Hi Robybel, Thank You for responding so quickly. Here are the logs you requested.
OTL logfile created on: 11/18/2012 1:39:57 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 52.46% Memory free
7.50 Gb Paging File | 4.91 Gb Available in Paging File | 65.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 547.20 Gb Free Space | 79.90% Space Free | Partition Type: NTFS
Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found
PRC - C:\Users\Bryan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Coupon Companion\Coupon Companion-bg.exe (215 Apps)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\clarosrv.exe (Montera Technologeis LTD)
PRC - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe (Oberon Media )
PRC - C:\Windows\SysWOW64\schtasks.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
PRC - C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\spext.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avutil-51.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avformat-54.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\avcodec-54.dll ()
MOD - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\escortShld.dll ()
MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
MOD - C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\Program Files (x86)\WOT\WOT.dll ()
MOD - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
========== Services (SafeList) ==========
SRV:
64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:
64bit: - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV:
64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:
64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:
64bit: - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:
64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Browser Manager) – C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (IDriveE Service) – C:\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (nvsvc) – C:\Windows\SysWOW64\nvvsvc.exe ()
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (GameConsoleService) – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:
64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:
64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:
64bit: - (aswNdis2) – C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:
64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:
64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:
64bit: - (aswFW) – C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:
64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:
64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:
64bit: - (aswNdis) – C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:
64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:
64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:
64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:
64bit: - (pneteth) – C:\Windows\SysNative\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV:
64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (GIDv2) – C:\Windows\SysNative\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV:
64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:
64bit: - (ssadserd) – C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:
64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:
64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:
64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:
64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:
64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (Uim_IM) – C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:
64bit: - (UimBus) – C:\Windows\SysNative\drivers\uimx64.sys (Windows ® 2000 DDK provider)
DRV:
64bit: - (hotcore3) – C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (sscdserd) – C:\Windows\SysNative\drivers\sscdserd.sys (MCCI Corporation)
DRV:
64bit: - (sscdmdm) – C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:
64bit: - (sscdbus) – C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:
64bit: - (sscdmdfl) – C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:
64bit: - (PCGenFam) – C:\Windows\SysNative\drivers\PCGenFAM.sys (Soluto LTD.)
DRV:
64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:
64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf.sys (Secunia)
DRV:
64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:
64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:
64bit: - (SaiMini) – C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:
64bit: - (SaiKF622) – C:\Windows\SysNative\drivers\SaiKF622.sys (Saitek)
DRV:
64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:
64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:
64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:
64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:
64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:
64bit: - (USBModem) – C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:
64bit: - (UsbDiag) – C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:
64bit: - (usbbus) – C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV:
64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:
64bit: - (VaneFltr) – C:\Windows\SysNative\drivers\Lachesis.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:
64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV - (GEARAspiWDM) – C:\Windows\SysWOW64\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:
64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:
64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\URLSearchHook: {a8a9d26a-734f-467a-8907-176f9c5bdf56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {fe337d7b-1447-4780-9a52-48bdac438235} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?…;ctid=CT1259247
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page =
https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C8 E7 16 3F C0 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" =
http://vshareus.my-quick-search.com/search…s}&srch;=dsp
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://www.claro-search.com/?q={searchTerm…000002637bd3942
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
http://websearch.ask.com/redirect?client=i…56-0F484A5B109E
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" =
http://search.comcast.net/search/?cat=Web&…q={searchTerms}
IE - HKCU\..\SearchScopes\{281534E3-35BD-4B33-B445-24865046DE66}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{4A88F9EE-674B-46AE-9562-34F23715B388}: "URL" =
