35C5-4734-806D-62D2F1DA0CA0}" = rport=138 | protocol=17 | dir=out | app=system |
"{98318391-E3BE-4D8F-AA65-7A453BD3AD18}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A8D74D3-7169-43E0-A350-6EB48B66E505}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BC629E68-C9CD-47D1-BAFE-BD8F83BBE697}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C058D27F-27BF-4BDB-B400-05627DE0B792}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D18CE43B-6FDA-4614-9470-FB2C43D3CB45}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DDF5C05B-D1E0-4247-A25D-73B4661B82A2}" = lport=445 | protocol=6 | dir=in | app=system |
"{DE6F0476-F00A-4AFE-9821-0C1504851E51}" = lport=137 | protocol=17 | dir=in | app=system |
"{E08385CC-CA86-4090-BB2E-486CC00A5E1F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E1FDE63C-4A1F-4CBF-B104-63EC256602A1}" = rport=137 | protocol=17 | dir=out | app=system |
"{F19F2EE7-2682-454B-8532-90C700B500A8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F5C7536A-A119-4B89-A912-D80700252437}" = rport=445 | protocol=6 | dir=out | app=system |
"{F80A712E-97E0-47DD-AE8D-D177F2ED184C}" = rport=139 | protocol=6 | dir=out | app=system |
"{FF4A6083-17C4-4127-960F-82927DF1AD22}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027F670E-DA28-4121-8644-C5BF657B9744}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{065E72E2-D7BC-47E7-8E3F-4D00819BB823}" = protocol=17 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"{0EE68060-7537-4819-B2CA-3FFFA326A5C7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{13B5C18E-46D6-4465-A5C6-CBD122BD9068}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1423C54D-14E4-4CD2-BB1A-C4848E700804}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{16B64EE6-7938-462E-940D-41A6339B55E6}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{250FA4EE-2370-46AF-BB1C-EB2FFA5F6E0D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2D76D381-BF79-4C06-8931-57204966F73E}" = protocol=6 | dir=out | app=system |
"{2E5F50E0-1812-4576-ADFF-7A2166E5C1FC}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{31007B4D-5B6D-41DA-A744-041F0710615C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{356EE293-DC3E-4B53-945A-91BDD5E5A75A}" = protocol=17 | dir=in | app=c:\program files (x86)\pokerstars\tracer.exe |
"{3F22A01A-0239-41B2-B4CD-154E99EBF045}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4099F175-2B40-4EE1-85E2-9E5BCC740D8E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{40FFECD8-227F-44A4-AD65-D72A018884D2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{41DB31FE-5E40-48E5-B458-7F3B15F05559}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{4F57BEDE-EB17-47DB-A5DD-8EFD3677D025}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{5715D280-6046-4F27-9B89-583D23F9E8B0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5FC80437-14B8-4AF2-8DD6-55D937C3767F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{60907F23-55BD-47D8-BE04-CEC4E2E6143F}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{6351A2D8-7E67-4FEF-BCFF-273427166F07}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{6C613935-5B49-4398-95CB-A46500153830}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{780095B7-9AA0-42F3-9762-77EF830EEC50}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8094DA2D-BFFE-4BDC-96BB-3A363516B651}" = protocol=6 | dir=in | app=c:\program files (x86)\pokerstars\tracer.exe |
"{8DEB4056-33BE-4031-806D-662922D8732B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{92516AF0-311C-44A6-82A1-04416BF90148}" = protocol=6 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"{94E43188-9DA4-42CE-9666-75EA1FD1668D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B0385632-AB92-4C31-AC96-96228000A83D}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{B8AF4B8A-1A3B-48CF-AFB4-0AF70DAF3B12}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD496999-4091-4EE5-8F34-1CD2A9F64BB2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{BEE511C4-9B46-4C73-9DB7-41D04FC3A008}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C384D863-4D35-484D-B8D7-4020E27DF58A}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{C698EEDD-0187-4CEA-8672-AFEB1DB1BE73}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C7F3647A-82C0-48D7-A1E7-CAB6306F1E97}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{D242DAD3-E042-407C-8337-1DEE83881CB7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DD5F8589-2D81-4CAB-BB83-EE71A728F13F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E36F2CDD-33F3-4109-80E1-33829E2112EA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F6FDC3BC-9361-4131-BD0F-C60DE7590737}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{F74540C2-915A-4ECD-BD14-F57B4F67B18C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FC98856A-4506-4762-9F47-D018171FADC5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"TCP Query User{1DFCF2C7-5C46-4E8A-BF0F-C5662076C54C}C:\program files (x86)\ifreetv\ifreetv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ifreetv\ifreetv.exe |
"TCP Query User{5F6D312D-8EE7-455D-9F23-8854320F20EF}C:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{8C5DFD30-3DA5-4605-95AB-476C4AF70387}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{7E5B9ECA-8A8D-4201-9591-D2C79AB4606C}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{E140EAAD-4D6B-48FC-9146-AD18C5FC118E}C:\program files (x86)\ifreetv\ifreetv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ifreetv\ifreetv.exe |
"UDP Query User{F1E9625B-B4A1-46A7-BC69-0D8239D14D4E}C:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{23170F69-40C1-2702-0922-000001000000}" = 7-Zip 9.22 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417009FF}" = Java 7 Update 9 (64-bit)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{47E5588F-C3A0-11DE-9857-005056C00008}" = Paragon Partition Manager™ 2010 Free Edition
"{563F041C-DFDB-437B-A1E8-E141E0906076}" = Microsoft IntelliPoint 8.0
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CBBBC4D-B0B6-49DB-A421-98C65080D8EE}" = Eraser 6.0.7.1893
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{A62F9CD0-B2E0-4F2A-88F2-79254A3C8539}" = WinPatrol
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{C0DA129B-1E45-494D-A362-5CD0109C306B}" = WOT for Internet Explorer
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D40DBBFD-B87E-4E45-B15F-753B75C0D7F8}_is1" = Spencerberus System Nucleus
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"HitmanPro36" = HitmanPro 3.6
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Recuva" = Recuva
"Sandboxie" = Sandboxie 3.64 (64-bit)
"SDEPRO20_is1" = SDExplorer 2.1
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{067B277E-F94B-4F04-B380-BA967C00377C}_is1" = MiniTool Partition Wizard Home Edition 6.0
"{069B290F-5398-4629-A009-85B4BCB4B1B9}" = Claro Chrome Toolbar
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = Browser Manager
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java™ 6 Update 37
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{30075A70-B5D2-440B-AFA3-FB2021740121}" = Backup Manager Advance
"{30E10267-3B27-42CC-B727-681DEBD30C4D}" = Clean Water Action TriMini Reminder by We-Care.com v5.0.3.2
"{31228E31-2BFF-11D2-8866-00805F0D9D40}" = QPST
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{44A69352-33DD-405E-ADB8-2D768643BBAE}_is1" = AnyBizSoft PDF to Word (Build 3.0.0)
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CB2511D-A074-40E0-A5ED-A875EBBDDF49}" = BotHunter
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6ED53E0C-EAC0-4F0F-947D-6BA817E4C8C3}" = HostsMan 3.2.73
"{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1" = AppGraffiti
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110194827}" = Jewel Quest
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111405753}" = Super Collapse 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119803590}" = Vacation Quest - The Hawaiian Islands
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-510005691}" = Vacation Quest Australia
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}" = Nero BurnLite 10
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88603FC0-6B3C-442D-981E-E3D49F083548}_is1" = NovaBench 3.0.4
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9191979D-821C-4EA8-B021-2DA1D859A7C5}" = GuardedID
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A54F806B-A2E1-4794-A7FE-365167EC67CB}" = Masque IGT Slots Little Green Men
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AA468551-1794-42FE-B504-C41D75EEBDF2}_is1" = Partition Wizard Home Edition 5.0
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}" = Nero BurnLite 10
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C268B5E1-A5DA-11DF-A289-005056C00008}" = Paragon Backup & Recovery™ 2011 (Advanced) Free
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E6A9840C-6FDA-4CAD-A783-6A7E73185094}" = HoDoKu
"{E6B43401-E818-4961-AFED-118DD8E87642}" = RAF
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4194A69-7B8F-4C9B-BDFF-E55126C9200F}_is1" = Anti-Malware Toolkit 1.13.326
"{FC279721-37A6-4777-AFD8-7A56681EBA14}" = Expert PDF 7 Reader
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"1ClickDownload" = FirstRowSportApp
"Acer Assist" = Acer Assist
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Aimersoft Video Studio Express_is1" = Aimersoft Video Studio Express(Build [removed])
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.17
"Android SDK Tools" = Android SDK Tools
"Anti-Twin 2012-06-23 06.28.20" = Anti-Twin (Installation 6/23/2012)
"AU11_is1" = Advanced Uninstaller PRO - Version 11
"avast" = avast! Internet Security
"Belarc Advisor" = Belarc Advisor 8.1
"Best of Slots II" = Best of Slots II
"BFGC" = Big Fish Games: Game Manager
"BFG-Gardenscapes - Mansion Makeover" = Gardenscapes: Mansion Makeover™
"BFG-Spirits of Mystery - Song of the Phoenix" = Spirits of Mystery: Song of the Phoenix
"bSaving" = bSaving
"BurnAware Home_is1" = BurnAware Home 4.3
"claro" = Claro LTD toolbar
"Coupon Companion" = Coupon Companion
"Easy Duplicate Finder_is1" = Easy Duplicate Finder v. 3.2
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"FinePix Genie_is1" = FUJIFILM MyFinePix Studio 2.0
"FrostWire 5" = FrostWire 5.3.9
"GamesBar" = GamesBar [removed]
"Google Chrome" = Google Chrome
"Gospel_Internet_Radio Toolbar" = Gospel Internet Radio Toolbar
"Hotkey Utility" = Hotkey Utility
"Identity Card" = Identity Card
"IDrive_is1" = IDrive version 3.4.0 April 05, 2011
"ImgBurn" = ImgBurn
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}" = Acer Backup Manager
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"Jaangle music management" = Jaangle music management
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.2.0 (Standard)
"MacX HD Video Converter Pro For Windows_is1" = MacX HD Video Converter Pro For Windows 3.12.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Maps_Bar Toolbar" = Maps Bar Toolbar
"Minefield (4.0b4pre)" = Minefield (4.0b4pre)
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenDNS Updater" = OpenDNS Updater 2.2.1
"PdaNet_is1" = PdaNet for Android 3.50
"Picasa 3" = Picasa 3
"PokerStars" = PokerStars
"PokerStars.net" = PokerStars.net
"PunkBusterSvc" = PunkBuster Services
"Quackle_is1" = Quackle 0.96 [Beta]
"Revo Uninstaller" = Revo Uninstaller 1.93
"Secunia PSI" = Secunia PSI (2.0.0.4003)
"SpiderOak" = SpiderOak
"SpywareBlaster_is1" = SpywareBlaster 4.5
"Surf Canyon" = Fast Search
"SystemRequirementsLab" = System Requirements Lab
"VideoPerformer" = VideoPerformer
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 7.0.0
"WinX HD Video Converter Deluxe_is1" = WinX HD Video Converter Deluxe 3.12.4
"WinX YouTube Downloader 3.0.3_is1" = WinX YouTube Downloader 3.0.3
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 6.21
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .

Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .

Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 13
Description =

Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 13
Description =

Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 8193
Description =

Error - 11/16/2012 7:29:59 PM | Computer Name = Family | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ System Events ]
Error - 11/16/2012 1:32:58 PM | Computer Name = Family | Source = Service Control Manager | ID = 7000
Description = The avast! Firewall service failed to start due to the following error:
%%1053

Error - 11/16/2012 1:42:54 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 11/16/2012 9:51:00 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 11/16/2012 10:21:27 PM | Computer Name = Family | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:18:00 PM on ?11/?16/?2012 was unexpected.

Error - 11/16/2012 10:21:05 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 11/17/2012 12:23:46 AM | Computer Name = Family | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 11/17/2012 12:33:49 PM | Computer Name = Family | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Netman service.

Error - 11/17/2012 8:01:41 PM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.

Error - 11/17/2012 11:45:44 PM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.

Error - 11/18/2012 12:25:58 AM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.


< End of report >

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-11-18 02:05:01
—————————–
02:05:01.676 OS Version: Windows x64 6.1.7601 Service Pack 1
02:05:01.676 Number of processors: 2 586 0x602
02:05:01.677 ComputerName: FAMILY UserName: Bryan
02:05:03.355 Initialize success
02:05:03.428 AVAST engine defs: 12111800
02:05:36.962 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000070
02:05:36.964 Disk 0 Vendor: ST375052 CC44 Size: 715404MB BusType: 3
02:05:36.984 Disk 0 MBR read successfully
02:05:36.986 Disk 0 MBR scan
02:05:36.989 Disk 0 unknown MBR code
02:05:36.999 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 14000 MB offset 2048
02:05:37.014 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 28674048
02:05:37.019 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 701302 MB offset 28878848
02:05:37.032 Disk 0 scanning C:\Windows\system32\drivers
02:05:46.645 Service scanning
02:06:02.718 Modules scanning
02:06:02.724 Disk 0 trace - called modules:
02:06:02.748 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys
02:06:02.752 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004962790]
02:06:02.756 3 CLASSPNP.SYS[fffff88001bc743f] -> nt!IofCallDriver -> [0xfffffa80046a4e40]
02:06:02.761 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\00000070[0xfffffa8004699530]
02:06:04.358 AVAST engine scan C:\Windows
02:06:06.480 AVAST engine scan C:\Windows\system32
02:08:20.831 AVAST engine scan C:\Windows\system32\drivers
02:08:33.052 AVAST engine scan C:\Users\Bryan
02:10:18.374 Disk 0 MBR has been saved successfully to "C:\Users\Bryan\Desktop\MBR.dat"
02:10:18.383 The log file has been saved successfully to "C:\Users\Bryan\Desktop\aswMBR.txt"


The attachment is also added in the manage current attahcments menu. THank You.
Hi Robybel, Thank You for responding so quickly. Here are the logs you requested.

OTL logfile created on: 11/18/2012 1:39:57 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 52.46% Memory free
7.50 Gb Paging File | 4.91 Gb Available in Paging File | 65.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 547.20 Gb Free Space | 79.90% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Bryan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Coupon Companion\Coupon Companion-bg.exe (215 Apps)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\clarosrv.exe (Montera Technologeis LTD)
PRC - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe (Oberon Media )
PRC - C:\Windows\SysWOW64\schtasks.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
PRC - C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\spext.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avutil-51.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avformat-54.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avcodec-54.dll ()
MOD - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\escortShld.dll ()
MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\Program Files (x86)\WOT\WOT.dll ()
MOD - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:64bit: - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Browser Manager) – C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (IDriveE Service) – C:\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (nvsvc) – C:\Windows\SysWOW64\nvvsvc.exe ()
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (GameConsoleService) – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswNdis2) – C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (aswFW) – C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswNdis) – C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:64bit: - (pneteth) – C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (GIDv2) – C:\Windows\SysNative\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadserd) – C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Uim_IM) – C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (UimBus) – C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:64bit: - (hotcore3) – C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sscdserd) – C:\Windows\SysNative\drivers\sscdserd.sys (MCCI Corporation)
DRV:64bit: - (sscdmdm) – C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) – C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) – C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (PCGenFam) – C:\Windows\SysNative\drivers\PCGenFAM.sys (Soluto LTD.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiKF622) – C:\Windows\SysNative\drivers\SaiKF622.sys (Saitek)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (VaneFltr) – C:\Windows\SysNative\drivers\Lachesis.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV - (GEARAspiWDM) – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\URLSearchHook: {a8a9d26a-734f-467a-8907-176f9c5bdf56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {fe337d7b-1447-4780-9a52-48bdac438235} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT1259247

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C8 E7 16 3F C0 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshareus.my-quick-search.com/search…s}&srch;=dsp
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerm…000002637bd3942
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…56-0F484A5B109E
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" = http://search.comcast.net/search/?cat=Web&…q={searchTerms}
IE - HKCU\..\SearchScopes\{281534E3-35BD-4B33-B445-24865046DE66}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{4A88F9EE-674B-46AE-9562-34F23715B388}: "URL" = http://www.bing.com/search?FORM=UP09DF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{53AD41BF-FFF3-49EB-89DF-C13AFED99786}: "URL" = http://websearch.shopathome.com?user_id=%g…q={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{6AB6D437-7F6D-4345-9B6C-E2D711B76132}: "URL" = http://www.google.com/search?sourceid=ie7&…;rlz=1I7ACZZ_en
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={8E35D18…mp;d=2012-06-17 23:22:47&v;=11.1.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{D5AC17B8-504C-41C5-9BF1-492AE1D6F4D7}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{EF1EE071-9EAD-44DD-A0C9-8C51EA637D51}: "URL" = http://search.yahoo.com/search?p={searchte…42,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Claro Search"
FF - prefs.js..browser.search.selectedEngine: "Claro Search"
FF - prefs.js..keyword.URL: "http://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=KW_ss&mntrId;=e075d4f6000000000000002637bd3942&q;="
FF - prefs.js..browser.search.order.1: "Claro Search"
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=HP_ss&mntrId;=e075d4f6000000000000002637bd3942"
FF - prefs.js..browser.search.selectedEngine: "XFINITY"
FF - prefs.js..browser.search.defaultenginename: "XFINITY"


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@GamingWonderland.com/Plugin: C:\Program Files (x86)\GamingWonderland\bar\1.bin\NPgtStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.91: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\npDisplayEngine: C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll ( )
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/08/06 10:55:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\GamingWonderland\bar\1.bin [2012/11/16 16:05:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Components: C:\Program Files (x86)\Minefield\components [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Plugins: C:\Program Files (x86)\Minefield\plugins [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/11/18 01:26:39 | 000,000,000 | —D | M]

[2012/07/04 22:52:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions
[2010/06/10 20:24:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/04 22:52:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/11/18 01:26:53 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions
[2012/11/18 01:26:54 | 000,000,000 | —D | M] ("Coupon Companion") – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/18 01:26:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/18 01:26:36 | 000,000,000 | —D | M] (Claro Toolbar) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/07/04 22:53:08 | 000,000,000 | —D | M] (Songbird Toolbar, Powered by Ask.com) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2011/11/29 23:56:34 | 000,000,000 | —D | M] (We-Care Reminder) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\wecarereminder@bryan
[2012/11/18 01:26:53 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]\chrome\content\extensionCode
[2012/10/14 08:56:22 | 000,214,127 | —- | M] () (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/07/04 22:53:08 | 000,002,335 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\askcom.xml
[2012/11/18 01:26:39 | 000,002,514 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\browsemngr.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.claro-search.com/?affID=116695&…000002637bd3942
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\background/registryAccess.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U35 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Display Engine v2 (Enabled) = C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Songbird Toolbar = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\
CHR - Extension: FreeHDSport.TV = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok\1.1_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl\1.1_0\
CHR - Extension: avast! WebRep = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: We-Care Reminder Lite = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: Yontoo = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.20.40\crossrider
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.20.40\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\