http://www.bing.com/search?FORM=UP09DF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{53AD41BF-FFF3-49EB-89DF-C13AFED99786}: "URL" =
http://websearch.shopathome.com?user_id=%g…q={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACZZ
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{6AB6D437-7F6D-4345-9B6C-E2D711B76132}: "URL" =
http://www.google.com/search?sourceid=ie7&…;rlz=1I7ACZZ_en
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
http://isearch.avg.com/search?cid={8E35D18…mp;d=2012-06-17 23:22:47&v;=11.1.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{D5AC17B8-504C-41C5-9BF1-492AE1D6F4D7}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{EF1EE071-9EAD-44DD-A0C9-8C51EA637D51}: "URL" =
http://search.yahoo.com/search?p={searchte…42,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Claro Search"
FF - prefs.js..browser.search.selectedEngine: "Claro Search"
FF - prefs.js..keyword.URL: "http://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=KW_ss&mntrId;=e075d4f6000000000000002637bd3942&q;="
FF - prefs.js..browser.search.order.1: "Claro Search"
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=116695&tt;=4612_4&babsrc;=HP_ss&mntrId;=e075d4f6000000000000002637bd3942"
FF - prefs.js..browser.search.selectedEngine: "XFINITY"
FF - prefs.js..browser.search.defaultenginename: "XFINITY"
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@GamingWonderland.com/Plugin: C:\Program Files (x86)\GamingWonderland\bar\1.bin\NPgtStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.91: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\npDisplayEngine: C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll ( )
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/08/06 10:55:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\GamingWonderland\bar\1.bin [2012/11/16 16:05:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Components: C:\Program Files (x86)\Minefield\components [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Minefield 4.0b4pre\extensions\\Plugins: C:\Program Files (x86)\Minefield\plugins [2012/11/14 22:19:04 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/11/18 01:26:39 | 000,000,000 | —D | M]
[2012/07/04 22:52:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions
[2010/06/10 20:24:39 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/04 22:52:40 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/11/18 01:26:53 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions
[2012/11/18 01:26:54 | 000,000,000 | —D | M] ("Coupon Companion") – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/18 01:26:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/11/18 01:26:36 | 000,000,000 | —D | M] (Claro Toolbar) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/07/04 22:53:08 | 000,000,000 | —D | M] (Songbird Toolbar, Powered by Ask.com) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2011/11/29 23:56:34 | 000,000,000 | —D | M] (We-Care Reminder) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\wecarereminder@bryan
[2012/11/18 01:26:53 | 000,000,000 | —D | M] (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]\chrome\content\extensionCode
[2012/10/14 08:56:22 | 000,214,127 | —- | M] () (No name found) – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\extensions\[removed]
[2012/07/04 22:53:08 | 000,002,335 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\askcom.xml
[2012/11/18 01:26:39 | 000,002,514 | —- | M] () – C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\sc8h00j6.default\searchplugins\browsemngr.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.claro-search.com/?affID=116695&…000002637bd3942
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: registryAccess (Enabled) = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\background/registryAccess.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U35 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.350.10 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Display Engine v2 (Enabled) = C:\Program Files (x86)\LivingPlay Games\nplplaypop.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Songbird Toolbar = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaanekkkbebcnpimficmalklgjoahpn\7.15.4.0_0\
CHR - Extension: FreeHDSport.TV = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok\1.1_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl\1.1_0\
CHR - Extension: avast! WebRep = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: We-Care Reminder Lite = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: Yontoo = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.20.40\crossrider
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.20.40\
CHR - Extension: No name found = C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\
O1 HOSTS File: ([2012/07/12 17:16:43 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:
64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:
64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:
64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2:
64bit: - BHO: (Reg Error: Value error.) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Reg Error: Value error. File not found
O2:
64bit: - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O2 - BHO: (Claro LTD Helper Object) - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\bh\claro.dll (Montera Technologeis LTD)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Coupon Companion) - {11111111-1111-1111-1111-110011441193} - C:\Program Files (x86)\Coupon Companion\Coupon Companion.dll (215 Apps)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Reg Error: Value error.) - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - Reg Error: Value error. File not found
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:
64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Claro LTD Toolbar) - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - C:\Program Files (x86)\Claro LTD\claro\1.8.3.10\claroTlbr.dll (Montera Technologeis LTD)
O3 - HKLM\..\Toolbar: (GamingWonderland) - {a899079d-206f-43a6-be6a-07e0fa648ea0} - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Gospel Internet Radio Toolbar) - {A8A9D26A-734F-467A-8907-176F9C5BDF56} - C:\Program Files (x86)\Gospel_Internet_Radio\prxtbGosp.dll (Conduit Ltd.)
O4:
64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [PLD_FrameworkRun] C:\Windows\SysNative\OEM\_NowIntoDT.vbs ()
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKCU..\Run: [HostsServer] C:\Program Files (x86)\HostsMan\hostssrv.exe (abelhadigital.com)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\SysWOW64\StikyNot.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:
64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Windows\SysNative\nvLsp64.dll (NVIDIA)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O15 - HKCU\..Trusted Domains: bleacherreport.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hoptoadapp.com ([]https in Trusted sites)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821}
http://gamesville.worldwinner.com/games/v4…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874}
http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC}
http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/….0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03}
http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717}
http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605}
http://www.worldwinner.com/games/v68/clue/clue.cab (Clue Control)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F}
http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39}
http://www.worldwinner.com/games/v46/monopoly/monopoly.cab (Monopoly Control)
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43}
http://www.worldwinner.com/games/v42/tilecity/tilecity.cab (Tilecity Control)
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916}
http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab (MysteryPI Control)
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8}
http://www.worldwinner.com/games/v43/paint/paint.cab (Paint Control)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}
http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab (SysInfo Class)
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4}
http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab (CPlayFirstSweetopiaControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\rebinfo - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:
64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\rebinfo - No CLSID value found
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O28:
64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/11/18 01:37:00 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:26:55 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Coupon Companion
[2012/11/18 01:26:50 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Claro
[2012/11/18 01:26:49 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
[2012/11/18 01:26:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Coupon Companion
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Claro LTD
[2012/11/18 01:26:36 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012/11/16 17:46:35 | 000,000,000 | —D | C] – C:\Users\Bryan\.idlerc
[2012/11/16 03:52:29 | 000,132,864 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/11/16 03:52:14 | 000,262,656 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/11/16 03:52:13 | 000,012,368 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswNdis.sys
[2012/11/16 03:38:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012/11/16 02:06:30 | 000,370,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/11/16 02:06:30 | 000,025,232 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/11/16 02:06:25 | 000,054,072 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/11/16 02:06:23 | 000,059,728 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/11/16 02:06:21 | 000,984,144 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/11/16 02:06:20 | 000,071,600 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/11/16 02:05:55 | 000,041,224 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012/11/16 02:05:54 | 000,227,648 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/11/16 01:07:04 | 000,000,000 | —D | C] – C:\ProgramData\GID
[2012/11/14 22:18:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2012/11/14 22:18:53 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2012/11/14 10:39:30 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Local\Secunia PSI
[2012/11/14 08:29:21 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/11/14 08:29:21 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2012/11/14 08:28:38 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2012/11/14 08:28:37 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2012/11/14 08:28:37 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2012/11/14 08:28:37 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2012/11/14 08:28:36 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2012/11/14 08:28:36 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2012/11/14 08:28:36 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2012/11/14 08:28:36 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2012/11/14 08:28:36 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2012/11/14 08:28:36 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2012/11/14 08:28:35 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2012/11/14 08:28:35 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2012/11/14 08:28:35 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2012/11/14 08:28:35 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2012/11/14 08:28:35 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2012/11/14 08:28:35 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2012/11/14 08:28:35 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2012/11/14 08:28:35 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2012/11/14 08:28:35 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2012/11/14 08:28:35 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2012/11/14 08:28:35 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2012/11/14 08:28:35 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2012/11/14 08:28:34 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2012/11/14 08:20:10 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/11/14 08:20:10 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/11/14 08:20:09 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/11/14 08:20:09 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/11/14 08:20:09 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/11/14 08:20:09 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/11/14 08:20:09 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/11/14 08:20:09 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/11/14 08:20:08 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/11/14 08:20:08 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/11/14 08:20:08 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/11/14 08:20:08 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/11/14 08:20:07 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/11/14 08:20:07 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/11/14 08:20:07 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/11/14 08:15:34 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2012/11/14 08:15:33 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2012/11/14 08:15:33 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2012/11/14 08:15:33 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/11/14 08:14:38 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2012/11/14 08:14:38 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2012/11/14 08:14:15 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcorehc.dll