O1 HOSTS File: ([2012/07/12 17:16:43 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2:64bit: - BHO: (Reg Error: Value error.) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Reg Error: Value error. File not found
O2:64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O2 - BHO: (Claro LTD Helper Object) - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll (Montera Technologeis LTD)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Coupon Companion) - {11111111-1111-1111-1111-110011441193} - C:\Program Files (x86)\Coupon Companion\Coupon Companion.dll (215 Apps)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Reg Error: Value error.) - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - Reg Error: Value error. File not found
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Claro LTD Toolbar) - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\claroTlbr.dll (Montera Technologeis LTD)
O3 - HKLM\..\Toolbar: (GamingWonderland) - {a899079d-206f-43a6-be6a-07e0fa648ea0} - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Gospel Internet Radio Toolbar) - {A8A9D26A-734F-467A-8907-176F9C5BDF56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PLD_FrameworkRun] C:\Windows\SysNative\OEM\_NowIntoDT.vbs ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [HostsServer] C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWOW64\StikyNot.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O15 - HKCU\..Trusted Domains: bleacherreport.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hoptoadapp.com ([]https in Trusted sites)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://gamesville.worldwinner.com/games/v4…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} http://www.worldwinner.com/games/v68/clue/clue.cab (Clue Control)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} http://www.worldwinner.com/games/v42/tilecity/tilecity.cab (Tilecity Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} http://www.worldwinner.com/games/v43/paint/paint.cab (Paint Control)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab (SysInfo Class)
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab (CPlayFirstSweetopiaControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\rebinfo - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\rebinfo - No CLSID value found
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/11/18 01:37:00 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:26:55 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Coupon Companion
[2012/11/18 01:26:50 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Claro
[2012/11/18 01:26:49 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
[2012/11/18 01:26:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Coupon Companion
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Claro LTD
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012/11/16 17:46:35 | 000,000,000 | —D | C] – C:\Users\Bryan\.idlerc
[2012/11/16 03:52:29 | 000,132,864 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/11/16 03:52:14 | 000,262,656 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/11/16 03:52:13 | 000,012,368 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswNdis.sys
[2012/11/16 03:38:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012/11/16 02:06:30 | 000,370,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/11/16 02:06:30 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/11/16 02:06:25 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/11/16 02:06:23 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/11/16 02:06:21 | 000,984,144 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/11/16 02:06:20 | 000,071,600 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/11/16 02:05:55 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/11/16 02:05:54 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/11/16 01:07:04 | 000,000,000 | —D | C] – C:\ProgramData\GID
[2012/11/14 22:18:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2012/11/14 10:39:30 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Secunia PSI
[2012/11/14 08:29:21 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/11/14 08:29:21 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2012/11/14 08:28:38 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2012/11/14 08:28:37 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2012/11/14 08:28:37 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2012/11/14 08:28:36 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2012/11/14 08:28:36 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2012/11/14 08:28:36 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2012/11/14 08:28:36 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2012/11/14 08:28:36 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2012/11/14 08:28:36 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2012/11/14 08:28:35 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2012/11/14 08:28:35 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2012/11/14 08:28:35 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2012/11/14 08:28:35 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2012/11/14 08:28:35 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2012/11/14 08:28:35 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2012/11/14 08:28:35 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2012/11/14 08:28:35 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2012/11/14 08:28:35 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2012/11/14 08:28:35 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2012/11/14 08:28:35 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2012/11/14 08:28:35 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2012/11/14 08:28:34 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2012/11/14 08:20:10 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/11/14 08:20:10 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/11/14 08:20:09 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/11/14 08:20:09 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/11/14 08:20:09 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/11/14 08:20:09 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/11/14 08:20:09 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/11/14 08:20:09 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/11/14 08:20:08 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/11/14 08:20:08 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/11/14 08:20:08 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/11/14 08:20:08 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/11/14 08:20:07 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/11/14 08:20:07 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/11/14 08:20:07 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/11/14 08:15:34 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2012/11/14 08:15:33 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2012/11/14 08:15:33 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2012/11/14 08:15:33 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/11/14 08:14:38 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2012/11/14 08:14:15 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2012/11/14 08:14:15 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2012/11/14 08:14:15 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2012/11/14 08:14:14 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2012/11/14 08:14:04 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/11/14 08:14:04 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/11/14 08:14:01 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2012/11/14 08:14:01 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2012/11/13 21:03:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderland
[2012/11/10 21:31:14 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/11/10 21:30:41 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpiderOak
[2012/11/10 21:30:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpiderOak
[2012/11/01 22:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\bSaving
[2012/10/25 20:56:30 | 000,000,000 | —D | C] – C:\Users\Bryan\Documents\Aimersoft Video Studio Express
[2012/10/25 20:56:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2012/10/25 20:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Aimersoft
[2012/10/25 03:12:26 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:40:00 | 000,108,008 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/10/19 19:00:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/10/19 18:59:38 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/10/19 18:59:38 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/10/19 18:59:38 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/10/19 18:58:12 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/07/12 09:14:08 | 003,405,744 | —- | C] (ESET) – C:\Users\Bryan\OnlineScanner.ocx
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/18 01:39:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/18 01:37:00 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:29:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/18 01:28:23 | 000,001,346 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | M] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | M] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/18 00:53:55 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/18 00:50:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/17 10:52:07 | 000,003,084 | —- | M] () – C:\Windows\Sandboxie.ini
[2012/11/16 22:03:47 | 000,779,306 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/16 22:03:47 | 000,660,296 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/11/16 22:03:47 | 000,121,224 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/11/16 18:29:57 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 18:29:57 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 18:21:05 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2012/11/16 16:36:34 | 000,002,120 | —- | M] () – C:\scu.dat
[2012/11/16 09:41:54 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/11/16 03:38:39 | 000,001,962 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/16 03:09:36 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/11/16 03:09:36 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/11/16 03:07:02 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:31 | 000,001,110 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 10:30:05 | 000,002,439 | —- | M] () – C:\Users\Bryan\Desktop\Advanced Uninstaller PRO 11.lnk
[2012/11/14 09:40:39 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 08:43:02 | 000,334,096 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/05 13:30:02 | 005,770,487 | —- | M] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/10/30 15:51:56 | 000,059,728 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/10/30 15:51:55 | 000,984,144 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/10/30 15:51:55 | 000,370,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/10/30 15:51:55 | 000,262,656 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/10/30 15:51:55 | 000,071,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/10/30 15:51:55 | 000,021,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2012/10/30 15:51:53 | 000,132,864 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/10/30 15:51:53 | 000,025,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/10/30 15:51:07 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/10/30 15:50:59 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/10/30 15:50:30 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/10/29 14:46:59 | 000,344,696 | —- | M] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/29 14:42:02 | 000,001,021 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/10/29 10:11:08 | 000,001,121 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.net.lnk
[2012/10/29 10:11:06 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\PokerStars.net.lnk
[2012/10/27 08:07:03 | 000,001,430 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:03 | 000,001,406 | —- | M] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | M] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/10/25 03:12:26 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:39:53 | 000,108,008 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/10/23 07:39:52 | 001,034,216 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npdeployJava1.dll
[2012/10/23 07:39:52 | 000,916,456 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/18 01:28:23 | 000,001,346 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | C] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | C] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:05:06 | 000,002,120 | —- | C] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | C] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:30 | 000,001,110 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 21:55:30 | 000,001,073 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/11/14 08:29:23 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 08:15:33 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/05 12:34:15 | 005,770,487 | —- | C] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/10/29 14:46:53 | 000,344,696 | —- | C] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/27 08:07:03 | 000,001,430 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:02 | 000,001,406 | —- | C] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | C] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/09/14 17:11:09 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/07/12 13:48:22 | 000,000,839 | —- | C] () – C:\Users\Bryan\AppData\Roaming\result.db
[2012/07/12 09:14:18 | 000,000,172 | —- | C] () – C:\Users\Bryan\OnlineScanner.inf
[2012/05/20 21:59:25 | 000,000,000 | —- | C] () – C:\Users\Bryan\cd
[2012/02/15 02:14:35 | 000,000,000 | —- | C] () – C:\Users\Bryan\NetStat
[2012/02/08 03:10:36 | 000,003,084 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/12/28 13:15:52 | 000,000,151 | —- | C] () – C:\Users\Bryan\AppData\Roaming\burnaware.ini
[2011/12/23 14:46:15 | 000,005,632 | —- | C] () – C:\Users\Bryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 22:33:11 | 000,000,000 | —- | C] () – C:\Windows\Ransom.INI
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/07/27 02:20:24 | 000,000,000 | —- | C] () – C:\Users\Bryan\AppData\Local\{E6301488-4DE8-441E-9F4B-23956CD1A782}
[2011/05/18 11:08:35 | 000,148,936 | —- | C] () – C:\Windows\hpoins19.dat
[2011/04/05 08:40:01 | 000,026,032 | —- | C] () – C:\Windows\SysWow64\IDriveEXceedCryReg.exe
[2011/04/05 08:39:57 | 000,055,808 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2011/01/14 21:10:47 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/01/02 21:40:04 | 000,776,466 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/13 18:08:49 | 000,000,036 | —- | C] () – C:\Users\Bryan\AppData\Local\housecall.guid.cache
[2010/05/08 09:16:55 | 000,007,594 | —- | C] () – C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg
[2010/05/03 12:09:55 | 000,000,632 | RHS- | C] () – C:\Users\Bryan\ntuser.pol
[2010/05/02 13:44:28 | 000,001,102 | —- | C] () – C:\Users\Bryan\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011/05/09 20:03:26 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Reels
[2011/05/09 19:55:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Spins
[2010/08/12 19:25:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\abelhadigital.com
[2011/04/17 10:17:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Absolute Poker
[2010/05/01 21:39:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Acer
[2012/03/03 11:35:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\AdamOutler
[2012/09/01 13:26:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Amazon
[2011/12/22 15:52:32 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Auslogics
[2012/06/07 09:25:37 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Azureus
[2012/03/14 13:24:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Babylon
[2012/11/18 01:26:51 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Claro
[2011/05/27 02:43:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DiamondVipClub
[2011/03/18 22:52:47 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Diceland
[2012/11/18 01:28:27 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Digiarty
[2011/04/04 14:14:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DriverCure
[2012/11/14 10:20:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Dropbox
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Easy Duplicate Finder
[2012/09/07 09:51:08 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Expert PDF 7
[2011/12/23 19:26:48 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\FrostWire
[2012/11/16 01:16:53 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ID Vault
[2011/12/28 14:57:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ImgBurn
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Jaangle
[2010/05/01 21:39:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Leadertech
[2010/05/12 10:46:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Locate32
[2010/05/10 11:07:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Masque
[2011/05/20 20:10:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Mayflower
[2011/12/23 14:43:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\MusicNet
[2010/11/12 14:55:41 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Oberon Media
[2010/07/14 17:01:02 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\OpenDNS Updater
[2012/11/14 22:21:29 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Opera
[2010/07/22 11:00:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Panda Security
[2011/04/04 14:14:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ParetoLogic
[2010/12/28 17:39:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Pogo
[2010/12/20 13:04:13 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Razer
[2010/12/25 13:19:33 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Returnil
[2011/05/06 18:53:12 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\RomeCasino
[2011/11/23 17:23:44 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SecondLife
[2011/06/11 17:14:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Software Inspection Library
[2012/07/04 22:52:11 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Songbird2
[2012/11/10 23:05:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/03/25 07:02:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Spotify
[2012/01/04 19:59:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\streamWriter
[2011/12/18 22:58:00 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SystemNucleus
[2010/05/02 13:44:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Template
[2010/06/10 20:24:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Thunderbird
[2011/06/11 14:41:16 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Vegascasino21
[2011/05/06 18:54:35 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\VTExtra
[2011/12/14 00:47:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\wargaming.net
[2010/05/02 13:46:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WildTangent
[2010/10/27 17:24:01 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Windows Live Writer
[2012/07/31 18:32:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WinPatrol
[2012/01/21 09:22:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wise Registry Cleaner
[2012/08/06 14:31:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wondershare
[2010/06/25 11:03:34 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\X-Setup Pro
[2012/07/22 22:10:40 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\YourFileDownloader

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe

< MD5 for: EXPLORER.EXE >
[2011/02/25 22:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 21:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 17:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 21:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 21:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\ERDNT\cache86\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 22:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 04:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 22:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 22:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 21:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 05:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 22:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 21:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 17:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 22:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 22:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 22:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\ERDNT\cache64\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\ERDNT\cache86\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 17:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 17:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\ERDNT\cache64\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\ERDNT\cache64\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 17:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/27 23:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 22:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST375052 8AS SCSI Disk Device
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- SM/xD/SD/MMC/MS USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 14.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 14681112576
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 685.00GB
Starting Offset: 14785970176
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:6DCFAD3B
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:987CE5C8
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:25FF8A61
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:B7910E41
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:3E996AD9
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FD80436E
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:DC3A4904
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D822654B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:C966DE9F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:5304CF6F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:11590865
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C1C705A1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B84EF836
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:9B7E8561
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:5095D8B1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:30C74695
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:7C3E753C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F36D7549
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2E81DAB7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0256104B
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:9373B271
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:54997B77
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:1960DAF2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C5B78274
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3B3A302E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F54781BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F3AB0B43
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E0648389
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ABCD2B94
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:962FBFE7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2A8CD561
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:2881AFC0
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3F3BEF8F
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:F3239111
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

OTL Extras logfile created on: 11/18/2012 1:39:57 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 52.46% Memory free
7.50 Gb Paging File | 4.91 Gb Available in Paging File | 65.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 547.20 Gb Free Space | 79.90% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{065ABD98-F5B7-4A5E-9F32-C470E8CFE382}" = rport=10243 | protocol=6 | dir=out | app=system |
"{09C3AD09-2DE4-43FE-8960-6B5672570DFC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{13661FAA-49B2-42E0-875A-599ED504E92F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1A52733A-27F1-497E-8319-75C23620B1F6}" = lport=139 | protocol=6 | dir=in | app=system |
"{1F6D207D-AAC9-4F8F-B7CB-24712CE1AF9B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1FD35719-8649-4DD6-95AC-0B62A9D193AB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{531ED8DA-0EEC-426D-A57F-A60BEE904626}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{584774FE-733B-498A-B235-2CFA9EA05DFA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{683C4E01-A4CC-41EC-9A81-2FF4A864D6EB}" = lport=138 | protocol=17 | dir=in | app=system |
"{6D0D193C-12FB-48C1-AF5F-FB53BC34500B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6EC57AFE-CAF4-461B-B793-DE2BE4D5934E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7242F2F1-4E72-4318-97E3-4D29EE44B976}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{82314B2C-F18A-4E5E-838D-0381DFBC1A36}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{90F7B26B-35C5-4734-806D-62D2F1DA0CA0}" = rport=138 | protocol=17 | dir=out | app=system |
"{98318391-E3BE-4D8F-AA65-7A453BD3AD18}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A8D74D3-7169-43E0-A350-6EB48B66E505}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BC629E68-C9CD-47D1-BAFE-BD8F83BBE697}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C058D27F-27BF-4BDB-B400-05627DE0B792}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D18CE43B-6FDA-4614-9470-FB2C43D3CB45}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DDF5C05B-D1E0-4247-A25D-73B4661B82A2}" = lport=445 | protocol=6 | dir=in | app=system |
"{DE6F0476-F00A-4AFE-9821-0C1504851E51}" = lport=137 | protocol=17 | dir=in | app=system |
"{E08385CC-CA86-4090-BB2E-486CC00A5E1F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E1FDE63C-4A1F-4CBF-B104-63EC256602A1}" = rport=137 | protocol=17 | dir=out | app=system |
"{F19F2EE7-2682-454B-8532-90C700B500A8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F5C7536A-A119-4B89-A912-D80700252437}" = rport=445 | protocol=6 | dir=out | app=system |
"{F80A712E-97E0-47DD-AE8D-D177F2ED184C}" = rport=139 | protocol=6 | dir=out | app=system |
"{FF4A6083-17C4-4127-960F-82927DF1AD22}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027F670E-DA28-4121-8644-C5BF657B9744}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{065E72E2-D7BC-47E7-8E3F-4D00819BB823}" = protocol=17 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"{0EE68060-7537-4819-B2CA-3FFFA326A5C7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{13B5C18E-46D6-4465-A5C6-CBD122BD9068}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1423C54D-14E4-4CD2-BB1A-C4848E700804}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{16B64EE6-7938-462E-940D-41A6339B55E6}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{250FA4EE-2370-46AF-BB1C-EB2FFA5F6E0D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2D76D381-BF79-4C06-8931-57204966F73E}" = protocol=6 | dir=out | app=system |
"{2E5F50E0-1812-4576-ADFF-7A2166E5C1FC}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{31007B4D-5B6D-41DA-A744-041F0710615C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{356EE293-DC3E-4B53-945A-91BDD5E5A75A}" = protocol=17 | dir=in | app=c:\program files (x86)\pokerstars\tracer.exe |
"{3F22A01A-0239-41B2-B4CD-154E99EBF045}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4099F175-2B40-4EE1-85E2-9E5BCC740D8E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{40FFECD8-227F-44A4-AD65-D72A018884D2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{41DB31FE-5E40-48E5-B458-7F3B15F05559}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{4F57BEDE-EB17-47DB-A5DD-8EFD3677D025}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{5715D280-6046-4F27-9B89-583D23F9E8B0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5FC80437-14B8-4AF2-8DD6-55D937C3767F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{60907F23-55BD-47D8-BE04-CEC4E2E6143F}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{6351A2D8-7E67-4FEF-BCFF-273427166F07}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{6C613935-5B49-4398-95CB-A46500153830}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{780095B7-9AA0-42F3-9762-77EF830EEC50}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8094DA2D-BFFE-4BDC-96BB-3A363516B651}" = protocol=6 | dir=in | app=c:\program files (x86)\pokerstars\tracer.exe |
"{8DEB4056-33BE-4031-806D-662922D8732B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{92516AF0-311C-44A6-82A1-04416BF90148}" = protocol=6 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"{94E43188-9DA4-42CE-9666-75EA1FD1668D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B0385632-AB92-4C31-AC96-96228000A83D}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{B8AF4B8A-1A3B-48CF-AFB4-0AF70DAF3B12}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD496999-4091-4EE5-8F34-1CD2A9F64BB2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{BEE511C4-9B46-4C73-9DB7-41D04FC3A008}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C384D863-4D35-484D-B8D7-4020E27DF58A}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{C698EEDD-0187-4CEA-8672-AFEB1DB1BE73}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C7F3647A-82C0-48D7-A1E7-CAB6306F1E97}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{D242DAD3-E042-407C-8337-1DEE83881CB7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DD5F8589-2D81-4CAB-BB83-EE71A728F13F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E36F2CDD-33F3-4109-80E1-33829E2112EA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F6FDC3BC-9361-4131-BD0F-C60DE7590737}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{F74540C2-915A-4ECD-BD14-F57B4F67B18C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FC98856A-4506-4762-9F47-D018171FADC5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"TCP Query User{1DFCF2C7-5C46-4E8A-BF0F-C5662076C54C}C:\program files (x86)\ifreetv\ifreetv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ifreetv\ifreetv.exe |
"TCP Query User{5F6D312D-8EE7-455D-9F23-8854320F20EF}C:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{8C5DFD30-3DA5-4605-95AB-476C4AF70387}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{7E5B9ECA-8A8D-4201-9591-D2C79AB4606C}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{E140EAAD-4D6B-48FC-9146-AD18C5FC118E}C:\program files (x86)\ifreetv\ifreetv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ifreetv\ifreetv.exe |
"UDP Query User{F1E9625B-B4A1-46A7-BC69-0D8239D14D4E}C:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{23170F69-40C1-2702-0922-000001000000}" = 7-Zip 9.22 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417009FF}" = Java 7 Update 9 (64-bit)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{47E5588F-C3A0-11DE-9857-005056C00008}" = Paragon Partition Manager™ 2010 Free Edition
"{563F041C-DFDB-437B-A1E8-E141E0906076}" = Microsoft IntelliPoint 8.0
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CBBBC4D-B0B6-49DB-A421-98C65080D8EE}" = Eraser 6.0.7.1893
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{A62F9CD0-B2E0-4F2A-88F2-79254A3C8539}" = WinPatrol
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{C0DA129B-1E45-494D-A362-5CD0109C306B}" = WOT for Internet Explorer
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D40DBBFD-B87E-4E45-B15F-753B75C0D7F8}_is1" = Spencerberus System Nucleus
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"HitmanPro36" = HitmanPro 3.6
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Recuva" = Recuva
"Sandboxie" = Sandboxie 3.64 (64-bit)
"SDEPRO20_is1" = SDExplorer 2.1
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{067B277E-F94B-4F04-B380-BA967C00377C}_is1" = MiniTool Partition Wizard Home Edition 6.0
"{069B290F-5398-4629-A009-85B4BCB4B1B9}" = Claro Chrome Toolbar
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = Browser Manager
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java™ 6 Update 37
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{30075A70-B5D2-440B-AFA3-FB2021740121}" = Backup Manager Advance
"{30E10267-3B27-42CC-B727-681DEBD30C4D}" = Clean Water Action TriMini Reminder by We-Care.com v5.0.3.2
"{31228E31-2BFF-11D2-8866-00805F0D9D40}" = QPST
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{44A69352-33DD-405E-ADB8-2D768643BBAE}_is1" = AnyBizSoft PDF to Word (Build 3.0.0)
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CB2511D-A074-40E0-A5ED-A875EBBDDF49}" = BotHunter
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6ED53E0C-EAC0-4F0F-947D-6BA817E4C8C3}" = HostsMan 3.2.73
"{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1" = AppGraffiti
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110194827}" = Jewel Quest
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111405753}" = Super Collapse 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119803590}" = Vacation Quest - The Hawaiian Islands
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-510005691}" = Vacation Quest Australia
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}" = Nero BurnLite 10
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88603FC0-6B3C-442D-981E-E3D49F083548}_is1" = NovaBench 3.0.4
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9191979D-821C-4EA8-B021-2DA1D859A7C5}" = GuardedID
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A54F806B-A2E1-4794-A7FE-365167EC67CB}" = Masque IGT Slots Little Green Men
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AA468551-1794-42FE-B504-C41D75EEBDF2}_is1" = Partition Wizard Home Edition 5.0
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}" = Nero BurnLite 10
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C268B5E1-A5DA-11DF-A289-005056C00008}" = Paragon Backup & Recovery™ 2011 (Advanced) Free
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E6A9840C-6FDA-4CAD-A783-6A7E73185094}" = HoDoKu
"{E6B43401-E818-4961-AFED-118DD8E87642}" = RAF
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4194A69-7B8F-4C9B-BDFF-E55126C9200F}_is1" = Anti-Malware Toolkit 1.13.326
"{FC279721-37A6-4777-AFD8-7A56681EBA14}" = Expert PDF 7 Reader
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"1ClickDownload" = FirstRowSportApp
"Acer Assist" = Acer Assist
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Aimersoft Video Studio Express_is1" = Aimersoft Video Studio Express(Build [removed])
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.17
"Android SDK Tools" = Android SDK Tools
"Anti-Twin 2012-06-23 06.28.20" = Anti-Twin (Installation 6/23/2012)
"AU11_is1" = Advanced Uninstaller PRO - Version 11
"avast" = avast! Internet Security
"Belarc Advisor" = Belarc Advisor 8.1
"Best of Slots II" = Best of Slots II
"BFGC" = Big Fish Games: Game Manager
"BFG-Gardenscapes - Mansion Makeover" = Gardenscapes: Mansion Makeover™
"BFG-Spirits of Mystery - Song of the Phoenix" = Spirits of Mystery: Song of the Phoenix
"bSaving" = bSaving
"BurnAware Home_is1" = BurnAware Home 4.3
"claro" = Claro LTD toolbar
"Coupon Companion" = Coupon Companion
"Easy Duplicate Finder_is1" = Easy Duplicate Finder v. 3.2
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"FinePix Genie_is1" = FUJIFILM MyFinePix Studio 2.0
"FrostWire 5" = FrostWire 5.3.9
"GamesBar" = GamesBar [removed]
"Google Chrome" = Google Chrome
"Gospel_Internet_Radio Toolbar" = Gospel Internet Radio Toolbar
"Hotkey Utility" = Hotkey Utility
"Identity Card" = Identity Card
"IDrive_is1" = IDrive version 3.4.0 April 05, 2011
"ImgBurn" = ImgBurn
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}" = Acer Backup Manager
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"Jaangle music management" = Jaangle music management
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.2.0 (Standard)
"MacX HD Video Converter Pro For Windows_is1" = MacX HD Video Converter Pro For Windows 3.12.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Maps_Bar Toolbar" = Maps Bar Toolbar
"Minefield (4.0b4pre)" = Minefield (4.0b4pre)
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenDNS Updater" = OpenDNS Updater 2.2.1
"PdaNet_is1" = PdaNet for Android 3.50
"Picasa 3" = Picasa 3
"PokerStars" = PokerStars
"PokerStars.net" = PokerStars.net
"PunkBusterSvc" = PunkBuster Services
"Quackle_is1" = Quackle 0.96 [Beta]
"Revo Uninstaller" = Revo Uninstaller 1.93
"Secunia PSI" = Secunia PSI (2.0.0.4003)
"SpiderOak" = SpiderOak
"SpywareBlaster_is1" = SpywareBlaster 4.5
"Surf Canyon" = Fast Search
"SystemRequirementsLab" = System Requirements Lab
"VideoPerformer" = VideoPerformer
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 7.0.0
"WinX HD Video Converter Deluxe_is1" = WinX HD Video Converter Deluxe 3.12.4
"WinX YouTube Downloader 3.0.3_is1" = WinX YouTube Downloader 3.0.3
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 6.21
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .

Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .

Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.

Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .

Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 13
Description =

Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 13
Description =

Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 8193
Description =

Error - 11/16/2012 7:29:59 PM | Computer Name = Family | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ System Events ]
Error - 11/16/2012 1:32:58 PM | Computer Name = Family | Source = Service Control Manager | ID = 7000
Description = The avast! Firewall service failed to start due to the following error:
%%1053

Error - 11/16/2012 1:42:54 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 11/16/2012 9:51:00 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 11/16/2012 10:21:27 PM | Computer Name = Family | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:18:00 PM on ?11/?16/?2012 was unexpected.

Error - 11/16/2012 10:21:05 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 11/17/2012 12:23:46 AM | Computer Name = Family | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 11/17/2012 12:33:49 PM | Computer Name = Family | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Netman service.

Error - 11/17/2012 8:01:41 PM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.

Error - 11/17/2012 11:45:44 PM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.

Error - 11/18/2012 12:25:58 AM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.


< End of report >

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-11-18 02:05:01
—————————–
02:05:01.676 OS Version: Windows x64 6.1.7601 Service Pack 1
02:05:01.676 Number of processors: 2 586 0x602
02:05:01.677 ComputerName: FAMILY UserName: Bryan
02:05:03.355 Initialize success
02:05:03.428 AVAST engine defs: 12111800
02:05:36.962 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000070
02:05:36.964 Disk 0 Vendor: ST375052 CC44 Size: 715404MB BusType: 3
02:05:36.984 Disk 0 MBR read successfully
02:05:36.986 Disk 0 MBR scan
02:05:36.989 Disk 0 unknown MBR code
02:05:36.999 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 14000 MB offset 2048
02:05:37.014 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 28674048
02:05:37.019 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 701302 MB offset 28878848
02:05:37.032 Disk 0 scanning C:\Windows\system32\drivers
02:05:46.645 Service scanning
02:06:02.718 Modules scanning
02:06:02.724 Disk 0 trace - called modules:
02:06:02.748 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys
02:06:02.752 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004962790]
02:06:02.756 3 CLASSPNP.SYS[fffff88001bc743f] -> nt!IofCallDriver -> [0xfffffa80046a4e40]
02:06:02.761 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\00000070[0xfffffa8004699530]
02:06:04.358 AVAST engine scan C:\Windows
02:06:06.480 AVAST engine scan C:\Windows\system32
02:08:20.831 AVAST engine scan C:\Windows\system32\drivers
02:08:33.052 AVAST engine scan C:\Users\Bryan
02:10:18.374 Disk 0 MBR has been saved successfully to "C:\Users\Bryan\Desktop\MBR.dat"
02:10:18.383 The log file has been saved successfully to "C:\Users\Bryan\Desktop\aswMBR.txt"


The attachment is also added in the manage current attahcments menu. THank You.

Attachments:

Hi Bryan A


P2P Programs:

P2P programs are a major source of Malware infections.
From your log I see you have Frostwire We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
If you wish to keep the program(s), please do not use them until your computer is cleaned.

Information regarding the risk of using these programs can be found from here and here

——————————————

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT1259247
    IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshareus.my-quick-search.com/search…s}&srch=dsp
    IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerm…000002637bd3942
    IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…56-0F484A5B109E
    IE - HKCU\..\SearchScopes\{53AD41BF-FFF3-49EB-89DF-C13AFED99786}: "URL" = http://websearch.shopathome.com?user_id=%g…q={searchTerms}
    FF - prefs.js..browser.search.defaultenginename: "Claro Search"
    FF - prefs.js..browser.search.selectedEngine: "Claro Search"
    FF - prefs.js..keyword.URL: "http://www.claro-search.com/?affID=116695&tt=4612_4&babsrc=KW_ss&mntrId=e075d4f6000000000000002637bd3942&q="
    FF - prefs.js..browser.search.order.1: "Claro Search"
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=116695&tt=4612_4&babsrc=HP_ss&mntrId=e075d4f6000000000000002637bd3942"
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/11/18 01:26:39 | 000,000,000 | —D | M]
    [2012/11/18 01:26:54 | 000,000,000 | —D | M] ("Coupon Companion") – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
    [2012/11/18 01:26:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
    [2012/11/18 01:26:36 | 000,000,000 | —D | M] (Claro Toolbar) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
    [2012/07/04 22:53:08 | 000,000,000 | —D | M] (Songbird Toolbar, Powered by Ask.com) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
    [2012/11/18 01:26:53 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]\chrome\content\extensionCode
    [2012/10/14 08:56:22 | 000,214,127 | —- | M] () (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
    [2012/07/04 22:53:08 | 000,002,335 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\askcom.xml
    CHR - homepage: http://www.claro-search.com/?affID=116695&…000002637bd3942
    O2:64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
    O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
    O2:64bit: - BHO: (Reg Error: Value error.) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Reg Error: Value error. File not found
    O2:64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
    O2 - BHO: (Claro LTD Helper Object) - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll (Montera Technologeis LTD)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (Coupon Companion) - {11111111-1111-1111-1111-110011441193} - C:\Program Files (x86)\Coupon Companion\Coupon Companion.dll (215 Apps)
    O2 - BHO: (Reg Error: Value error.) - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - Reg Error: Value error. File not found
    O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Claro LTD Toolbar) - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\claroTlbr.dll (Montera Technologeis LTD)
    O15 - HKCU\..Trusted Domains: bleacherreport.com ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: hoptoadapp.com ([]https in Trusted sites)
    O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [EMPTYFLASH]
    [REBOOT]
    [RESETHOSTS]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.

next

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Next

AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Next

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.



On your next reply please post :
  • JRT.txt
  • AdwCleaner log
  • Combofix log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Well some very weird things have just happened. First I ran the OTL fix w/ the script. Then I couldn't run it again (in fix mode) without the script so I ran it as a scan but didn't check the LOP or Purity boxes. The result of that scan will be posted later. Then I ran JRT and follwed the instructions but it wouldn't let me choose to run it as administrator, instead the command box opened right after it made a back up file but it would run for about a minute and then go away without producing any log. So I did it again and the same thing happened, no logs or results, it just disappeared but it did close any window I had open before it ran.

ADW went perfectly and produced the log. Then I ran ComboFix, I've used Combofix many times in the past so I can say that everything looked good all the way through. Except that once it was done and closed itself out and rebooted it did make the log. However after it closed out after making the log and rebooting I couldn't open any browsers. No matter how I tried no internet window would load, I looked into device manager to make sure that there was nothing wrong with the network adaptors and they were OK. I tried to change my internet from msn to google but nothing opened up windows.

I couldn't even ask what to do because I couldn't get on the internet so I had to do a system restore to the first possible restore point and after that ran I could now log back on but even though the logs from all scans including Combofix were still saved to the desktop the actual links from the desktop were no longer on it as though I had never downloaded those tools. I'm not sure if teh logs I am posting actually reflect the true condition of the system since I had to do the system restore to be able to log back on. What should I do to show the actual condition of the system now. Which scan should I run? I'm sorry for all the trouble but I'm concerned that something very serious is wrong and that the restore may have undone any good your scans and tools may have accomplished.

Awaiting instructions on how to proceed with this. Thank You.

OTL logfile created on: 11/18/2012 10:47:35 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.05 Gb Available Physical Memory | 54.76% Memory free
7.50 Gb Paging File | 5.80 Gb Available in Paging File | 77.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 545.54 Gb Free Space | 79.66% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Bryan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
PRC - C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
MOD - C:\Program Files (x86)\WOT\WOT.dll ()
MOD - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:64bit: - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Browser Manager) – C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (IDriveE Service) – C:\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (nvsvc) – C:\Windows\SysWOW64\nvvsvc.exe ()
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (GameConsoleService) – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswNdis2) – C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (aswFW) – C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswNdis) – C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:64bit: - (pneteth) – C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (GIDv2) – C:\Windows\SysNative\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadserd) – C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Uim_IM) – C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (UimBus) – C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:64bit: - (hotcore3) – C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sscdserd) – C:\Windows\SysNative\drivers\sscdserd.sys (MCCI Corporation)
DRV:64bit: - (sscdmdm) – C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) – C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) – C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (PCGenFam) – C:\Windows\SysNative\drivers\PCGenFAM.sys (Soluto LTD.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiKF622) – C:\Windows\SysNative\drivers\SaiKF622.sys (Saitek)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (VaneFltr) – C:\Windows\SysNative\drivers\Lachesis.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV - (GEARAspiWDM) – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\URLSearchHook: {a8a9d26a-734f-467a-8907-176f9c5bdf56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {fe337d7b-1447-4780-9a52-48bdac438235} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C8 E7 16 3F C0 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerm…000002637bd3942
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" = http://search.comcast.net/search/?cat=Web&…q={searchTerms}
IE - HKCU\..\SearchScopes\{281534E3-35BD-4B33-B445-24865046DE66}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{4A88F9EE-674B-46AE-9562-34F23715B388}: "URL" = http://www.bing.com/search?FORM=UP09DF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{6AB6D437-7F6D-4345-9B6C-E2D711B76132}: "URL" = http://www.google.com/search?sourceid=ie7&…;rlz=1I7ACZZ_en
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={8E35D18…mp;d=2012-06-17 23:22:47&v;=11.1.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{D5AC17B8-504C-41C5-9BF1-492AE1D6F4D7}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{EF1EE071-9EAD-44DD-A0C9-8C51EA637D51}: "URL" = http://search.yahoo.com/search?p={searchte…42,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..browser.search.selectedEngine: "XFINITY"


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@GamingWonderland.com/Plugin: C:\Program Files (x86)\GamingWonderland\bar\1.bin\NPgtStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.91: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\npDisplayEngine: C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll ( )
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/08/06 10:55:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\GamingWonderland\bar\1.bin [2012/11/16 16:05:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Components: C:\Program Files (x86)\Minefield\components [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Plugins: C:\Program Files (x86)\Minefield\plugins [2012/11/14 22:19:04 | 000,000,000 | —D | M]

[2012/07/04 22:52:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions
[2010/06/10 20:24:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/04 22:52:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/11/18 22:38:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions
[2011/11/29 23:56:34 | 000,000,000 | —D | M] (We-Care Reminder) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\wecarereminder@bryan
[2012/11/18 01:26:39 | 000,002,514 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\browsemngr.xml

========== Chrome ==========

CHR - homepage: http://www.claro-search.com/?affID=116695&…000002637bd3942
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.claro-search.com/?affID=116695&…000002637bd3942
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok\1.1_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl\1.1_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\