[2012/11/14 08:14:15 | 000,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2012/11/14 08:14:15 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncsi.dll
[2012/11/14 08:14:14 | 000,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcorehc.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netevent.dll
[2012/11/14 08:14:14 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netevent.dll
[2012/11/14 08:14:04 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/11/14 08:14:04 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/11/14 08:14:01 | 000,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2012/11/14 08:14:01 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2012/11/13 21:03:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\GamingWonderland
[2012/11/10 21:31:14 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/11/10 21:30:41 | 000,000,000 | —D | C] – C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpiderOak
[2012/11/10 21:30:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpiderOak
[2012/11/01 22:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\bSaving
[2012/10/25 20:56:30 | 000,000,000 | —D | C] – C:\Users\Bryan\Documents\Aimersoft Video Studio Express
[2012/10/25 20:56:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2012/10/25 20:56:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Aimersoft
[2012/10/25 03:12:26 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:40:00 | 000,108,008 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/10/19 19:00:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/10/19 18:59:38 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/10/19 18:59:38 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/10/19 18:59:38 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/10/19 18:58:12 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/07/12 09:14:08 | 003,405,744 | —- | C] (ESET) – C:\Users\Bryan\OnlineScanner.ocx
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/11/18 01:39:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/18 01:37:00 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Bryan\Desktop\OTL.exe
[2012/11/18 01:29:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/18 01:28:23 | 000,001,346 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | M] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | M] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/18 00:53:55 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/18 00:50:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/11/17 10:52:07 | 000,003,084 | —- | M] () – C:\Windows\Sandboxie.ini
[2012/11/16 22:03:47 | 000,779,306 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/16 22:03:47 | 000,660,296 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/11/16 22:03:47 | 000,121,224 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/11/16 18:29:57 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 18:29:57 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/16 18:21:05 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2012/11/16 16:36:34 | 000,002,120 | —- | M] () – C:\scu.dat
[2012/11/16 09:41:54 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/11/16 03:38:39 | 000,001,962 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/16 03:09:36 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/11/16 03:09:36 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/11/16 03:07:02 | 000,002,378 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:31 | 000,001,110 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 10:30:05 | 000,002,439 | —- | M] () – C:\Users\Bryan\Desktop\Advanced Uninstaller PRO 11.lnk
[2012/11/14 09:40:39 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/14 08:43:02 | 000,334,096 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/05 13:30:02 | 005,770,487 | —- | M] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/10/30 15:51:56 | 000,059,728 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2012/10/30 15:51:55 | 000,984,144 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2012/10/30 15:51:55 | 000,370,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2012/10/30 15:51:55 | 000,262,656 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/10/30 15:51:55 | 000,071,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/10/30 15:51:55 | 000,021,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2012/10/30 15:51:53 | 000,132,864 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2012/10/30 15:51:53 | 000,025,232 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/10/30 15:51:07 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/10/30 15:50:59 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2012/10/30 15:50:30 | 000,285,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2012/10/29 14:46:59 | 000,344,696 | —- | M] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/29 14:42:02 | 000,001,021 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/10/29 10:11:08 | 000,001,121 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerStars.net.lnk
[2012/10/29 10:11:06 | 000,001,097 | —- | M] () – C:\Users\Public\Desktop\PokerStars.net.lnk
[2012/10/27 08:07:03 | 000,001,430 | —- | M] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:03 | 000,001,406 | —- | M] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | M] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/10/25 03:12:26 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTimeVR.qtx
[2012/10/25 03:12:26 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\SysWow64\QuickTime.qts
[2012/10/23 07:39:53 | 000,108,008 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2012/10/23 07:39:52 | 001,034,216 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npdeployJava1.dll