O1 HOSTS File: ([2012/11/18 22:38:45 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (GamingWonderland) - {a899079d-206f-43a6-be6a-07e0fa648ea0} - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Gospel Internet Radio Toolbar) - {A8A9D26A-734F-467A-8907-176F9C5BDF56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PLD_FrameworkRun] C:\Windows\SysNative\OEM\_NowIntoDT.vbs ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [HostsServer] C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWOW64\StikyNot.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://gamesville.worldwinner.com/games/v4…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} http://www.worldwinner.com/games/v68/clue/clue.cab (Clue Control)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} http://www.worldwinner.com/games/v42/tilecity/tilecity.cab (Tilecity Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} http://www.worldwinner.com/games/v43/paint/paint.cab (Paint Control)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab (SysInfo Class)
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab (CPlayFirstSweetopiaControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\rebinfo - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\rebinfo - No CLSID value found
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/18 22:38:01 | 000,000,000 | —D | C] – C:\_OTL
[2012/11/18 02:02:58 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Bryan\Desktop\aswMBR.exe
[2012/11/18 01:37:00 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:26:50 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Claro
[2012/11/18 01:26:49 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012/11/16 17:46:35 | 000,000,000 | —D | C] – C:\Users\Bryan\.idlerc
[2012/11/16 03:52:29 | 000,132,864 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/11/16 03:52:14 | 000,262,656 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/11/16 03:52:13 | 000,012,368 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswNdis.sys
[2012/11/16 03:38:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012/11/16 02:06:30 | 000,370,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/11/16 02:06:30 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/11/16 02:06:25 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/11/16 02:06:23 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/11/16 02:06:21 | 000,984,144 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/11/16 02:06:20 | 000,071,600 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/11/16 02:05:55 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/11/16 02:05:54 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/11/16 01:07:04 | 000,000,000 | —D | C] – C:\ProgramData\GID
[2012/11/14 22:18:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2012/11/14 10:39:30 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Secunia PSI
[2012/11/14 08:29:21 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/11/14 08:29:21 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2012/11/14 08:28:38 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2012/11/14 08:28:37 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2012/11/14 08:28:37 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2012/11/14 08:28:36 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2012/11/14 08:28:36 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2012/11/14 08:28:36 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2012/11/14 08:28:36 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2012/11/14 08:28:36 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2012/11/14 08:28:36 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2012/11/14 08:28:35 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2012/11/14 08:28:35 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2012/11/14 08:28:35 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2012/11/14 08:28:35 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2012/11/14 08:28:35 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2012/11/14 08:28:35 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2012/11/14 08:28:35 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2012/11/14 08:28:35 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2012/11/14 08:28:35 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2012/11/14 08:28:35 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2012/11/14 08:28:35 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2012/11/14 08:28:35 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2012/11/14 08:28:34 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2012/11/14 08:20:10 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/11/14 08:20:10 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/11/14 08:20:09 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/11/14 08:20:09 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/11/14 08:20:09 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/11/14 08:20:09 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/11/14 08:20:09 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/11/14 08:20:09 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/11/14 08:20:08 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/11/14 08:20:08 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/11/14 08:20:08 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/11/14 08:20:08 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/11/14 08:20:07 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/11/14 08:20:07 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/11/14 08:20:07 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/11/14 08:15:34 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2012/11/14 08:15:33 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2012/11/14 08:15:33 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2012/11/14 08:15:33 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/11/14 08:14:38 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2012/11/14 08:14:15 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2012/11/14 08:14:15 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2012/11/14 08:14:15 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2012/11/14 08:14:14 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2012/11/14 08:14:04 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/11/14 08:14:04 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/11/14 08:14:01 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2012/11/14 08:14:01 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2012/11/13 21:03:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderland
[2012/11/10 21:31:14 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/11/10 21:30:41 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpiderOak
[2012/11/10 21:30:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpiderOak
[2012/11/01 22:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\bSaving
[2012/10/25 20:56:30 | 000,000,000 | —D | C] – C:\Users\Bryan\Documents\Aimersoft Video Studio Express
[2012/10/25 20:56:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2012/10/25 20:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Aimersoft
[2012/10/25 03:12:26 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:40:00 | 000,108,008 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/07/12 09:14:08 | 003,405,744 | —- | C] (ESET) – C:\Users\Bryan\OnlineScanner.ocx
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/18 22:47:28 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/18 22:47:28 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/18 22:44:29 | 000,779,306 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/18 22:44:29 | 000,660,296 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/11/18 22:44:29 | 000,121,224 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/11/18 22:40:42 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/18 22:40:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/18 22:39:57 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2012/11/18 22:39:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/18 22:38:45 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2012/11/18 22:29:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/18 15:04:21 | 000,003,084 | —- | M] () – C:\Windows\Sandboxie.ini
[2012/11/18 02:21:15 | 000,000,471 | —- | M] () – C:\Users\Bryan\Desktop\MBR.zip
[2012/11/18 02:10:18 | 000,000,512 | —- | M] () – C:\Users\Bryan\Desktop\MBR.dat
[2012/11/18 02:03:26 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Bryan\Desktop\aswMBR.exe
[2012/11/18 01:37:00 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:28:23 | 000,001,346 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | M] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | M] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:36:34 | 000,002,120 | —- | M] () – C:\scu.dat
[2012/11/16 09:41:54 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/11/16 03:38:39 | 000,001,962 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/16 03:09:36 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/11/16 03:09:36 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/11/16 03:07:02 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:31 | 000,001,110 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 10:30:05 | 000,002,439 | —- | M] () – C:\Users\Bryan\Desktop\Advanced Uninstaller PRO 11.lnk
[2012/11/14 09:40:39 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 08:43:02 | 000,334,096 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/05 13:30:02 | 005,770,487 | —- | M] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/10/30 15:51:56 | 000,059,728 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/10/30 15:51:55 | 000,984,144 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/10/30 15:51:55 | 000,370,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/10/30 15:51:55 | 000,262,656 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/10/30 15:51:55 | 000,071,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/10/30 15:51:55 | 000,021,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2012/10/30 15:51:53 | 000,132,864 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/10/30 15:51:53 | 000,025,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/10/30 15:51:07 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/10/30 15:50:59 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/10/30 15:50:30 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/10/29 14:46:59 | 000,344,696 | —- | M] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/29 14:42:02 | 000,001,021 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/10/29 10:11:08 | 000,001,121 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.net.lnk
[2012/10/29 10:11:06 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\PokerStars.net.lnk
[2012/10/27 08:07:03 | 000,001,430 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:03 | 000,001,406 | —- | M] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | M] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/10/25 03:12:26 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:39:53 | 000,108,008 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/10/23 07:39:52 | 001,034,216 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npdeployJava1.dll
[2012/10/23 07:39:52 | 000,916,456 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/18 02:21:15 | 000,000,471 | —- | C] () – C:\Users\Bryan\Desktop\MBR.zip
[2012/11/18 02:10:18 | 000,000,512 | —- | C] () – C:\Users\Bryan\Desktop\MBR.dat
[2012/11/18 01:28:23 | 000,001,346 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | C] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | C] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:05:06 | 000,002,120 | —- | C] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | C] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:30 | 000,001,110 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 21:55:30 | 000,001,073 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/11/14 08:29:23 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 08:15:33 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/05 12:34:15 | 005,770,487 | —- | C] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/10/29 14:46:53 | 000,344,696 | —- | C] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/27 08:07:03 | 000,001,430 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:02 | 000,001,406 | —- | C] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | C] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/09/14 17:11:09 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/07/12 13:48:22 | 000,000,839 | —- | C] () – C:\Users\Bryan\AppData\Roaming\result.db
[2012/07/12 09:14:18 | 000,000,172 | —- | C] () – C:\Users\Bryan\OnlineScanner.inf
[2012/05/20 21:59:25 | 000,000,000 | —- | C] () – C:\Users\Bryan\cd
[2012/02/15 02:14:35 | 000,000,000 | —- | C] () – C:\Users\Bryan\NetStat
[2012/02/08 03:10:36 | 000,003,084 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/12/28 13:15:52 | 000,000,151 | —- | C] () – C:\Users\Bryan\AppData\Roaming\burnaware.ini
[2011/12/23 14:46:15 | 000,005,632 | —- | C] () – C:\Users\Bryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 22:33:11 | 000,000,000 | —- | C] () – C:\Windows\Ransom.INI
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/07/27 02:20:24 | 000,000,000 | —- | C] () – C:\Users\Bryan\AppData\Local\{E6301488-4DE8-441E-9F4B-23956CD1A782}
[2011/05/18 11:08:35 | 000,148,936 | —- | C] () – C:\Windows\hpoins19.dat
[2011/04/05 08:40:01 | 000,026,032 | —- | C] () – C:\Windows\SysWow64\IDriveEXceedCryReg.exe
[2011/04/05 08:39:57 | 000,055,808 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2011/01/14 21:10:47 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/01/02 21:40:04 | 000,776,466 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/13 18:08:49 | 000,000,036 | —- | C] () – C:\Users\Bryan\AppData\Local\housecall.guid.cache
[2010/05/08 09:16:55 | 000,007,594 | —- | C] () – C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg
[2010/05/03 12:09:55 | 000,000,632 | RHS- | C] () – C:\Users\Bryan\ntuser.pol
[2010/05/02 13:44:28 | 000,001,102 | —- | C] () – C:\Users\Bryan\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:6DCFAD3B
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:987CE5C8
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:25FF8A61
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:B7910E41
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:3E996AD9
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FD80436E
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:DC3A4904
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D822654B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:C966DE9F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:5304CF6F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:11590865
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C1C705A1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B84EF836
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:9B7E8561
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:5095D8B1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:30C74695
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:7C3E753C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F36D7549
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2E81DAB7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0256104B
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:9373B271
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:54997B77
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:1960DAF2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C5B78274
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3B3A302E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F54781BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F3AB0B43
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E0648389
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ABCD2B94
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:962FBFE7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2A8CD561
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:2881AFC0
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3F3BEF8F
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:F3239111
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

# AdwCleaner v2.008 - Logfile created 11/18/2012 at 23:13:10
# Updated 17/11/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Bryan - FAMILY
# Boot Mode : Normal
# Running from : C:\Users\Bryan\Downloads\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\browsemngr.xml
File Deleted : C:\Users\Zanthia.Family\AppData\Roaming\Mozilla\Firefox\Profiles\pn1zgulf.default\searchplugins\Askcom.xml
Folder Deleted : C:\Program Files (x86)\AppGraffiti
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\Dogpile Bundle Toolbar
Folder Deleted : C:\Program Files (x86)\GamesBar
Folder Deleted : C:\Program Files (x86)\GamingWonderland
Folder Deleted : C:\Program Files (x86)\Gospel_Internet_Radio
Folder Deleted : C:\Program Files (x86)\Ilivid
Folder Deleted : C:\Program Files (x86)\Inbox.com
Folder Deleted : C:\Program Files (x86)\Maps_Bar
Folder Deleted : C:\Program Files (x86)\RebateInformer
Folder Deleted : C:\Program Files (x86)\Surf Canyon
Folder Deleted : C:\Program Files (x86)\Yontoo
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\GamesBar
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppGraffiti
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GamesBar
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\Betty\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Bryan\AppData\Local\APN
Folder Deleted : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc
Folder Deleted : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Folder Deleted : C:\Users\Bryan\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\Bryan\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Bryan\AppData\LocalLow\Claro LTD
Folder Deleted : C:\Users\Bryan\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Bryan\AppData\LocalLow\GamingWonderland
Folder Deleted : C:\Users\Bryan\AppData\LocalLow\Gospel_Internet_Radio
Folder Deleted : C:\Users\Bryan\AppData\LocalLow\Maps_Bar
Folder Deleted : C:\Users\Bryan\AppData\LocalLow\Zynga
Folder Deleted : C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
Folder Deleted : C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\wecarereminder@bryan
Folder Deleted : C:\Users\Daniel.Family\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Gwen\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Gwen\AppData\LocalLow\Gospel_Internet_Radio
Folder Deleted : C:\Users\Zanthia.Family\AppData\Local\Conduit
Folder Deleted : C:\Users\Zanthia.Family\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\Zanthia.Family\AppData\Local\OpenCandy
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\AppGraffiti
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\GamingWonderland
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\Gospel_Internet_Radio
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\Inbox Toolbar
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\searchquband
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\Searchqutoolbar
Folder Deleted : C:\Users\Zanthia.Family\AppData\LocalLow\vShare
Folder Deleted : C:\Users\Zanthia.Family\AppData\Roaming\Mozilla\Firefox\Profiles\pn1zgulf.default\extensions\[removed]
Folder Deleted : C:\Users\Zanthia.Family\AppData\Roaming\OpenCandy
Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registry] *****

Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Gospel_Internet_Radio
Key Deleted : HKCU\Software\AppDataLow\Software\Maps_Bar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\MarketPrecision
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2E64779A-5B66-482C-B8C4-F6CA9CC8EF99}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5AB7104A-B71F-49AD-9154-F7F8806AE848}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A899079D-206F-43A6-BE6A-07E0FA648EA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A8A9D26A-734F-467A-8907-176F9C5BDF56}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5AB7104A-B71F-49AD-9154-F7F8806AE848}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A899079D-206F-43A6-BE6A-07E0FA648EA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8A9D26A-734F-467A-8907-176F9C5BDF56}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Surf Canyon
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AppGraffiti
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppGraffiti.AppGraffitiJS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A3514F71-E63F-440B-8076-14226E21B2BF}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\surfcanyon.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\rebinfo
Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.BhoSite
Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.BhoSite.1
Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.ShowSettings
Key Deleted : HKLM\SOFTWARE\Classes\surfcanyon.ShowSettings.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1259247
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2860550
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{438B047C-C041-4D15-98CF-A97C6B366C28}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BA3105E9-5DE6-4A1E-A819-6F5046AB67F5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB02BC6B-B0F0-4074-99E6-884B70FCB6AE}
Key Deleted : HKLM\Software\CToolbar
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\SOFTWARE\FCTB000060231
Key Deleted : HKLM\Software\GamesBarSetup
Key Deleted : HKLM\Software\Gospel_Internet_Radio
Key Deleted : HKLM\Software\Maps_Bar
Key Deleted : HKLM\Software\MarketPrecision
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3B7599DF-3D5D-4EF5-BF51-9C2EDA788E83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D0466A1-E643-4899-B394-8BD2A4D71DC4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{987F51E8-5181-4531-A281-509722F49DAB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2E64779A-5B66-482C-B8C4-F6CA9CC8EF99}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5AB7104A-B71F-49AD-9154-F7F8806AE848}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6D0466A1-E643-4899-B394-8BD2A4D71DC4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{987F51E8-5181-4531-A281-509722F49DAB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A899079D-206F-43A6-BE6A-07E0FA648EA0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A8A9D26A-734F-467A-8907-176F9C5BDF56}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AAFFE112-08AB-4B91-8428-C008A22864FB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AF808758-C780-404C-A4EE-4526323FD9B6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DB35C569-5624-4CFC-8043-E5139F55A073}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{022C9F90-2E96-47D6-A971-107650154563}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{68AD96A1-2A28-4841-ABD0-F5AA45F008C9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2A533FF4-C021-4F3F-B293-259BB8C87C3A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33444B36-0260-46CF-B8DA-9F9326246B4B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D29976C-3EDE-4810-9AD3-FC2DECA84A08}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5AB7104A-B71F-49AD-9154-F7F8806AE848}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Gospel_Internet_Radio Toolbar
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Maps_Bar Toolbar
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Surf Canyon
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{022C9F90-2E96-47D6-A971-107650154563}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{68AD96A1-2A28-4841-ABD0-F5AA45F008C9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{A8A9D26A-734F-467A-8907-176F9C5BDF56}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A8A9D26A-734F-467A-8907-176F9C5BDF56}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FE337D7B-1447-4780-9A52-48BDAC438235}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{A899079D-206F-43A6-BE6A-07E0FA648EA0}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - SearchAssistant] = hxxp://toolbar.inbox.com/search/ie.aspx?tbid=80681&lng;=en –> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - CustomizeSearch] = hxxp://toolbar.inbox.com/help/sa_customize.aspx?tbid=80681 –> hxxp://www.google.com

-\\ Mozilla Firefox v [Unable to get version]

Profile name : default
File : C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\prefs.js

C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\user.js … Deleted !

Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://search.my-tools-app.com/?babsrc=home&s;[…]

Profile name : default
File : C:\Users\Zanthia.Family\AppData\Roaming\Mozilla\Firefox\Profiles\pn1zgulf.default\prefs.js

Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Deleted : user_pref("browser.startup.homepage", "hxxp://isearch.avg.com/?cid={8E35D18F-BD2B-4123-9452-537E5214[…]
Deleted : user_pref("browser.startup.homepage", "hxxp://www.ask.com/?l=dis&o;=1590&gct;=hp");
Deleted : user_pref("browser.search.selectedEngine", "Ask.com");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultenginename", "Ask.com");
Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src;=kw&tb;=SGD2&o;=2421&locale;=e[…]
Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");

Profile name : default
File : C:\Users\Daniel.Family\AppData\Roaming\Mozilla\Firefox\Profiles\7nnyk70j.default\prefs.js

[OK] File is clean.

Profile name : default
File : C:\Users\Ashanthe\AppData\Roaming\Mozilla\Firefox\Profiles\l0uoosi0.default\prefs.js

Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
Deleted : user_pref("browser.startup.homepage", "hxxp://isearch.avg.com/?cid={8E35D18F-BD2B-4123-9452-537E5214[…]

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

File : C:\Users\Zanthia.Family\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

File : C:\Users\Daniel.Family\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [20950 octets] - [18/11/2012 23:13:10]