[2012/10/23 07:39:52 | 000,916,456 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/11/18 01:28:23 | 000,001,346 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX YouTube Downloader.lnk
[2012/11/18 01:28:23 | 000,001,322 | —- | C] () – C:\Users\Public\Desktop\WinX YouTube Downloader.lnk
[2012/11/18 01:24:19 | 000,001,358 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Ripper Platinum.lnk
[2012/11/18 01:24:19 | 000,001,334 | —- | C] () – C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
[2012/11/16 16:05:06 | 000,002,120 | —- | C] () – C:\scu.dat
[2012/11/16 03:38:39 | 000,001,962 | —- | C] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/11/14 22:19:00 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/11/14 21:55:30 | 000,001,110 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/11/14 21:55:30 | 000,001,073 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/11/14 08:29:23 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 08:15:33 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/05 12:34:15 | 005,770,487 | —- | C] () – C:\Users\Bryan\Desktop\cure-for-all-diseases.pdf
[2012/10/31 14:57:17 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/10/29 14:46:53 | 000,344,696 | —- | C] () – C:\Users\Bryan\Desktop\ccregbackup1029.reg
[2012/10/27 08:07:03 | 000,001,430 | —- | C] () – C:\Users\Bryan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX HD Video Converter Deluxe.lnk
[2012/10/27 08:07:02 | 000,001,406 | —- | C] () – C:\Users\Bryan\Desktop\WinX HD Video Converter Deluxe.lnk
[2012/10/25 20:56:20 | 000,001,283 | —- | C] () – C:\Users\Bryan\Desktop\Aimersoft Video Studio Express.lnk
[2012/09/14 17:11:09 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/07/12 13:48:22 | 000,000,839 | —- | C] () – C:\Users\Bryan\AppData\Roaming\result.db
[2012/07/12 09:14:18 | 000,000,172 | —- | C] () – C:\Users\Bryan\OnlineScanner.inf
[2012/05/20 21:59:25 | 000,000,000 | —- | C] () – C:\Users\Bryan\cd
[2012/02/15 02:14:35 | 000,000,000 | —- | C] () – C:\Users\Bryan\NetStat
[2012/02/08 03:10:36 | 000,003,084 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/12/28 13:15:52 | 000,000,151 | —- | C] () – C:\Users\Bryan\AppData\Roaming\burnaware.ini
[2011/12/23 14:46:15 | 000,005,632 | —- | C] () – C:\Users\Bryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 22:33:11 | 000,000,000 | —- | C] () – C:\Windows\Ransom.INI
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/07/27 02:20:24 | 000,000,000 | —- | C] () – C:\Users\Bryan\AppData\Local\{E6301488-4DE8-441E-9F4B-23956CD1A782}
[2011/05/18 11:08:35 | 000,148,936 | —- | C] () – C:\Windows\hpoins19.dat
[2011/04/05 08:40:01 | 000,026,032 | —- | C] () – C:\Windows\SysWow64\IDriveEXceedCryReg.exe
[2011/04/05 08:39:57 | 000,055,808 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2011/01/14 21:10:47 | 000,000,193 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2011/01/02 21:40:04 | 000,776,466 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/13 18:08:49 | 000,000,036 | —- | C] () – C:\Users\Bryan\AppData\Local\housecall.guid.cache
[2010/05/08 09:16:55 | 000,007,594 | —- | C] () – C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg
[2010/05/03 12:09:55 | 000,000,632 | RHS- | C] () – C:\Users\Bryan\ntuser.pol
[2010/05/02 13:44:28 | 000,001,102 | —- | C] () – C:\Users\Bryan\AppData\Roaming\wklnhst.dat
========== ZeroAccess Check ==========
[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011/05/09 20:03:26 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Reels
[2011/05/09 19:55:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\7Spins
[2010/08/12 19:25:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\abelhadigital.com
[2011/04/17 10:17:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Absolute Poker
[2010/05/01 21:39:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Acer
[2012/03/03 11:35:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\AdamOutler
[2012/09/01 13:26:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Amazon
[2011/12/22 15:52:32 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Auslogics
[2012/06/07 09:25:37 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Azureus
[2012/03/14 13:24:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Babylon
[2012/11/18 01:26:51 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Claro
[2011/05/27 02:43:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DiamondVipClub
[2011/03/18 22:52:47 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Diceland
[2012/11/18 01:28:27 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Digiarty
[2011/04/04 14:14:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\DriverCure
[2012/11/14 10:20:54 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Dropbox
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Easy Duplicate Finder
[2012/09/07 09:51:08 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Expert PDF 7
[2011/12/23 19:26:48 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\FrostWire
[2012/11/16 01:16:53 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ID Vault
[2011/12/28 14:57:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ImgBurn
[2012/04/12 16:58:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Jaangle
[2010/05/01 21:39:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Leadertech
[2010/05/12 10:46:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Locate32
[2010/05/10 11:07:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Masque
[2011/05/20 20:10:25 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Mayflower
[2011/12/23 14:43:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\MusicNet
[2010/11/12 14:55:41 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Oberon Media
[2010/07/14 17:01:02 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\OpenDNS Updater
[2012/11/14 22:21:29 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Opera
[2010/07/22 11:00:15 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Panda Security
[2011/04/04 14:14:24 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\ParetoLogic
[2010/12/28 17:39:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Pogo
[2010/12/20 13:04:13 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Razer
[2010/12/25 13:19:33 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Returnil
[2011/05/06 18:53:12 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\RomeCasino
[2011/11/23 17:23:44 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SecondLife
[2011/06/11 17:14:59 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Software Inspection Library
[2012/07/04 22:52:11 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Songbird2
[2012/11/10 23:05:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SpiderOak
[2012/03/25 07:02:07 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Spotify
[2012/01/04 19:59:42 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\streamWriter
[2011/12/18 22:58:00 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\SystemNucleus
[2010/05/02 13:44:55 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Template
[2010/06/10 20:24:38 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Thunderbird
[2011/06/11 14:41:16 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Vegascasino21
[2011/05/06 18:54:35 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\VTExtra
[2011/12/14 00:47:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\wargaming.net
[2010/05/02 13:46:49 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WildTangent
[2010/10/27 17:24:01 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Windows Live Writer
[2012/07/31 18:32:43 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\WinPatrol
[2012/01/21 09:22:18 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wise Registry Cleaner
[2012/08/06 14:31:10 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\Wondershare
[2010/06/25 11:03:34 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\X-Setup Pro
[2012/07/22 22:10:40 | 000,000,000 | —D | M] – C:\Users\Bryan\AppData\Roaming\YourFileDownloader
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
< MD5 for: EXPLORER.EXE >
[2011/02/25 22:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 21:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 17:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 21:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 21:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\ERDNT\cache86\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 22:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 04:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 22:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 22:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 21:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 05:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 22:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 21:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 17:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 22:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 22:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 22:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: SERVICES.EXE >
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\ERDNT\cache64\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SVCHOST.EXE >
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: USERINIT.EXE >
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\ERDNT\cache86\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 17:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 17:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\ERDNT\cache64\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\ERDNT\cache64\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 17:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/27 23:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 22:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST375052 8AS SCSI Disk Device
Partitions: 3
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- SM/xD/SD/MMC/MS USB Device
Partitions: 0
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 14.00GB
Starting Offset: 1048576
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100.00MB
Starting Offset: 14681112576
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 685.00GB
Starting Offset: 14785970176
Hidden sectors: 0
========== Alternate Data Streams ==========
@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:6DCFAD3B
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:987CE5C8
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:25FF8A61
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:B7910E41
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:3E996AD9
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FD80436E
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:DC3A4904
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D822654B
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:C966DE9F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:5304CF6F
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:11590865
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C1C705A1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:B84EF836
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:9B7E8561
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:5095D8B1
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:30C74695
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:7C3E753C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F36D7549
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:2E81DAB7
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:0256104B
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:9373B271
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:54997B77
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:1960DAF2
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:C5B78274
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3B3A302E
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:F54781BF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F3AB0B43
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E0648389
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:ABCD2B94
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:962FBFE7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:2A8CD561
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:2881AFC0
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3F3BEF8F
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:F3239111
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
OTL Extras logfile created on: 11/18/2012 1:39:57 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 1.97 Gb Available Physical Memory | 52.46% Memory free
7.50 Gb Paging File | 4.91 Gb Available in Paging File | 65.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 547.20 Gb Free Space | 79.90% Space Free | Partition Type: NTFS
Computer Name: FAMILY | User Name: Bryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{065ABD98-F5B7-4A5E-9F32-C470E8CFE382}" = rport=10243 | protocol=6 | dir=out | app=system |