########## EOF - C:\AdwCleaner[S1].txt - [21011 octets] ##########

ComboFix 12-11-16.02 - Bryan 11/18/2012 23:25:04.8.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2203 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\bSaving
c:\program files (x86)\bSaving\.build
c:\program files (x86)\bSaving\.user
c:\program files (x86)\bSaving\8454abfc9b2302c7d226ba5726c147f0.dll.ping
c:\program files (x86)\bSaving\uninst.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-10-19 to 2012-11-19 )))))))))))))))))))))))))))))))
.
.
2012-11-19 07:00 . 2012-11-19 07:00 ——– d—–w- c:\windows\ERUNT
2012-11-19 06:59 . 2012-11-19 06:59 ——– d—–w- C:\JRT
2012-11-19 06:38 . 2012-11-19 06:38 ——– d—–w- C:\_OTL
2012-11-17 01:46 . 2012-11-17 01:46 ——– d—–w- c:\users\Bryan\.idlerc
2012-11-16 11:52 . 2012-10-30 23:51 132864 —-a-w- c:\windows\system32\drivers\aswFW.sys
2012-11-16 11:52 . 2012-10-30 23:51 262656 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-11-16 11:52 . 2012-09-21 09:26 12368 —-a-w- c:\windows\system32\drivers\aswNdis.sys
2012-11-16 10:06 . 2012-10-30 23:51 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-11-16 10:06 . 2012-10-30 23:51 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-11-16 10:06 . 2012-10-15 16:59 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-11-16 10:06 . 2012-10-30 23:51 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-11-16 10:06 . 2012-10-30 23:51 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-11-16 10:06 . 2012-10-30 23:51 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-11-16 10:05 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2012-11-16 10:05 . 2012-10-30 23:50 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe
2012-11-16 09:50 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6A0F0EF9-0761-4BEB-843C-C3624124003D}\mpengine.dll
2012-11-16 09:07 . 2012-11-16 09:07 ——– d—–w- c:\programdata\GID
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-11-15 06:18 . 2012-11-15 06:19 ——– d—–w- c:\program files (x86)\QuickTime
2012-11-15 06:18 . 2012-11-15 06:18 ——– d—–w- c:\programdata\Apple Computer
2012-11-14 18:39 . 2012-11-14 18:39 ——– d—–w- c:\users\Bryan\AppData\Local\Secunia PSI
2012-11-14 16:29 . 2012-07-26 04:55 785512 —-a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-14 16:29 . 2012-07-26 04:55 54376 —-a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-14 16:29 . 2012-07-26 04:47 2560 —-a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-14 16:29 . 2012-07-26 02:36 9728 —-a-w- c:\windows\system32\Wdfres.dll
2012-11-14 16:20 . 2012-10-08 11:13 96768 —-a-w- c:\windows\system32\mshtmled.dll
2012-11-14 16:15 . 2012-07-26 02:26 87040 —-a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-14 16:15 . 2012-07-26 02:26 198656 —-a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-14 16:15 . 2012-07-26 03:08 84992 —-a-w- c:\windows\system32\WUDFSvc.dll
2012-11-14 16:15 . 2012-07-26 03:08 194048 —-a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-14 16:15 . 2012-07-26 03:08 229888 —-a-w- c:\windows\system32\WUDFHost.exe
2012-11-14 16:15 . 2012-07-26 03:08 744448 —-a-w- c:\windows\system32\WUDFx.dll
2012-11-14 16:15 . 2012-07-26 03:08 45056 —-a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-13 16:55 . 2012-11-13 16:55 ——– d—–w- c:\users\Gwen\AppData\Roaming\ID Vault
2012-11-11 05:31 . 2012-11-11 07:05 ——– d—–w- c:\users\Bryan\AppData\Roaming\SpiderOak
2012-11-11 05:30 . 2012-11-11 05:30 ——– d—–w- c:\program files (x86)\SpiderOak
2012-11-06 07:48 . 2012-11-15 06:38 ——– d—–w- c:\users\Betty\AppData\Local\ID Vault
2012-11-06 07:48 . 2012-11-06 07:48 ——– d—–w- c:\users\Betty\AppData\Local\White_Sky,_Inc
2012-11-06 04:07 . 2012-11-06 04:07 ——– d—–w- c:\users\Zanthia.Family\AppData\Local\Windows Live Writer
2012-11-06 04:07 . 2012-11-06 04:07 ——– d—–w- c:\users\Zanthia.Family\AppData\Roaming\Windows Live Writer
2012-10-26 04:56 . 2012-10-26 04:56 ——– d—–w- c:\program files (x86)\Aimersoft
2012-10-25 11:12 . 2012-10-25 11:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-25 11:12 . 2012-10-25 11:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts
2012-10-23 15:40 . 2012-10-23 15:39 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-16 11:09 . 2012-04-13 22:07 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-16 11:09 . 2011-11-07 17:34 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-14 16:16 . 2010-05-03 07:57 66395536 —-a-w- c:\windows\system32\MRT.exe
2012-10-30 23:51 . 2012-06-24 04:06 21136 —-a-w- c:\windows\system32\drivers\aswKbd.sys
2012-10-30 23:50 . 2012-06-24 03:57 285328 —-a-w- c:\windows\system32\aswBoot.exe
2012-10-23 15:39 . 2011-12-22 23:57 1034216 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-10-23 15:39 . 2010-07-26 21:02 916456 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-02 22:21 . 2012-10-10 22:33 7414632 —-a-w- c:\windows\system32\nvopencl.dll
2012-10-02 22:21 . 2012-10-10 22:33 6127464 —-a-w- c:\windows\SysWow64\nvopencl.dll
2012-10-02 22:21 . 2012-10-10 22:33 26331496 —-a-w- c:\windows\system32\nvoglv64.dll
2012-10-02 22:21 . 2012-10-10 22:33 19906920 —-a-w- c:\windows\SysWow64\nvoglv32.dll
2012-10-02 22:21 . 2012-10-10 22:33 9146728 —-a-w- c:\windows\system32\nvcuda.dll
2012-10-02 22:21 . 2012-10-10 22:33 7697768 —-a-w- c:\windows\SysWow64\nvcuda.dll
2012-10-02 22:21 . 2012-10-10 22:33 2747240 —-a-w- c:\windows\system32\nvcuvid.dll
2012-10-02 22:21 . 2012-10-10 22:33 2574696 —-a-w- c:\windows\SysWow64\nvcuvid.dll
2012-10-02 22:21 . 2012-10-10 22:33 25256296 —-a-w- c:\windows\system32\nvcompiler.dll
2012-10-02 22:21 . 2012-10-10 22:33 2428776 —-a-w- c:\windows\SysWow64\nvapi.dll
2012-10-02 22:21 . 2012-10-10 22:33 2218344 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-10-02 22:21 . 2012-10-10 22:33 1867112 —-a-w- c:\windows\SysWow64\nvcuvenc.dll
2012-10-02 22:21 . 2012-10-10 22:33 18252136 —-a-w- c:\windows\system32\nvd3dumx.dll
2012-10-02 22:21 . 2012-10-10 22:33 17559912 —-a-w- c:\windows\SysWow64\nvcompiler.dll
2012-10-02 22:21 . 2012-10-10 22:33 1482600 —-a-w- c:\windows\system32\nvdispgenco64.dll
2012-10-02 22:21 . 2012-10-10 22:33 13443944 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-10-02 22:21 . 2012-09-22 11:51 15309160 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2012-10-02 22:21 . 2012-09-22 11:51 12501352 —-a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-10-02 22:21 . 2012-02-10 05:43 1760104 —-a-w- c:\windows\system32\nvdispco64.dll
2012-10-02 22:21 . 2012-02-10 05:43 14922600 —-a-w- c:\windows\system32\nvwgf2umx.dll
2012-10-02 22:21 . 2009-10-28 06:27 2731880 —-a-w- c:\windows\system32\nvapi64.dll
2012-10-02 20:15 . 2012-10-02 20:15 430952 —-a-w- c:\windows\SysWow64\nvStreaming.exe
2012-10-02 19:51 . 2010-07-09 23:27 3293544 —-a-w- c:\windows\system32\nvsvc64.dll
2012-10-02 19:51 . 2010-07-09 23:27 6200680 —-a-w- c:\windows\system32\nvcpl.dll
2012-10-02 19:50 . 2010-07-09 23:27 891240 —-a-w- c:\windows\system32\nvvsvc.exe
2012-10-02 19:50 . 2010-07-09 23:27 118120 —-a-w- c:\windows\system32\nvmctray.dll
2012-10-02 19:50 . 2009-07-14 16:51 63336 —-a-w- c:\windows\system32\nvshext.dll
2012-10-02 19:50 . 2009-07-14 16:51 2557800 —-a-w- c:\windows\system32\nvsvcr.dll
2012-09-30 03:54 . 2012-09-19 15:27 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-24 22:32 . 2012-06-18 18:25 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-09-24 22:32 . 2011-11-09 09:03 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-14 19:19 . 2012-10-10 20:57 2048 —-a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-10 20:57 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-08-31 18:19 . 2012-10-10 20:56 1659760 —-a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-30 18:03 . 2012-10-10 20:56 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-30 17:12 . 2012-10-10 20:56 3968880 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12 . 2012-10-10 20:56 3914096 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05 . 2012-10-10 20:56 220160 —-a-w- c:\windows\system32\wintrust.dll
2012-08-24 16:57 . 2012-10-10 20:56 172544 —-a-w- c:\windows\SysWow64\wintrust.dll
2012-08-22 18:12 . 2012-09-12 15:31 376688 —-a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 15:31 950128 —-a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 15:31 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-26 07:45 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"HostsServer"="c:\program files (x86)\HostsMan\hostssrv.exe" [2010-02-06 1930240]
"OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2010-05-07 0]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2012-02-07 666384]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-06 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-13 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ALSysIO;ALSysIO;c:\users\Bryan\AppData\Local\Temp\ALSysIO64.sys [x]
R3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys [x]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 40464]
R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-05-06 19936]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-05-06 13280]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736]
R4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-10-06 140672]
R4 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R4 IDriveE Service;IDriveE Service;c:\idrive\IDriveE Service.exe [2011-03-31 153032]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 GIDv2;GIDv2; [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg]
2011-07-05 17:26 435976 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 11:09]
.
2012-11-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2012-11-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288]
"PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://msn.com/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: google.com\mail
Trusted Zone: google.com\www
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: browser.search.selectedEngine - XFINITY
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Toolbar-{a8a9d26a-734f-467a-8907-176f9c5bdf56} - (no file)
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
AddRemove-bSaving - c:\program files (x86)\bSaving\uninst.exe
AddRemove-GamesBar - c:\program files (x86)\GamesBar\uninst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7114.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\03\04\16\176\1e?"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
.
**************************************************************************
.
Completion time: 2012-11-18 23:44:47 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-19 07:44
.
Pre-Run: 585,765,154,816 bytes free
Post-Run: 586,338,045,952 bytes free
.
- - End Of File - - 136C27CD9B1AC64D933450FC73EEA10F

By the way I use a site called First Row Sports to stream live braodcasts of NFL games that I cannot get on TV locally. Is this also another P2P program that may be causing problems?

Also, when Combofix finished and rebooted and the web was no longer available I got a notice that Hosts Server was also shut down and could not be accessed. What would cause my internet access to be unavailable but still show that when I run a check on it that I'm connected to the internet? I want to be able have my system running as perfectly as possible without having to try and reload everything back to the original setups.

If I were to undo the system restore I would once again be unable to access the internet, is there somew way to find out what cuased this to happen and to correct it so that things could be restored to how they were after Combofix but still be able to use the internet.
I hope you haven't abandoned me yet. A couple of things, first is that my wifes brwoser keeps getting changed and for some reason the Avast anti virus definitions will not update any more as of this morning. I don't know whats going on because I'm experiencing more freezes and having to reboot several times a day. Looking forward to getting things back to working properly. If you are out of town for the holidays I understand fully, have a great Holiday and I'll be wiating to hear from when you return. Thanks, bart2201
Hi Bryan A

I hope you haven't abandoned me yet….If you are out of town for the holidays I understand fully, have a great Holiday and I'll be wiating to hear from when you return. Thanks, bart2201

Do you remember what I wrote in my first post?

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
:thumbup:

Very good :clap:

Run OTL

  • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • Post the OTL.txt log it produces in your next reply.

Next

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.

Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.


Please, reboot if you encounters the same issue


On your next reply please post :
  • OTL.txt
  • Combofix log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hello, There are some major problems after running ComboFix. First is that I had no internet connection again and couldn't access internet options or network center from the control panel. This messege came up every time I tried to access either of them. "Illegal operation attempted on a registry key that has been marked for deletion" This was the same problem that happened the first time I ran Combofix the other day, but then I did a system restore and was then able to log in but any changes Combofix made were reversed. This time I didn't do the restore, but I had to use the I.E 64 to log in because the I.E. that is normally used kept giving the error messege about the registry key. I rebooted twice to see if that would get teh regular I.E. working but it still doesn't. Also I got a messege that the hosts server could not access the internet and had been shut down.

This error messege also came up "Error loading Winsock2 Library (WS2_32.DLL): A system call has failed". Here are teh OTL and ComboFix logs you need:

OTL logfile created on: 11/20/2012 11:54:45 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.91 Gb Available Physical Memory | 50.83% Memory free
7.50 Gb Paging File | 4.28 Gb Available in Paging File | 57.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 542.30 Gb Free Space | 79.18% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\Bryan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe (Oberon Media )
PRC - C:\Windows\SysWOW64\schtasks.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
PRC - C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\Program Files (x86)\WOT\WOT.dll ()
MOD - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:64bit: - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Browser Manager) – C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (IDriveE Service) – C:\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (nvsvc) – C:\Windows\SysWOW64\nvvsvc.exe ()
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (GameConsoleService) – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswNdis2) – C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (aswFW) – C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswNdis) – C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:64bit: - (pneteth) – C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (GIDv2) – C:\Windows\SysNative\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadserd) – C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Uim_IM) – C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (UimBus) – C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:64bit: - (hotcore3) – C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sscdserd) – C:\Windows\SysNative\drivers\sscdserd.sys (MCCI Corporation)
DRV:64bit: - (sscdmdm) – C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) – C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) – C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (PCGenFam) – C:\Windows\SysNative\drivers\PCGenFAM.sys (Soluto LTD.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiKF622) – C:\Windows\SysNative\drivers\SaiKF622.sys (Saitek)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (VaneFltr) – C:\Windows\SysNative\drivers\Lachesis.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV - (GEARAspiWDM) – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\URLSearchHook: {a8a9d26a-734f-467a-8907-176f9c5bdf56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {fe337d7b-1447-4780-9a52-48bdac438235} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT1259247

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C8 E7 16 3F C0 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshareus.my-quick-search.com/search…s}&srch;=dsp
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerm…000002637bd3942
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…56-0F484A5B109E
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" = http://search.comcast.net/search/?cat=Web&…q={searchTerms}
IE - HKCU\..\SearchScopes\{281534E3-35BD-4B33-B445-24865046DE66}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{4A88F9EE-674B-46AE-9562-34F23715B388}: "URL" = http://www.bing.com/search?FORM=UP09DF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{53AD41BF-FFF3-49EB-89DF-C13AFED99786}: "URL" = http://websearch.shopathome.com?user_id=%g…q={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{6AB6D437-7F6D-4345-9B6C-E2D711B76132}: "URL" = http://www.google.com/search?sourceid=ie7&…;rlz=1I7ACZZ_en
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={8E35D18…mp;d=2012-06-17 23:22:47&v;=11.1.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{D5AC17B8-504C-41C5-9BF1-492AE1D6F4D7}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{EF1EE071-9EAD-44DD-A0C9-8C51EA637D51}: "URL" = http://search.yahoo.com/search?p={searchte…42,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Claro Search"
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=HP_ss&mntrId;=e075d4f6000000000000002637bd3942"
FF - prefs.js..browser.search.selectedEngine: "XFINITY"


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@GamingWonderland.com/Plugin: C:\Program Files (x86)\GamingWonderland\bar\1.bin\NPgtStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.91: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\npDisplayEngine: C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll ( )
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/08/06 10:55:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\GamingWonderland\bar\1.bin [2012/11/19 00:06:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Components: C:\Program Files (x86)\Minefield\components [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Plugins: C:\Program Files (x86)\Minefield\plugins [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/11/19 00:06:04 | 000,000,000 | —D | M]

[2012/07/04 22:52:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions
[2010/06/10 20:24:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/04 22:52:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/11/19 00:06:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions
[2012/11/19 00:06:21 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/19 00:06:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/19 00:06:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\wecarereminder@bryan

========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok\1.1_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\

O1 HOSTS File: ([2012/07/12 17:16:43 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2:64bit: - BHO: (Reg Error: Value error.) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Reg Error: Value error. File not found
O2:64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Reg Error: Value error.) - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - Reg Error: Value error. File not found
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (GamingWonderland) - {a899079d-206f-43a6-be6a-07e0fa648ea0} - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Gospel Internet Radio Toolbar) - {A8A9D26A-734F-467A-8907-176F9C5BDF56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PLD_FrameworkRun] C:\Windows\SysNative\OEM\_NowIntoDT.vbs ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [HostsServer] C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWOW64\StikyNot.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O15 - HKCU\..Trusted Domains: bleacherreport.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hoptoadapp.com ([]https in Trusted sites)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://gamesville.worldwinner.com/games/v4…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} http://www.worldwinner.com/games/v68/clue/clue.cab (Clue Control)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} http://www.worldwinner.com/games/v42/tilecity/tilecity.cab (Tilecity Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} http://www.worldwinner.com/games/v43/paint/paint.cab (Paint Control)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab (SysInfo Class)
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab (CPlayFirstSweetopiaControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\rebinfo - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\rebinfo - No CLSID value found
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/20 23:45:01 | 005,004,421 | —- | C] (Swearware) – C:\Users\Bryan\Desktop\ComboFix.exe
[2012/11/20 19:00:59 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2012/11/20 18:27:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingsoft Office
[2012/11/20 18:27:08 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Kingsoft
[2012/11/20 18:27:02 | 000,000,000 | —D | C] – C:\ProgramData\Kingsoft
[2012/11/20 18:26:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kingsoft
[2012/11/18 23:20:21 | 000,000,000 | —D | C] – C:\Qoobox
[2012/11/18 23:00:39 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2012/11/18 22:59:51 | 000,000,000 | —D | C] – C:\JRT
[2012/11/18 22:38:01 | 000,000,000 | —D | C] – C:\_OTL
[2012/11/18 02:02:58 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Bryan\Desktop\aswMBR.exe
[2012/11/18 01:37:00 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:26:49 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Claro LTD
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012/11/16 17:46:35 | 000,000,000 | —D | C] – C:\Users\Bryan\.idlerc
[2012/11/16 03:52:29 | 000,132,864 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/11/16 03:52:14 | 000,262,656 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/11/16 03:52:13 | 000,012,368 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswNdis.sys
[2012/11/16 03:38:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012/11/16 02:06:30 | 000,370,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/11/16 02:06:30 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/11/16 02:06:25 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/11/16 02:06:23 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/11/16 02:06:21 | 000,984,144 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/11/16 02:06:20 | 000,071,600 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/11/16 02:05:55 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/11/16 02:05:54 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/11/16 01:07:04 | 000,000,000 | —D | C] – C:\ProgramData\GID
[2012/11/14 22:18:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2012/11/14 10:39:30 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Secunia PSI
[2012/11/13 21:03:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderland
[2012/11/10 21:31:14 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/11/10 21:30:41 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpiderOak
[2012/11/10 21:30:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpiderOak
[2012/11/01 22:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\bSaving
[2012/10/25 20:56:30 | 000,000,000 | —D | C] – C:\Users\Bryan\Documents\Aimersoft Video Studio Express
[2012/10/25 20:56:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2012/10/25 20:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Aimersoft
[2012/07/12 09:14:08 | 003,405,744 | —- | C] (ESET) – C:\Users\Bryan\OnlineScanner.ocx
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/20 23:45:05 | 005,004,421 | —- | M] (Swearware) – C:\Users\Bryan\Desktop\ComboFix.exe
[2012/11/20 23:39:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/20 23:32:01 | 000,000,374 | —- | M] () – C:\Windows\tasks\WpsUpdateTask_Bryan.job
[2012/11/20 23:29:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/20 23:02:59 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/20 23:02:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/20 19:00:59 | 000,001,408 | —- | M] () – C:\Users\Public\Desktop\Kingsoft Writer.lnk
[2012/11/20 19:00:59 | 000,001,408 | —- | M] () – C:\Users\Public\Desktop\Kingsoft Presentation.lnk
[2012/11/20 19:00:59 | 000,001,387 | —- | M] () – C:\Users\Public\Desktop\Kingsoft Spreadsheets.lnk
[2012/11/20 15:42:07 | 000,003,084 | —- | M] () – C:\Windows\Sandboxie.ini
[2012/11/20 12:51:47 | 000,779,306 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/20 12:51:47 | 000,660,296 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/11/20 12:51:47 | 000,121,224 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/11/20 11:21:49 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/11/20 08:08:58 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/20 08:08:58 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/20 08:01:10 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2012/11/18 22:59:51 | 000,873,802 | —- | M] () – C:\Users\Bryan\Desktop\JRT (1).exe
[2012/11/18 02:21:15 | 000,000,471 | —- | M] () – C:\Users\Bryan\Desktop\MBR.zip
[2012/11/18 02:10:18 | 000,000,512 | —- | M] () – C:\Users\Bryan\Desktop\MBR.dat
[2012/11/18 02:03:26 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Bryan\Desktop\aswMBR.exe
[2012/11/18 01:37:00 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:28:23 | 000,001,346 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | M] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | M] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:36:34 | 000,002,120 | —- | M] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/16 03:07:02 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:31 | 000,001,110 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 10:30:05 | 000,002,439 | —- | M] () – C:\Users\Bryan\Desktop\Advanced Uninstaller PRO 11.lnk
[2012/11/14 09:40:39 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 08:43:02 | 000,334,096 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/05 13:30:02 | 005,770,487 | —- | M] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/10/30 15:51:56 | 000,059,728 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/10/30 15:51:55 | 000,984,144 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/10/30 15:51:55 | 000,370,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/10/30 15:51:55 | 000,262,656 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/10/30 15:51:55 | 000,071,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/10/30 15:51:55 | 000,021,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2012/10/30 15:51:53 | 000,132,864 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/10/30 15:51:53 | 000,025,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/10/30 15:51:07 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/10/30 15:50:59 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/10/30 15:50:30 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/10/29 14:46:59 | 000,344,696 | —- | M] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/29 14:42:02 | 000,001,021 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/10/29 10:11:08 | 000,001,121 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.net.lnk
[2012/10/29 10:11:06 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\PokerStars.net.lnk
[2012/10/27 08:07:03 | 000,001,430 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:03 | 000,001,406 | —- | M] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | M] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/20 19:01:06 | 000,000,374 | —- | C] () – C:\Windows\tasks\WpsUpdateTask_Bryan.job
[2012/11/20 19:00:59 | 000,001,408 | —- | C] () – C:\Users\Public\Desktop\Kingsoft Writer.lnk
[2012/11/20 19:00:59 | 000,001,408 | —- | C] () – C:\Users\Public\Desktop\Kingsoft Presentation.lnk
[2012/11/20 19:00:59 | 000,001,387 | —- | C] () – C:\Users\Public\Desktop\Kingsoft Spreadsheets.lnk
[2012/11/18 22:59:41 | 000,873,802 | —- | C] () – C:\Users\Bryan\Desktop\JRT (1).exe
[2012/11/18 02:21:15 | 000,000,471 | —- | C] () – C:\Users\Bryan\Desktop\MBR.zip
[2012/11/18 02:10:18 | 000,000,512 | —- | C] () – C:\Users\Bryan\Desktop\MBR.dat
[2012/11/18 01:28:23 | 000,001,346 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | C] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | C] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:05:06 | 000,002,120 | —- | C] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | C] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:30 | 000,001,110 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 21:55:30 | 000,001,073 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/11/14 08:29:23 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 08:15:33 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/05 12:34:15 | 005,770,487 | —- | C] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/10/29 14:46:53 | 000,344,696 | —- | C] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/27 08:07:03 | 000,001,430 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:02 | 000,001,406 | —- | C] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | C] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/09/14 17:11:09 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/07/12 13:48:22 | 000,000,839 | —- | C] () – C:\Users\Bryan\AppData\Roaming\result.db
[2012/07/12 09:14:18 | 000,000,172 | —- | C] () – C:\Users\Bryan\OnlineScanner.inf
[2012/05/20 21:59:25 | 000,000,000 | —- | C] () – C:\Users\Bryan\cd
[2012/02/15 02:14:35 | 000,000,000 | —- | C] () – C:\Users\Bryan\NetStat
[2012/02/08 03:10:36 | 000,003,084 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/12/28 13:15:52 | 000,000,151 | —- | C] () – C:\Users\Bryan\AppData\Roaming\burnaware.ini
[2011/12/23 14:46:15 | 000,005,632 | —- | C] () – C:\Users\Bryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 22:33:11 | 000,000,000 | —- | C] () – C:\Windows\Ransom.INI
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/07/27 02:20:24 | 000,000,000 | —- | C] () – C:\Users\Bryan\AppData\Local\{E6301488-4DE8-441E-9F4B-23956CD1A782}
[2011/05/18 11:08:35 | 000,148,936 | —- | C] () – C:\Windows\hpoins19.dat
[2011/04/05 08:40:01 | 000,026,032 | —- | C] () – C:\Windows\SysWow64\IDriveEXceedCryReg.exe
[2011/04/05 08:39:57 | 000,055,808 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2011/01/14 21:10:47 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/01/02 21:40:04 | 000,776,466 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/13 18:08:49 | 000,000,036 | —- | C] () – C:\Users\Bryan\AppData\Local\housecall.guid.cache
[2010/05/08 09:16:55 | 000,007,594 | —- | C] () – C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg
[2010/05/03 12:09:55 | 000,000,632 | RHS- | C] () – C:\Users\Bryan\ntuser.pol
[2010/05/02 13:44:28 | 000,001,102 | —- | C] () – C:\Users\Bryan\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011/05/09 20:03:26 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Reels
[2011/05/09 19:55:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Spins
[2010/08/12 19:25:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\abelhadigital.com
[2011/04/17 10:17:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Absolute Poker
[2010/05/01 21:39:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Acer
[2012/03/03 11:35:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\AdamOutler
[2012/09/01 13:26:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Amazon
[2011/12/22 15:52:32 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Auslogics
[2012/06/07 09:25:37 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Azureus
[2011/05/27 02:43:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DiamondVipClub
[2011/03/18 22:52:47 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Diceland
[2012/11/18 01:28:27 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Digiarty
[2011/04/04 14:14:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DriverCure
[2012/11/14 10:20:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Dropbox
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Easy Duplicate Finder
[2012/09/07 09:51:08 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Expert PDF 7
[2011/12/23 19:26:48 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\FrostWire
[2012/11/16 01:16:53 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ID Vault
[2011/12/28 14:57:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ImgBurn
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Jaangle
[2012/11/20 18:27:08 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Kingsoft
[2010/05/01 21:39:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Leadertech
[2010/05/12 10:46:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Locate32
[2010/05/10 11:07:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Masque
[2011/05/20 20:10:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Mayflower
[2011/12/23 14:43:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\MusicNet
[2010/11/12 14:55:41 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Oberon Media
[2010/07/14 17:01:02 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\OpenDNS Updater
[2012/11/14 22:21:29 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Opera
[2010/07/22 11:00:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Panda Security
[2011/04/04 14:14:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ParetoLogic
[2010/12/28 17:39:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Pogo
[2010/12/20 13:04:13 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Razer
[2010/12/25 13:19:33 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Returnil
[2011/05/06 18:53:12 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\RomeCasino
[2011/11/23 17:23:44 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SecondLife
[2011/06/11 17:14:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Software Inspection Library
[2012/07/04 22:52:11 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Songbird2
[2012/11/10 23:05:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/03/25 07:02:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Spotify
[2012/01/04 19:59:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\streamWriter
[2011/12/18 22:58:00 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SystemNucleus
[2010/05/02 13:44:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Template
[2010/06/10 20:24:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Thunderbird
[2011/06/11 14:41:16 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Vegascasino21
[2011/05/06 18:54:35 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\VTExtra
[2011/12/14 00:47:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\wargaming.net
[2010/05/02 13:46:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WildTangent
[2010/10/27 17:24:01 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Windows Live Writer
[2012/07/31 18:32:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WinPatrol
[2012/01/21 09:22:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wise Registry Cleaner
[2012/08/06 14:31:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wondershare
[2010/06/25 11:03:34 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\X-Setup Pro