"{09C3AD09-2DE4-43FE-8960-6B5672570DFC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{13661FAA-49B2-42E0-875A-599ED504E92F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1A52733A-27F1-497E-8319-75C23620B1F6}" = lport=139 | protocol=6 | dir=in | app=system |
"{1F6D207D-AAC9-4F8F-B7CB-24712CE1AF9B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1FD35719-8649-4DD6-95AC-0B62A9D193AB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{531ED8DA-0EEC-426D-A57F-A60BEE904626}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{584774FE-733B-498A-B235-2CFA9EA05DFA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{683C4E01-A4CC-41EC-9A81-2FF4A864D6EB}" = lport=138 | protocol=17 | dir=in | app=system |
"{6D0D193C-12FB-48C1-AF5F-FB53BC34500B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6EC57AFE-CAF4-461B-B793-DE2BE4D5934E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7242F2F1-4E72-4318-97E3-4D29EE44B976}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{82314B2C-F18A-4E5E-838D-0381DFBC1A36}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{90F7B26B-35C5-4734-806D-62D2F1DA0CA0}" = rport=138 | protocol=17 | dir=out | app=system |
"{98318391-E3BE-4D8F-AA65-7A453BD3AD18}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A8D74D3-7169-43E0-A350-6EB48B66E505}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BC629E68-C9CD-47D1-BAFE-BD8F83BBE697}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C058D27F-27BF-4BDB-B400-05627DE0B792}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D18CE43B-6FDA-4614-9470-FB2C43D3CB45}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DDF5C05B-D1E0-4247-A25D-73B4661B82A2}" = lport=445 | protocol=6 | dir=in | app=system |
"{DE6F0476-F00A-4AFE-9821-0C1504851E51}" = lport=137 | protocol=17 | dir=in | app=system |
"{E08385CC-CA86-4090-BB2E-486CC00A5E1F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E1FDE63C-4A1F-4CBF-B104-63EC256602A1}" = rport=137 | protocol=17 | dir=out | app=system |
"{F19F2EE7-2682-454B-8532-90C700B500A8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F5C7536A-A119-4B89-A912-D80700252437}" = rport=445 | protocol=6 | dir=out | app=system |
"{F80A712E-97E0-47DD-AE8D-D177F2ED184C}" = rport=139 | protocol=6 | dir=out | app=system |
"{FF4A6083-17C4-4127-960F-82927DF1AD22}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027F670E-DA28-4121-8644-C5BF657B9744}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{065E72E2-D7BC-47E7-8E3F-4D00819BB823}" = protocol=17 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"{0EE68060-7537-4819-B2CA-3FFFA326A5C7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{13B5C18E-46D6-4465-A5C6-CBD122BD9068}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1423C54D-14E4-4CD2-BB1A-C4848E700804}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{16B64EE6-7938-462E-940D-41A6339B55E6}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{250FA4EE-2370-46AF-BB1C-EB2FFA5F6E0D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2D76D381-BF79-4C06-8931-57204966F73E}" = protocol=6 | dir=out | app=system |
"{2E5F50E0-1812-4576-ADFF-7A2166E5C1FC}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{31007B4D-5B6D-41DA-A744-041F0710615C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{356EE293-DC3E-4B53-945A-91BDD5E5A75A}" = protocol=17 | dir=in | app=c:\program files (x86)\pokerstars\tracer.exe |
"{3F22A01A-0239-41B2-B4CD-154E99EBF045}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4099F175-2B40-4EE1-85E2-9E5BCC740D8E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{40FFECD8-227F-44A4-AD65-D72A018884D2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{41DB31FE-5E40-48E5-B458-7F3B15F05559}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{4F57BEDE-EB17-47DB-A5DD-8EFD3677D025}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{5715D280-6046-4F27-9B89-583D23F9E8B0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5FC80437-14B8-4AF2-8DD6-55D937C3767F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{60907F23-55BD-47D8-BE04-CEC4E2E6143F}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{6351A2D8-7E67-4FEF-BCFF-273427166F07}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{6C613935-5B49-4398-95CB-A46500153830}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{780095B7-9AA0-42F3-9762-77EF830EEC50}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8094DA2D-BFFE-4BDC-96BB-3A363516B651}" = protocol=6 | dir=in | app=c:\program files (x86)\pokerstars\tracer.exe |
"{8DEB4056-33BE-4031-806D-662922D8732B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{92516AF0-311C-44A6-82A1-04416BF90148}" = protocol=6 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"{94E43188-9DA4-42CE-9666-75EA1FD1668D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B0385632-AB92-4C31-AC96-96228000A83D}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{B8AF4B8A-1A3B-48CF-AFB4-0AF70DAF3B12}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD496999-4091-4EE5-8F34-1CD2A9F64BB2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{BEE511C4-9B46-4C73-9DB7-41D04FC3A008}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C384D863-4D35-484D-B8D7-4020E27DF58A}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{C698EEDD-0187-4CEA-8672-AFEB1DB1BE73}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C7F3647A-82C0-48D7-A1E7-CAB6306F1E97}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{D242DAD3-E042-407C-8337-1DEE83881CB7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DD5F8589-2D81-4CAB-BB83-EE71A728F13F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E36F2CDD-33F3-4109-80E1-33829E2112EA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F6FDC3BC-9361-4131-BD0F-C60DE7590737}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{F74540C2-915A-4ECD-BD14-F57B4F67B18C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FC98856A-4506-4762-9F47-D018171FADC5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"TCP Query User{1DFCF2C7-5C46-4E8A-BF0F-C5662076C54C}C:\program files (x86)\ifreetv\ifreetv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ifreetv\ifreetv.exe |
"TCP Query User{5F6D312D-8EE7-455D-9F23-8854320F20EF}C:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{8C5DFD30-3DA5-4605-95AB-476C4AF70387}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{7E5B9ECA-8A8D-4201-9591-D2C79AB4606C}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{E140EAAD-4D6B-48FC-9146-AD18C5FC118E}C:\program files (x86)\ifreetv\ifreetv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ifreetv\ifreetv.exe |
"UDP Query User{F1E9625B-B4A1-46A7-BC69-0D8239D14D4E}C:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\bryan\appdata\roaming\dropbox\bin\dropbox.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{23170F69-40C1-2702-0922-000001000000}" = 7-Zip 9.22 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417009FF}" = Java 7 Update 9 (64-bit)