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:6DCFAD3B
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:987CE5C8
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:25FF8A61
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:B7910E41
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:3E996AD9
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FD80436E
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:DC3A4904
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D822654B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:C966DE9F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:5304CF6F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:11590865
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C1C705A1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B84EF836
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:9B7E8561
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:5095D8B1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:30C74695
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:7C3E753C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F36D7549
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2E81DAB7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0256104B
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:9373B271
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:54997B77
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:1960DAF2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C5B78274
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3B3A302E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F54781BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F3AB0B43
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E0648389
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ABCD2B94
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:962FBFE7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2A8CD561
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:2881AFC0
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3F3BEF8F
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:F3239111
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

ComboFix 12-11-20.02 - Bryan 11/21/2012 0:15.8.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2187 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\bSaving
c:\program files (x86)\bSaving\uninst.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-10-21 to 2012-11-21 )))))))))))))))))))))))))))))))
.
.
2012-11-19 07:00 . 2012-11-19 07:00 ——– d—–w- c:\windows\ERUNT
2012-11-19 06:59 . 2012-11-19 08:06 ——– d—–w- C:\JRT
2012-11-19 06:38 . 2012-11-19 06:38 ——– d—–w- C:\_OTL
2012-11-18 09:26 . 2012-11-19 08:06 ——– d—–w- c:\programdata\Browser Manager
2012-11-18 09:26 . 2012-11-19 08:06 ——– d—–w- c:\program files (x86)\Claro LTD
2012-11-17 01:46 . 2012-11-17 01:46 ——– d—–w- c:\users\Bryan\.idlerc
2012-11-16 11:52 . 2012-10-30 23:51 132864 —-a-w- c:\windows\system32\drivers\aswFW.sys
2012-11-16 11:52 . 2012-10-30 23:51 262656 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-11-16 11:52 . 2012-09-21 09:26 12368 —-a-w- c:\windows\system32\drivers\aswNdis.sys
2012-11-16 10:06 . 2012-10-30 23:51 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-11-16 10:06 . 2012-10-30 23:51 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-11-16 10:06 . 2012-10-15 16:59 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-11-16 10:06 . 2012-10-30 23:51 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-11-16 10:06 . 2012-10-30 23:51 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-11-16 10:06 . 2012-10-30 23:51 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-11-16 10:05 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2012-11-16 10:05 . 2012-10-30 23:50 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe
2012-11-16 09:50 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6A0F0EF9-0761-4BEB-843C-C3624124003D}\mpengine.dll
2012-11-16 09:07 . 2012-11-16 09:07 ——– d—–w- c:\programdata\GID
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-11-15 06:18 . 2012-11-15 06:19 ——– d—–w- c:\program files (x86)\QuickTime
2012-11-15 06:18 . 2012-11-15 06:18 ——– d—–w- c:\programdata\Apple Computer
2012-11-14 18:39 . 2012-11-14 18:39 ——– d—–w- c:\users\Bryan\AppData\Local\Secunia PSI
2012-11-14 16:29 . 2012-07-26 04:55 785512 —-a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-14 16:29 . 2012-07-26 04:55 54376 —-a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-14 16:29 . 2012-07-26 04:47 2560 —-a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-14 16:29 . 2012-07-26 02:36 9728 —-a-w- c:\windows\system32\Wdfres.dll
2012-11-14 16:20 . 2012-10-08 11:13 96768 —-a-w- c:\windows\system32\mshtmled.dll
2012-11-14 16:15 . 2012-07-26 02:26 87040 —-a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-14 16:15 . 2012-07-26 02:26 198656 —-a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-14 16:15 . 2012-07-26 03:08 84992 —-a-w- c:\windows\system32\WUDFSvc.dll
2012-11-14 16:15 . 2012-07-26 03:08 194048 —-a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-14 16:15 . 2012-07-26 03:08 229888 —-a-w- c:\windows\system32\WUDFHost.exe
2012-11-14 16:15 . 2012-07-26 03:08 744448 —-a-w- c:\windows\system32\WUDFx.dll
2012-11-14 16:15 . 2012-07-26 03:08 45056 —-a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-14 05:03 . 2012-11-19 08:06 ——– d—–w- c:\program files (x86)\GamingWonderland
2012-11-13 16:55 . 2012-11-13 16:55 ——– d—–w- c:\users\Gwen\AppData\Roaming\ID Vault
2012-11-11 05:31 . 2012-11-11 07:05 ——– d—–w- c:\users\Bryan\AppData\Roaming\SpiderOak
2012-11-11 05:30 . 2012-11-11 05:30 ——– d—–w- c:\program files (x86)\SpiderOak
2012-11-06 07:48 . 2012-11-15 06:38 ——– d—–w- c:\users\Betty\AppData\Local\ID Vault
2012-11-06 07:48 . 2012-11-06 07:48 ——– d—–w- c:\users\Betty\AppData\Local\White_Sky,_Inc
2012-11-06 04:07 . 2012-11-06 04:07 ——– d—–w- c:\users\Zanthia.Family\AppData\Local\Windows Live Writer
2012-11-06 04:07 . 2012-11-06 04:07 ——– d—–w- c:\users\Zanthia.Family\AppData\Roaming\Windows Live Writer
2012-10-26 04:56 . 2012-10-26 04:56 ——– d—–w- c:\program files (x86)\Aimersoft
2012-10-25 11:12 . 2012-10-25 11:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-25 11:12 . 2012-10-25 11:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts
2012-10-23 15:40 . 2012-10-23 15:39 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-16 11:09 . 2012-04-13 22:07 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-16 11:09 . 2011-11-07 17:34 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-14 16:16 . 2010-05-03 07:57 66395536 —-a-w- c:\windows\system32\MRT.exe
2012-10-30 23:51 . 2012-06-24 04:06 21136 —-a-w- c:\windows\system32\drivers\aswKbd.sys
2012-10-30 23:50 . 2012-06-24 03:57 285328 —-a-w- c:\windows\system32\aswBoot.exe
2012-10-23 15:39 . 2011-12-22 23:57 1034216 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-10-23 15:39 . 2010-07-26 21:02 916456 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-02 22:21 . 2012-10-10 22:33 7414632 —-a-w- c:\windows\system32\nvopencl.dll
2012-10-02 22:21 . 2012-10-10 22:33 6127464 —-a-w- c:\windows\SysWow64\nvopencl.dll
2012-10-02 22:21 . 2012-10-10 22:33 26331496 —-a-w- c:\windows\system32\nvoglv64.dll
2012-10-02 22:21 . 2012-10-10 22:33 19906920 —-a-w- c:\windows\SysWow64\nvoglv32.dll
2012-10-02 22:21 . 2012-10-10 22:33 9146728 —-a-w- c:\windows\system32\nvcuda.dll
2012-10-02 22:21 . 2012-10-10 22:33 7697768 —-a-w- c:\windows\SysWow64\nvcuda.dll
2012-10-02 22:21 . 2012-10-10 22:33 2747240 —-a-w- c:\windows\system32\nvcuvid.dll
2012-10-02 22:21 . 2012-10-10 22:33 2574696 —-a-w- c:\windows\SysWow64\nvcuvid.dll
2012-10-02 22:21 . 2012-10-10 22:33 25256296 —-a-w- c:\windows\system32\nvcompiler.dll
2012-10-02 22:21 . 2012-10-10 22:33 2428776 —-a-w- c:\windows\SysWow64\nvapi.dll
2012-10-02 22:21 . 2012-10-10 22:33 2218344 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-10-02 22:21 . 2012-10-10 22:33 1867112 —-a-w- c:\windows\SysWow64\nvcuvenc.dll
2012-10-02 22:21 . 2012-10-10 22:33 18252136 —-a-w- c:\windows\system32\nvd3dumx.dll
2012-10-02 22:21 . 2012-10-10 22:33 17559912 —-a-w- c:\windows\SysWow64\nvcompiler.dll
2012-10-02 22:21 . 2012-10-10 22:33 1482600 —-a-w- c:\windows\system32\nvdispgenco64.dll
2012-10-02 22:21 . 2012-10-10 22:33 13443944 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-10-02 22:21 . 2012-09-22 11:51 15309160 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2012-10-02 22:21 . 2012-09-22 11:51 12501352 —-a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-10-02 22:21 . 2012-02-10 05:43 1760104 —-a-w- c:\windows\system32\nvdispco64.dll
2012-10-02 22:21 . 2012-02-10 05:43 14922600 —-a-w- c:\windows\system32\nvwgf2umx.dll
2012-10-02 22:21 . 2009-10-28 06:27 2731880 —-a-w- c:\windows\system32\nvapi64.dll
2012-10-02 20:15 . 2012-10-02 20:15 430952 —-a-w- c:\windows\SysWow64\nvStreaming.exe
2012-10-02 19:51 . 2010-07-09 23:27 3293544 —-a-w- c:\windows\system32\nvsvc64.dll
2012-10-02 19:51 . 2010-07-09 23:27 6200680 —-a-w- c:\windows\system32\nvcpl.dll
2012-10-02 19:50 . 2010-07-09 23:27 891240 —-a-w- c:\windows\system32\nvvsvc.exe
2012-10-02 19:50 . 2010-07-09 23:27 118120 —-a-w- c:\windows\system32\nvmctray.dll
2012-10-02 19:50 . 2009-07-14 16:51 63336 —-a-w- c:\windows\system32\nvshext.dll
2012-10-02 19:50 . 2009-07-14 16:51 2557800 —-a-w- c:\windows\system32\nvsvcr.dll
2012-09-30 03:54 . 2012-09-19 15:27 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-24 22:32 . 2012-06-18 18:25 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-09-24 22:32 . 2011-11-09 09:03 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-14 19:19 . 2012-10-10 20:57 2048 —-a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-10 20:57 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-08-31 18:19 . 2012-10-10 20:56 1659760 —-a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-30 18:03 . 2012-10-10 20:56 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-30 17:12 . 2012-10-10 20:56 3968880 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12 . 2012-10-10 20:56 3914096 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-08-24 18:05 . 2012-10-10 20:56 220160 —-a-w- c:\windows\system32\wintrust.dll
2012-08-24 16:57 . 2012-10-10 20:56 172544 —-a-w- c:\windows\SysWow64\wintrust.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{a8a9d26a-734f-467a-8907-176f9c5bdf56}"= "c:\program files (x86)\Gospel_Internet_Radio\prxtbGosp.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{a8a9d26a-734f-467a-8907-176f9c5bdf56}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"HostsServer"="c:\program files (x86)\HostsMan\hostssrv.exe" [2010-02-06 1930240]
"OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2010-05-07 0]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2012-02-07 666384]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-06 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-13 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~3\BROWSE~1\23796~1.11\{16CDF~1\browsemngr.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ALSysIO;ALSysIO;c:\users\Bryan\AppData\Local\Temp\ALSysIO64.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328]
R3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys [x]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 40464]
R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-05-06 19936]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-05-06 13280]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736]
R4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-10-06 140672]
R4 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R4 IDriveE Service;IDriveE Service;c:\idrive\IDriveE Service.exe [2011-03-31 153032]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 GIDv2;GIDv2; [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
S2 Browser Manager;Browser Manager;c:\programdata\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [2012-10-11 2312216]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg]
2011-07-05 17:26 435976 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 11:09]
.
2012-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2012-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2012-11-21 c:\windows\Tasks\WpsUpdateTask_Bryan.job
- c:\program files (x86)\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2012-09-17 16:00]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288]
"PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]
.
——- Supplementary Scan ——-
.
uStart Page = https://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: bleacherreport.com
Trusted Zone: google.com\mail
Trusted Zone: google.com\www
Trusted Zone: hoptoadapp.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\
FF - prefs.js: browser.search.selectedEngine - Claro Search
FF - prefs.js: browser.startup.homepage - hxxp://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=HP_ss&mntrId;=e075d4f6000000000000002637bd3942
FF - prefs.js: browser.search.selectedEngine - XFINITY
FF - user.js: extensions.claro.autoRvrt - false
FF - user.js: extensions.claro_i.newTab - false
FF - user.js: extensions.claro.tlbrSrchUrl -
FF - user.js: extensions.claro.id - e075d4f6000000000000002637bd3942
FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062}
FF - user.js: extensions.claro.instlDay - 15662
FF - user.js: extensions.claro.vrsn - [removed]
FF - user.js: extensions.claro.vrsni - [removed]
FF - user.js: extensions.claro_i.vrsnTs - [removed]:26
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - base
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{CCB69577-088B-4004-9ED8-FF5BCC83A039} - (no file)
Toolbar-10 - (no file)
Toolbar-{a899079d-206f-43a6-be6a-07e0fa648ea0} - c:\program files (x86)\GamingWonderland\bar\1.bin\gtbar.dll
BHO-{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - (value not set)
WebBrowser-{A8A9D26A-734F-467A-8907-176F9C5BDF56} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
AddRemove-bSaving - c:\program files (x86)\bSaving\uninst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7114.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\03\04\16\176\1e?"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\SysWOW64\schtasks.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
.
**************************************************************************
.
Completion time: 2012-11-21 00:34:31 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-21 08:34
ComboFix2.txt 2012-11-19 07:44
.
Pre-Run: 583,553,433,600 bytes free
Post-Run: 584,171,597,824 bytes free
.
- - End Of File - - 2A5CF65F04047F9A94B33A3C0A5DC52F

I know that something very serious is wrong and appreciate any help you can give me in getting things repaired. Thank You.
When I say that I.E. won't load its because there is no home page showing when I attempt it so it tries to load for a minute and then just shuts off, the only way to get online is by using the I.E. 64 prompt.
Hi Brian A ;)

Please delete the copy of adwcleaner that you have on your desktop and download a fresh copy from here
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply

Next

[external image: Posted Image] Re-run Junkware> Removal Tool
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Next

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


Next

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]


On your next reply please post :
  • AdwCleaner log
  • JRT report
  • MBAM report
  • Eset log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

:wavey:
Please listen to what I'm saying, I cannot access the internet explorer unless I use I.E. 64. Nothing will update because of this, the hosts file cannot run, I cannot update MBAM, I cannot update ESET and because of this it will not run because the virus definitions are not up to date. All of these things happened after running ComboFix. Now the first time I ran it I actually used system recovery to go back to where I could get online with I.E. and thus run all scans and updates. But when this was done it also undid any changes that Combofix had made to the computer. So this time I didn't use system recovery and now my computer cannot get online unless its with I.E.64 which none of the programs you need me to use can access so that they can update and run. This has been like this since the other night when you asked me to run ComboFix again. Also I did run Adw Cleaner from the new download but it didn't produce a log report. Just like the first time when I ran Junkware removal tool it also didn't produce any log file after running. So all I can give you right now is the log from the MBAM scan, but keep in mind that this also could not update because it could not access the internet. So unless you can instruct me on how to repair the internet so that everything can update and run like it is supposed to it will be very difficult to be able to follow the instructions that require use of teh interent. Is there any way to reset everything so that they all use the I.E.64 interent connection? Also the hosts program will not run because it cannot get online. Here is the error message from the attempt to run the Hosts program: Application ERROR Hosts server has failed to load. Exception EIDStackInitialization Failed in module hostssrv.exe at 000B5131 Error on loading Winsock2 library (WS2_32.DLL): A system call has failed. Here is the MBAM log, but remember it is not up to date on the definitions. First here is the error message from the attempt to update MBAM: An error occured please report this to our support team. (include content of all error messages and codes in your submission. PROGRAM_ERROR_UPDATING (0,0, Net exception) Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.18.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Bryan :: FAMILY [administrator] 11/22/2012 9:56:22 PM mbam-log-2012-11-22 (21-56-22).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 411381 Time elapsed: 7 minute(s), 3 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Good News, I've repaired the Winsock 2 registry rpoblems that were blocking me from accessing the internet with x86. This of course means I can now update Avast, MBAM, ESET, and Secunia. So I've reoaded ADW Cleaner and run it and this time it did produce a log report, JRT once again did not produce a log report after running it. The MBAM and ESET logs are also included below.I had to reset and reload the Winsock 2 files and repair the LSP chain so that all the 32bit software and scans would now work. # AdwCleaner v2.008 - Logfile created 11/23/2012 at 16:19:00 # Updated 17/11/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Bryan - FAMILY # Boot Mode : Normal # Running from : C:\Users\Bryan\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v [Unable to get version] Profile name : default File : C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\prefs.js [OK] File is clean. Profile name : default File : C:\Users\Zanthia.Family\AppData\Roaming\Mozilla\Firefox\Profiles\pn1zgulf.default\prefs.js [OK] File is clean. Profile name : default File : C:\Users\Daniel.Family\AppData\Roaming\Mozilla\Firefox\Profiles\7nnyk70j.default\prefs.js [OK] File is clean. Profile name : default File : C:\Users\Ashanthe\AppData\Roaming\Mozilla\Firefox\Profiles\l0uoosi0.default\prefs.js [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Users\Zanthia.Family\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted [l.15] : urls_to_restore_on_startup = [ "hxxp://isearch.avg.com/?cid={8E35D18F-BD2B-4123-9452-537E5[…] Deleted [l.400] : urls_to_restore_on_startup = [ "hxxp://isearch.avg.com/?cid={8E35D18F-BD2B-4123-9452-537E5214[…] File : C:\Users\Daniel.Family\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S2].txt - [1735 octets] - [23/11/2012 16:19:00] ########## EOF - C:\AdwCleaner[S2].txt - [1795 octets] ########## Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.11.23.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Bryan :: FAMILY [administrator] 11/23/2012 4:28:04 PM mbam-log-2012-11-23 (16-28-04).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 413716 Time elapsed: 7 minute(s), 47 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET Log File C:\backup\sdcard\Verbous_GenoCYde.version.666.zip Android/Plankton.H trojan C:\backup\sdcard\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\backup\sdcopy\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\New folder (2)\Removable Disk\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pptextlinks.jar Win32/Adware.Gamevance.Gen application C:\Users\Bryan\Desktop\sd card bu\appmonster2\backup\great.app.luck\rev\19.apk a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Desktop\sd card bu\App_Manager\App_Backups\user_apps\great.app.luck.apk a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\great.app.luck-73d83b0622200494240f8460c0a9cfa7.apk.gz a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\mobi.mgeek.TunnyBrowser-b32e904a89df7510548bb253d28cbce0.apk.gz a variant of Android/Adware.Waps.D application C:\Users\Bryan\Documents\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\Users\Bryan\Downloads\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\Users\Bryan\Downloads\Avengers_Reborn_Verbous.zip a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Downloads\Eternal_Ecstasy.zip multiple threats C:\Users\Bryan\Downloads\Verbous_GenoCYde.version.666.zip Android/Plankton.H trojan So the only log missing is the JRT one that didn't come out. What to do with the infections in quarantine on ESET?
Hi Brian A ;)

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

File::
C:\backup\sdcard\Verbous_GenoCYde.version.666.zip
C:\backup\sdcard\back up\Removable Disk\Admiral-Beast-CWM.zip C:\backup\sdcopy\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\New folder (2)\Removable Disk\back up\Removable Disk\Admiral-Beast-CWM.zip C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pptextlinks.jar 
C:\Users\Bryan\Desktop\sd card bu\appmonster2\backup\great.app.luck\rev\19.apk 
C:\Users\Bryan\Desktop\sd card bu\App_Manager\App_Backups\user_apps\great.app.luck.apk
C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\great.app.luck-73d83b0622200494240f8460c0a9cfa7.apk.gz 
C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\mobi.mgeek.TunnyBrowser-b32e904a89df7510548bb253d28cbce0.apk.gz 
C:\Users\Bryan\Documents\back up\Removable Disk\Admiral-Beast-CWM.zip 
C:\Users\Bryan\Downloads\Admiral-Beast-CWM.zip 
C:\Users\Bryan\Downloads\Avengers_Reborn_Verbous.zip 
C:\Users\Bryan\Downloads\Eternal_Ecstasy.zip 
C:\Users\Bryan\Downloads\Verbous_GenoCYde.version.666.zip

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]



Run OTL

  • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • Post the OTL.txt log it produces in your next reply.
Hi Robyrel, Here are the scan results from ComboFix and OTL. Last night my wife used the computer and may have downloaded a game and a toolbar. I've tried to get her to understand how to disable the check box that enables toolbars I hope she is doing so. Anyway in the future I'll see if I can set her up to run in a Sandbox.

ComboFix 12-11-24.02 - Bryan 11/24/2012 13:04:33.9.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2374 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Bryan\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\backup\sdcard\back up\Removable Disk\Admiral-Beast-CWM.zip c:\backup\sdcopy\back up\Removable Disk\Admiral-Beast-CWM.zip"
"c:\backup\sdcard\Verbous_GenoCYde.version.666.zip"
"c:\new folder (2)\Removable Disk\back up\Removable Disk\Admiral-Beast-CWM.zip c:\users\Bryan\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pptextlinks.jar"
"c:\users\Bryan\Desktop\sd card bu\App_Manager\App_Backups\user_apps\great.app.luck.apk"
"c:\users\Bryan\Desktop\sd card bu\appmonster2\backup\great.app.luck\rev\19.apk"
"c:\users\Bryan\Desktop\sd card bu\TitaniumBackup\great.app.luck-73d83b0622200494240f8460c0a9cfa7.apk.gz"
"c:\users\Bryan\Desktop\sd card bu\TitaniumBackup\mobi.mgeek.TunnyBrowser-b32e904a89df7510548bb253d28cbce0.apk.gz"
"c:\users\Bryan\Documents\back up\Removable Disk\Admiral-Beast-CWM.zip"
"c:\users\Bryan\Downloads\Admiral-Beast-CWM.zip"
"c:\users\Bryan\Downloads\Avengers_Reborn_Verbous.zip"
"c:\users\Bryan\Downloads\Eternal_Ecstasy.zip"
"c:\users\Bryan\Downloads\Verbous_GenoCYde.version.666.zip"
.
.
((((((((((((((((((((((((( Files Created from 2012-10-24 to 2012-11-24 )))))))))))))))))))))))))))))))
.
.
2012-11-24 17:46 . 2012-11-24 17:46 ——– d—–w- c:\users\Zanthia.Family\AppData\Roaming\Digiarty
2012-11-24 17:32 . 2012-11-24 17:32 ——– d—–w- c:\program files (x86)\GamingWonderland
2012-11-23 08:50 . 2012-11-23 08:50 ——– d—–w- c:\program files (x86)\sysnew
2012-11-23 08:47 . 2012-01-17 19:00 25368 —-a-w- c:\windows\system32\drivers\fastmnt.sys
2012-11-21 08:34 . 2012-11-24 21:14 ——– d—–w- c:\users\Bryan\AppData\Local\temp
2012-11-21 03:00 . 2012-11-21 03:00 ——– d—–w- c:\windows\SHELLNEW
2012-11-21 02:27 . 2012-11-21 02:27 ——– d—–w- c:\users\Bryan\AppData\Roaming\Kingsoft
2012-11-21 02:27 . 2012-11-21 02:27 ——– d—–w- c:\programdata\Kingsoft
2012-11-21 02:26 . 2012-11-21 02:26 ——– d—–w- c:\program files (x86)\Kingsoft
2012-11-19 07:00 . 2012-11-19 07:00 ——– d—–w- c:\windows\ERUNT
2012-11-19 06:59 . 2012-11-23 05:51 ——– d—–w- C:\JRT
2012-11-19 06:38 . 2012-11-19 06:38 ——– d—–w- C:\_OTL
2012-11-17 01:46 . 2012-11-17 01:46 ——– d—–w- c:\users\Bryan\.idlerc
2012-11-16 11:52 . 2012-10-30 23:51 132864 —-a-w- c:\windows\system32\drivers\aswFW.sys
2012-11-16 11:52 . 2012-10-30 23:51 262656 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-11-16 11:52 . 2012-09-21 09:26 12368 —-a-w- c:\windows\system32\drivers\aswNdis.sys
2012-11-16 10:06 . 2012-10-30 23:51 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-11-16 10:06 . 2012-10-30 23:51 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-11-16 10:06 . 2012-10-15 16:59 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-11-16 10:06 . 2012-10-30 23:51 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-11-16 10:06 . 2012-10-30 23:51 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-11-16 10:06 . 2012-10-30 23:51 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-11-16 10:05 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2012-11-16 10:05 . 2012-10-30 23:50 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe
2012-11-16 09:50 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6A0F0EF9-0761-4BEB-843C-C3624124003D}\mpengine.dll
2012-11-16 09:07 . 2012-11-16 09:07 ——– d—–w- c:\programdata\GID
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-11-15 06:19 . 2012-11-15 06:19 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-11-15 06:18 . 2012-11-15 06:19 ——– d—–w- c:\program files (x86)\QuickTime
2012-11-15 06:18 . 2012-11-15 06:18 ——– d—–w- c:\programdata\Apple Computer
2012-11-14 18:39 . 2012-11-14 18:39 ——– d—–w- c:\users\Bryan\AppData\Local\Secunia PSI
2012-11-14 16:29 . 2012-07-26 04:55 785512 —-a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-14 16:29 . 2012-07-26 04:55 54376 —-a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-14 16:29 . 2012-07-26 04:47 2560 —-a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-14 16:29 . 2012-07-26 02:36 9728 —-a-w- c:\windows\system32\Wdfres.dll
2012-11-14 16:20 . 2012-10-08 11:13 96768 —-a-w- c:\windows\system32\mshtmled.dll
2012-11-14 16:15 . 2012-07-26 02:26 87040 —-a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-14 16:15 . 2012-07-26 02:26 198656 —-a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-14 16:15 . 2012-07-26 03:08 84992 —-a-w- c:\windows\system32\WUDFSvc.dll
2012-11-14 16:15 . 2012-07-26 03:08 194048 —-a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-14 16:15 . 2012-07-26 03:08 229888 —-a-w- c:\windows\system32\WUDFHost.exe
2012-11-14 16:15 . 2012-07-26 03:08 744448 —-a-w- c:\windows\system32\WUDFx.dll
2012-11-14 16:15 . 2012-07-26 03:08 45056 —-a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-13 16:55 . 2012-11-13 16:55 ——– d—–w- c:\users\Gwen\AppData\Roaming\ID Vault
2012-11-11 05:31 . 2012-11-11 07:05 ——– d—–w- c:\users\Bryan\AppData\Roaming\SpiderOak
2012-11-11 05:30 . 2012-11-11 05:30 ——– d—–w- c:\program files (x86)\SpiderOak
2012-11-06 07:48 . 2012-11-15 06:38 ——– d—–w- c:\users\Betty\AppData\Local\ID Vault
2012-11-06 07:48 . 2012-11-06 07:48 ——– d—–w- c:\users\Betty\AppData\Local\White_Sky,_Inc
2012-11-06 04:07 . 2012-11-06 04:07 ——– d—–w- c:\users\Zanthia.Family\AppData\Local\Windows Live Writer
2012-11-06 04:07 . 2012-11-06 04:07 ——– d—–w- c:\users\Zanthia.Family\AppData\Roaming\Windows Live Writer
2012-10-26 04:56 . 2012-10-26 04:56 ——– d—–w- c:\program files (x86)\Aimersoft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-16 11:09 . 2012-04-13 22:07 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-16 11:09 . 2011-11-07 17:34 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-14 16:16 . 2010-05-03 07:57 66395536 —-a-w- c:\windows\system32\MRT.exe
2012-10-30 23:51 . 2012-06-24 04:06 21136 —-a-w- c:\windows\system32\drivers\aswKbd.sys
2012-10-30 23:50 . 2012-06-24 03:57 285328 —-a-w- c:\windows\system32\aswBoot.exe
2012-10-25 11:12 . 2012-10-25 11:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-25 11:12 . 2012-10-25 11:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts
2012-10-23 15:39 . 2012-10-23 15:40 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-10-23 15:39 . 2011-12-22 23:57 1034216 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-10-23 15:39 . 2010-07-26 21:02 916456 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-02 22:21 . 2012-10-10 22:33 7414632 —-a-w- c:\windows\system32\nvopencl.dll
2012-10-02 22:21 . 2012-10-10 22:33 6127464 —-a-w- c:\windows\SysWow64\nvopencl.dll
2012-10-02 22:21 . 2012-10-10 22:33 26331496 —-a-w- c:\windows\system32\nvoglv64.dll
2012-10-02 22:21 . 2012-10-10 22:33 19906920 —-a-w- c:\windows\SysWow64\nvoglv32.dll
2012-10-02 22:21 . 2012-10-10 22:33 9146728 —-a-w- c:\windows\system32\nvcuda.dll
2012-10-02 22:21 . 2012-10-10 22:33 7697768 —-a-w- c:\windows\SysWow64\nvcuda.dll
2012-10-02 22:21 . 2012-10-10 22:33 2747240 —-a-w- c:\windows\system32\nvcuvid.dll
2012-10-02 22:21 . 2012-10-10 22:33 2574696 —-a-w- c:\windows\SysWow64\nvcuvid.dll
2012-10-02 22:21 . 2012-10-10 22:33 25256296 —-a-w- c:\windows\system32\nvcompiler.dll
2012-10-02 22:21 . 2012-10-10 22:33 2428776 —-a-w- c:\windows\SysWow64\nvapi.dll
2012-10-02 22:21 . 2012-10-10 22:33 2218344 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-10-02 22:21 . 2012-10-10 22:33 1867112 —-a-w- c:\windows\SysWow64\nvcuvenc.dll
2012-10-02 22:21 . 2012-10-10 22:33 18252136 —-a-w- c:\windows\system32\nvd3dumx.dll
2012-10-02 22:21 . 2012-10-10 22:33 17559912 —-a-w- c:\windows\SysWow64\nvcompiler.dll
2012-10-02 22:21 . 2012-10-10 22:33 1482600 —-a-w- c:\windows\system32\nvdispgenco64.dll
2012-10-02 22:21 . 2012-10-10 22:33 13443944 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-10-02 22:21 . 2012-09-22 11:51 15309160 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2012-10-02 22:21 . 2012-09-22 11:51 12501352 —-a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-10-02 22:21 . 2012-02-10 05:43 1760104 —-a-w- c:\windows\system32\nvdispco64.dll
2012-10-02 22:21 . 2012-02-10 05:43 14922600 —-a-w- c:\windows\system32\nvwgf2umx.dll
2012-10-02 22:21 . 2009-10-28 06:27 2731880 —-a-w- c:\windows\system32\nvapi64.dll
2012-10-02 20:15 . 2012-10-02 20:15 430952 —-a-w- c:\windows\SysWow64\nvStreaming.exe
2012-10-02 19:51 . 2010-07-09 23:27 3293544 —-a-w- c:\windows\system32\nvsvc64.dll
2012-10-02 19:51 . 2010-07-09 23:27 6200680 —-a-w- c:\windows\system32\nvcpl.dll
2012-10-02 19:50 . 2010-07-09 23:27 891240 —-a-w- c:\windows\system32\nvvsvc.exe
2012-10-02 19:50 . 2010-07-09 23:27 118120 —-a-w- c:\windows\system32\nvmctray.dll
2012-10-02 19:50 . 2009-07-14 16:51 63336 —-a-w- c:\windows\system32\nvshext.dll
2012-10-02 19:50 . 2009-07-14 16:51 2557800 —-a-w- c:\windows\system32\nvsvcr.dll
2012-09-30 03:54 . 2012-09-19 15:27 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-24 22:32 . 2012-06-18 18:25 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-09-24 22:32 . 2011-11-09 09:03 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-14 19:19 . 2012-10-10 20:57 2048 —-a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-10 20:57 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-08-31 18:19 . 2012-10-10 20:56 1659760 —-a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-30 18:03 . 2012-10-10 20:56 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-30 17:12 . 2012-10-10 20:56 3968880 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12 . 2012-10-10 20:56 3914096 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"HostsServer"="c:\program files (x86)\HostsMan\hostssrv.exe" [2010-02-06 1930240]
"OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2010-05-07 0]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2012-02-07 666384]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-06 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-14 5629312]
"IDriveE Startup"="c:\idrive\IDrvieEStartup.exe" [2011-03-30 193992]
"Device Detection"="c:\program files (x86)\FUJIFILM\MyFinePix Studio\dd.exe" [2011-04-27 404664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
IDrive Tray.lnk - c:\idrive\IDriveEReg2ini.exe [2011-4-5 292296]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
RSS 2011.lnk - c:\program files (x86)\Returnil\RVS3\rvsgui.exe [N/A]
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-13 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ALSysIO;ALSysIO;c:\users\Bryan\AppData\Local\Temp\ALSysIO64.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328]
R3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys [x]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 40464]
R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-05-06 19936]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-05-06 13280]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 GIDv2;GIDv2; [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-10-06 140672]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
S2 GamingWonderlandService;GamingWonderlandService;c:\progra~2\GAMING~2\bar\2.bin\gtbarsvc.exe [2012-11-24 42504]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 IDriveE Service;IDriveE Service;c:\idrive\IDriveE Service.exe [2011-03-31 153032]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg]
2011-07-05 17:26 435976 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 11:09]
.
2012-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2012-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2012-11-24 c:\windows\Tasks\WpsUpdateTask_Bryan.job
- c:\program files (x86)\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2012-09-17 16:00]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 97792 —-a-w- c:\users\Bryan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288]
"PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]
"WinPatrol"="c:\program files (x86)\BillP Studios\WinPatrol\WinPatrol.exe" [2012-07-13 384232]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://msn.com/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: bleacherreport.com
Trusted Zone: google.com\mail
Trusted Zone: google.com\www
Trusted Zone: hoptoadapp.com
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\
FF - prefs.js: browser.search.selectedEngine - XFINITY
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Toolbar-{a8a9d26a-734f-467a-8907-176f9c5bdf56} - (no file)
Wow6432Node-HKLM-Run-Adobe Reader Speed Launcher - c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
Wow6432Node-HKLM-Run-Adobe ARM - c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
AddRemove-bSaving - c:\program files (x86)\bSaving\uninst.exe
AddRemove-GamesBar - c:\program files (x86)\GamesBar\uninst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7114.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\03\04\16\176\1e?"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-24 13:19:16
ComboFix-quarantined-files.txt 2012-11-24 21:19
ComboFix2.txt 2012-11-21 08:34
ComboFix3.txt 2012-11-19 07:44
.
Pre-Run: 582,329,556,992 bytes free
Post-Run: 582,717,534,208 bytes free
.
- - End Of File - - 311D6CA84CE3D62AEA9130FD00DF9922