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{47E5588F-C3A0-11DE-9857-005056C00008}" = Paragon Partition Manager™ 2010 Free Edition
"{563F041C-DFDB-437B-A1E8-E141E0906076}" = Microsoft IntelliPoint 8.0
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CBBBC4D-B0B6-49DB-A421-98C65080D8EE}" = Eraser 6.0.7.1893
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{A62F9CD0-B2E0-4F2A-88F2-79254A3C8539}" = WinPatrol
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0604
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{C0DA129B-1E45-494D-A362-5CD0109C306B}" = WOT for Internet Explorer
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D40DBBFD-B87E-4E45-B15F-753B75C0D7F8}_is1" = Spencerberus System Nucleus
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"HitmanPro36" = HitmanPro 3.6
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Recuva" = Recuva
"Sandboxie" = Sandboxie 3.64 (64-bit)
"SDEPRO20_is1" = SDExplorer 2.1
"WinRAR archiver" = WinRAR 4.01 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{067B277E-F94B-4F04-B380-BA967C00377C}_is1" = MiniTool Partition Wizard Home Edition 6.0
"{069B290F-5398-4629-A009-85B4BCB4B1B9}" = Claro Chrome Toolbar
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = Browser Manager
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216035FF}" = Java™ 6 Update 37
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2FDD750F-49B7-40C1-9D5E-D2955BC0E2D8}" = NVIDIA PhysX
"{30075A70-B5D2-440B-AFA3-FB2021740121}" = Backup Manager Advance
"{30E10267-3B27-42CC-B727-681DEBD30C4D}" = Clean Water Action TriMini Reminder by We-Care.com v5.0.3.2
"{31228E31-2BFF-11D2-8866-00805F0D9D40}" = QPST
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{44A69352-33DD-405E-ADB8-2D768643BBAE}_is1" = AnyBizSoft PDF to Word (Build 3.0.0)
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CB2511D-A074-40E0-A5ED-A875EBBDDF49}" = BotHunter
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6ED53E0C-EAC0-4F0F-947D-6BA817E4C8C3}" = HostsMan 3.2.73
"{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1" = AppGraffiti
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110194827}" = Jewel Quest
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111405753}" = Super Collapse 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119803590}" = Vacation Quest - The Hawaiian Islands
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-510005691}" = Vacation Quest Australia
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{842BEE12-CCCB-43F4-ABAF-CBA6DFE2583D}" = Nero BurnLite 10
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88603FC0-6B3C-442D-981E-E3D49F083548}_is1" = NovaBench 3.0.4
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9191979D-821C-4EA8-B021-2DA1D859A7C5}" = GuardedID
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A54F806B-A2E1-4794-A7FE-365167EC67CB}" = Masque IGT Slots Little Green Men
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AA468551-1794-42FE-B504-C41D75EEBDF2}_is1" = Partition Wizard Home Edition 5.0
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB627AF2-9C7E-4DBD-816B-3B2646B81E89}" = Nero BurnLite 10
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C268B5E1-A5DA-11DF-A289-005056C00008}" = Paragon Backup & Recovery™ 2011 (Advanced) Free
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E6A9840C-6FDA-4CAD-A783-6A7E73185094}" = HoDoKu
"{E6B43401-E818-4961-AFED-118DD8E87642}" = RAF
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4194A69-7B8F-4C9B-BDFF-E55126C9200F}_is1" = Anti-Malware Toolkit 1.13.326
"{FC279721-37A6-4777-AFD8-7A56681EBA14}" = Expert PDF 7 Reader
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"1ClickDownload" = FirstRowSportApp
"Acer Assist" = Acer Assist
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Aimersoft Video Studio Express_is1" = Aimersoft Video Studio Express(Build [removed])
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.17
"Android SDK Tools" = Android SDK Tools
"Anti-Twin 2012-06-23 06.28.20" = Anti-Twin (Installation 6/23/2012)
"AU11_is1" = Advanced Uninstaller PRO - Version 11
"avast" = avast! Internet Security
"Belarc Advisor" = Belarc Advisor 8.1
"Best of Slots II" = Best of Slots II
"BFGC" = Big Fish Games: Game Manager
"BFG-Gardenscapes - Mansion Makeover" = Gardenscapes: Mansion Makeover™
"BFG-Spirits of Mystery - Song of the Phoenix" = Spirits of Mystery: Song of the Phoenix
"bSaving" = bSaving
"BurnAware Home_is1" = BurnAware Home 4.3
"claro" = Claro LTD toolbar
"Coupon Companion" = Coupon Companion
"Easy Duplicate Finder_is1" = Easy Duplicate Finder v. 3.2
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"FinePix Genie_is1" = FUJIFILM MyFinePix Studio 2.0
"FrostWire 5" = FrostWire 5.3.9
"GamesBar" = GamesBar [removed]
"Google Chrome" = Google Chrome
"Gospel_Internet_Radio Toolbar" = Gospel Internet Radio Toolbar
"Hotkey Utility" = Hotkey Utility
"Identity Card" = Identity Card
"IDrive_is1" = IDrive version 3.4.0 April 05, 2011
"ImgBurn" = ImgBurn
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}" = Acer Backup Manager
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"Jaangle music management" = Jaangle music management
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.2.0 (Standard)
"MacX HD Video Converter Pro For Windows_is1" = MacX HD Video Converter Pro For Windows 3.12.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Maps_Bar Toolbar" = Maps Bar Toolbar
"Minefield (4.0b4pre)" = Minefield (4.0b4pre)
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenDNS Updater" = OpenDNS Updater 2.2.1
"PdaNet_is1" = PdaNet for Android 3.50
"Picasa 3" = Picasa 3
"PokerStars" = PokerStars
"PokerStars.net" = PokerStars.net
"PunkBusterSvc" = PunkBuster Services
"Quackle_is1" = Quackle 0.96 [Beta]
"Revo Uninstaller" = Revo Uninstaller 1.93
"Secunia PSI" = Secunia PSI (2.0.0.4003)
"SpiderOak" = SpiderOak
"SpywareBlaster_is1" = SpywareBlaster 4.5
"Surf Canyon" = Fast Search
"SystemRequirementsLab" = System Requirements Lab
"VideoPerformer" = VideoPerformer
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"WinX DVD Ripper Platinum_is1" = WinX DVD Ripper Platinum 7.0.0
"WinX HD Video Converter Deluxe_is1" = WinX HD Video Converter Deluxe 3.12.4
"WinX YouTube Downloader 3.0.3_is1" = WinX YouTube Downloader 3.0.3
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 6.21
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Spotify" = Spotify
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .
Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.
Error - 11/16/2012 5:44