OTL logfile created on: 11/24/2012 1:23:37 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.62 Gb Available Physical Memory | 43.18% Memory free
7.50 Gb Paging File | 5.66 Gb Available in Paging File | 75.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 542.81 Gb Free Space | 79.26% Space Free | Partition Type: NTFS

Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbarsvc.exe (COMPANYVERS_NAME)
PRC - C:\Users\Bryan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
PRC - C:\IDrive\IDriveEBackground.exe (Pro-SoftNet Corp, U.S.A)
PRC - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
PRC - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\WOT\WOT.dll ()
MOD - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:64bit: - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (GamingWonderlandService) – C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbarsvc.exe (COMPANYVERS_NAME)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (IDriveE Service) – C:\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (nvsvc) – C:\Windows\SysWOW64\nvvsvc.exe ()
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (GameConsoleService) – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswNdis2) – C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (aswFW) – C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswNdis) – C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:64bit: - (pneteth) – C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (GIDv2) – C:\Windows\SysNative\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadserd) – C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Uim_IM) – C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:64bit: - (UimBus) – C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:64bit: - (hotcore3) – C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sscdserd) – C:\Windows\SysNative\drivers\sscdserd.sys (MCCI Corporation)
DRV:64bit: - (sscdmdm) – C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) – C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) – C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (PCGenFam) – C:\Windows\SysNative\drivers\PCGenFAM.sys (Soluto LTD.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiKF622) – C:\Windows\SysNative\drivers\SaiKF622.sys (Saitek)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (VaneFltr) – C:\Windows\SysNative\drivers\Lachesis.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV - (GEARAspiWDM) – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C8 E7 16 3F C0 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" = http://search.comcast.net/search/?cat=Web&…q={searchTerms}
IE - HKCU\..\SearchScopes\{281534E3-35BD-4B33-B445-24865046DE66}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{4A88F9EE-674B-46AE-9562-34F23715B388}: "URL" = http://www.bing.com/search?FORM=UP09DF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{53AD41BF-FFF3-49EB-89DF-C13AFED99786}: "URL" = http://websearch.shopathome.com?user_id=%g…q={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…;rlz=1I7GGHP_en
IE - HKCU\..\SearchScopes\{6AB6D437-7F6D-4345-9B6C-E2D711B76132}: "URL" = http://www.google.com/search?sourceid=ie7&…;rlz=1I7ACZZ_en
IE - HKCU\..\SearchScopes\{D5AC17B8-504C-41C5-9BF1-492AE1D6F4D7}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{EF1EE071-9EAD-44DD-A0C9-8C51EA637D51}: "URL" = http://search.yahoo.com/search?p={searchte…42,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "XFINITY"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@GamingWonderland.com/Plugin: C:\Program Files (x86)\GamingWonderland\bar\2.bin\NPgtStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.91: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\npDisplayEngine: C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll ( )
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/08/06 10:55:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\GamingWonderland\bar\2.bin [2012/11/24 09:32:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Components: C:\Program Files (x86)\Minefield\components [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Plugins: C:\Program Files (x86)\Minefield\plugins [2012/11/14 22:19:04 | 000,000,000 | —D | M]

[2012/07/04 22:52:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions
[2010/06/10 20:24:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/04 22:52:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/11/22 21:38:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions

========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://start.msn.iplay.com/?o=shp
CHR - homepage: http://start.msn.iplay.com/?o=shp
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6\plugins\npPDFXCviewNPPlugin.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6\plugins\npzylomgamesplayer.dll
CHR - plugin: getPlusPlus for Adobe 16291 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6\plugins\np_gp.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\Daniel.Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\background/registryAccess.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U33 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.330.3 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Display Engine v2 (Enabled) = C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - homepage: http://start.msn.iplay.com/?o=shp
CHR - homepage: http://start.msn.iplay.com/?o=shp
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6\plugins\npPDFXCviewNPPlugin.dll
CHR - plugin: Zylom Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6\plugins\npzylomgamesplayer.dll
CHR - plugin: getPlusPlus for Adobe 16291 (Enabled) = C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 6\plugins\np_gp.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\Daniel.Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\background/registryAccess.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U33 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.330.3 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Display Engine v2 (Enabled) = C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: FreeHDSport.TV = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok\1.1_0\
CHR - Extension: avast! WebRep = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\

O1 HOSTS File: ([2012/11/21 00:28:37 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2:64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PLD_FrameworkRun] C:\Windows\SysNative\OEM\_NowIntoDT.vbs ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [Device Detection] C:\Program Files (x86)\FUJIFILM\MyFinePix Studio\dd.exe ()
O4 - HKCU..\Run: [HostsServer] C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
O4 - HKCU..\Run: [IDriveE Startup] C:\IDrive\IDrvieEStartup.exe (Pro Softnet Corporation)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWOW64\StikyNot.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IDrive Tray.lnk = C:\IDrive\IDriveEReg2ini.exe (Pro Softnet Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: bleacherreport.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hoptoadapp.com ([]https in Trusted sites)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://gamesville.worldwinner.com/games/v4…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} http://www.worldwinner.com/games/v68/clue/clue.cab (Clue Control)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} http://www.worldwinner.com/games/v42/tilecity/tilecity.cab (Tilecity Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} http://www.worldwinner.com/games/v43/paint/paint.cab (Paint Control)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab (SysInfo Class)
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab (CPlayFirstSweetopiaControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/24 13:21:07 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/11/24 13:19:18 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/11/24 09:32:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderland
[2012/11/23 00:50:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\sysnew
[2012/11/23 00:47:25 | 000,025,368 | —- | C] (CompanyName) – C:\Windows\SysNative\drivers\fastmnt.sys
[2012/11/21 00:34:33 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\temp
[2012/11/21 00:12:35 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/11/21 00:12:35 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/11/21 00:12:35 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/11/20 23:45:01 | 005,006,466 | R— | C] (Swearware) – C:\Users\Bryan\Desktop\ComboFix.exe
[2012/11/20 19:00:59 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2012/11/20 18:27:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingsoft Office
[2012/11/20 18:27:08 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Kingsoft
[2012/11/20 18:27:02 | 000,000,000 | —D | C] – C:\ProgramData\Kingsoft
[2012/11/20 18:26:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kingsoft
[2012/11/18 23:20:21 | 000,000,000 | —D | C] – C:\Qoobox
[2012/11/18 23:00:39 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2012/11/18 22:59:51 | 000,000,000 | —D | C] – C:\JRT
[2012/11/18 22:38:01 | 000,000,000 | —D | C] – C:\_OTL
[2012/11/18 02:02:58 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Bryan\Desktop\aswMBR.exe
[2012/11/18 01:37:00 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/16 17:46:35 | 000,000,000 | —D | C] – C:\Users\Bryan\.idlerc
[2012/11/16 03:52:29 | 000,132,864 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/11/16 03:52:14 | 000,262,656 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/11/16 03:52:13 | 000,012,368 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswNdis.sys
[2012/11/16 03:38:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012/11/16 02:06:30 | 000,370,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/11/16 02:06:30 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/11/16 02:06:25 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/11/16 02:06:23 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/11/16 02:06:21 | 000,984,144 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/11/16 02:06:20 | 000,071,600 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/11/16 02:05:55 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/11/16 02:05:54 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/11/16 01:07:04 | 000,000,000 | —D | C] – C:\ProgramData\GID
[2012/11/14 22:18:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2012/11/14 10:39:30 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Secunia PSI
[2012/11/10 21:31:14 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/11/10 21:30:41 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpiderOak
[2012/11/10 21:30:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpiderOak
[2012/10/25 20:56:30 | 000,000,000 | —D | C] – C:\Users\Bryan\Documents\Aimersoft Video Studio Express
[2012/10/25 20:56:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2012/10/25 20:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Aimersoft
[2012/07/12 09:14:08 | 003,405,744 | —- | C] (ESET) – C:\Users\Bryan\OnlineScanner.ocx
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/11/24 13:00:21 | 005,006,466 | R— | M] (Swearware) – C:\Users\Bryan\Desktop\ComboFix.exe
[2012/11/24 12:58:46 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/24 12:58:46 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/24 12:56:10 | 000,779,306 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/24 12:56:10 | 000,660,296 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/11/24 12:56:10 | 000,121,224 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/11/24 12:52:04 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/24 12:51:21 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/24 12:51:12 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2012/11/24 12:39:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/24 12:32:00 | 000,000,374 | —- | M] () – C:\Windows\tasks\WpsUpdateTask_Bryan.job
[2012/11/24 12:29:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/23 18:52:27 | 000,003,084 | —- | M] () – C:\Windows\Sandboxie.ini
[2012/11/23 16:18:01 | 000,543,531 | —- | M] () – C:\Users\Bryan\Desktop\adwcleaner.exe
[2012/11/21 00:28:37 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/11/21 00:27:27 | 000,334,096 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/20 19:00:59 | 000,001,408 | —- | M] () – C:\Users\Public\Desktop\Kingsoft Writer.lnk
[2012/11/20 19:00:59 | 000,001,408 | —- | M] () – C:\Users\Public\Desktop\Kingsoft Presentation.lnk
[2012/11/20 19:00:59 | 000,001,387 | —- | M] () – C:\Users\Public\Desktop\Kingsoft Spreadsheets.lnk
[2012/11/20 11:21:49 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/11/18 22:59:51 | 000,873,802 | —- | M] () – C:\Users\Bryan\Desktop\JRT (1).exe
[2012/11/18 02:21:15 | 000,000,471 | —- | M] () – C:\Users\Bryan\Desktop\MBR.zip
[2012/11/18 02:10:18 | 000,000,512 | —- | M] () – C:\Users\Bryan\Desktop\MBR.dat
[2012/11/18 02:03:26 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Bryan\Desktop\aswMBR.exe
[2012/11/18 01:37:00 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:28:23 | 000,001,346 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | M] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | M] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:36:34 | 000,002,120 | —- | M] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/16 03:07:02 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:31 | 000,001,110 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 10:30:05 | 000,002,439 | —- | M] () – C:\Users\Bryan\Desktop\Advanced Uninstaller PRO 11.lnk
[2012/11/14 09:40:39 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/05 13:30:02 | 005,770,487 | —- | M] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/10/30 15:51:56 | 000,059,728 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/10/30 15:51:55 | 000,984,144 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/10/30 15:51:55 | 000,370,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/10/30 15:51:55 | 000,262,656 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/10/30 15:51:55 | 000,071,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/10/30 15:51:55 | 000,021,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2012/10/30 15:51:53 | 000,132,864 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/10/30 15:51:53 | 000,025,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/10/30 15:51:07 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/10/30 15:50:59 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/10/30 15:50:30 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/10/29 14:46:59 | 000,344,696 | —- | M] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/29 14:42:02 | 000,001,021 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/10/29 10:11:08 | 000,001,121 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.net.lnk
[2012/10/29 10:11:06 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\PokerStars.net.lnk
[2012/10/27 08:07:03 | 000,001,430 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:03 | 000,001,406 | —- | M] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | M] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/11/23 16:18:01 | 000,543,531 | —- | C] () – C:\Users\Bryan\Desktop\adwcleaner.exe
[2012/11/21 20:46:10 | 000,001,996 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RSS 2011.lnk
[2012/11/21 20:46:09 | 000,001,506 | —- | C] () – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IDrive Tray.lnk
[2012/11/21 00:12:35 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/11/21 00:12:35 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/11/21 00:12:35 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/11/21 00:12:35 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/11/21 00:12:35 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/11/20 19:01:06 | 000,000,374 | —- | C] () – C:\Windows\tasks\WpsUpdateTask_Bryan.job
[2012/11/20 19:00:59 | 000,001,408 | —- | C] () – C:\Users\Public\Desktop\Kingsoft Writer.lnk
[2012/11/20 19:00:59 | 000,001,408 | —- | C] () – C:\Users\Public\Desktop\Kingsoft Presentation.lnk
[2012/11/20 19:00:59 | 000,001,387 | —- | C] () – C:\Users\Public\Desktop\Kingsoft Spreadsheets.lnk
[2012/11/18 22:59:41 | 000,873,802 | —- | C] () – C:\Users\Bryan\Desktop\JRT (1).exe
[2012/11/18 02:21:15 | 000,000,471 | —- | C] () – C:\Users\Bryan\Desktop\MBR.zip
[2012/11/18 02:10:18 | 000,000,512 | —- | C] () – C:\Users\Bryan\Desktop\MBR.dat
[2012/11/18 01:28:23 | 000,001,346 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | C] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | C] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:05:06 | 000,002,120 | —- | C] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | C] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:30 | 000,001,110 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 21:55:30 | 000,001,073 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/11/14 08:29:23 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 08:15:33 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/05 12:34:15 | 005,770,487 | —- | C] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/10/29 14:46:53 | 000,344,696 | —- | C] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/27 08:07:03 | 000,001,430 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:02 | 000,001,406 | —- | C] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | C] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/09/14 17:11:09 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/07/12 13:48:22 | 000,000,839 | —- | C] () – C:\Users\Bryan\AppData\Roaming\result.db
[2012/07/12 09:14:18 | 000,000,172 | —- | C] () – C:\Users\Bryan\OnlineScanner.inf
[2012/05/20 21:59:25 | 000,000,000 | —- | C] () – C:\Users\Bryan\cd
[2012/02/15 02:14:35 | 000,000,000 | —- | C] () – C:\Users\Bryan\NetStat
[2012/02/08 03:10:36 | 000,003,084 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/12/28 13:15:52 | 000,000,151 | —- | C] () – C:\Users\Bryan\AppData\Roaming\burnaware.ini
[2011/12/23 14:46:15 | 000,005,632 | —- | C] () – C:\Users\Bryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 22:33:11 | 000,000,000 | —- | C] () – C:\Windows\Ransom.INI
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/07/27 02:20:24 | 000,000,000 | —- | C] () – C:\Users\Bryan\AppData\Local\{E6301488-4DE8-441E-9F4B-23956CD1A782}
[2011/05/18 11:08:35 | 000,148,936 | —- | C] () – C:\Windows\hpoins19.dat
[2011/04/05 08:40:01 | 000,026,032 | —- | C] () – C:\Windows\SysWow64\IDriveEXceedCryReg.exe
[2011/04/05 08:39:57 | 000,055,808 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2011/01/14 21:10:47 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/01/02 21:40:04 | 000,776,466 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/13 18:08:49 | 000,000,036 | —- | C] () – C:\Users\Bryan\AppData\Local\housecall.guid.cache
[2010/05/08 09:16:55 | 000,007,594 | —- | C] () – C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg
[2010/05/03 12:09:55 | 000,000,632 | RHS- | C] () – C:\Users\Bryan\ntuser.pol
[2010/05/02 13:44:28 | 000,001,102 | —- | C] () – C:\Users\Bryan\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011/05/09 20:03:26 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Reels
[2011/05/09 19:55:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Spins
[2010/08/12 19:25:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\abelhadigital.com
[2011/04/17 10:17:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Absolute Poker
[2010/05/01 21:39:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Acer
[2012/03/03 11:35:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\AdamOutler
[2012/09/01 13:26:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Amazon
[2011/12/22 15:52:32 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Auslogics
[2012/06/07 09:25:37 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Azureus
[2011/05/27 02:43:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DiamondVipClub
[2011/03/18 22:52:47 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Diceland
[2012/11/18 01:28:27 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Digiarty
[2011/04/04 14:14:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DriverCure
[2012/11/14 10:20:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Dropbox
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Easy Duplicate Finder
[2012/09/07 09:51:08 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Expert PDF 7
[2011/12/23 19:26:48 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\FrostWire
[2012/11/16 01:16:53 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ID Vault
[2011/12/28 14:57:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ImgBurn
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Jaangle
[2012/11/20 18:27:08 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Kingsoft
[2010/05/01 21:39:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Leadertech
[2010/05/12 10:46:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Locate32
[2010/05/10 11:07:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Masque
[2011/05/20 20:10:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Mayflower
[2011/12/23 14:43:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\MusicNet
[2010/11/12 14:55:41 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Oberon Media
[2010/07/14 17:01:02 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\OpenDNS Updater
[2012/11/14 22:21:29 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Opera
[2010/07/22 11:00:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Panda Security
[2011/04/04 14:14:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ParetoLogic
[2010/12/28 17:39:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Pogo
[2010/12/20 13:04:13 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Razer
[2010/12/25 13:19:33 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Returnil
[2011/05/06 18:53:12 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\RomeCasino
[2011/11/23 17:23:44 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SecondLife
[2011/06/11 17:14:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Software Inspection Library
[2012/07/04 22:52:11 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Songbird2
[2012/11/10 23:05:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/03/25 07:02:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Spotify
[2012/01/04 19:59:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\streamWriter
[2011/12/18 22:58:00 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SystemNucleus
[2010/05/02 13:44:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Template
[2010/06/10 20:24:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Thunderbird
[2011/06/11 14:41:16 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Vegascasino21
[2011/05/06 18:54:35 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\VTExtra
[2011/12/14 00:47:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\wargaming.net
[2010/05/02 13:46:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WildTangent
[2010/10/27 17:24:01 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Windows Live Writer
[2012/07/31 18:32:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WinPatrol
[2012/01/21 09:22:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wise Registry Cleaner
[2012/08/06 14:31:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wondershare
[2010/06/25 11:03:34 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\X-Setup Pro

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:6DCFAD3B
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:987CE5C8
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:25FF8A61
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:B7910E41
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:3E996AD9
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FD80436E
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:DC3A4904
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D822654B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:C966DE9F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:5304CF6F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:11590865
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C1C705A1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B84EF836
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:9B7E8561
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:5095D8B1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:30C74695
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:7C3E753C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F36D7549
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2E81DAB7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0256104B
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:9373B271
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:54997B77
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:1960DAF2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C5B78274
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3B3A302E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F54781BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F3AB0B43
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E0648389
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ABCD2B94
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:962FBFE7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2A8CD561
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:2881AFC0
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3F3BEF8F
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:F3239111
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI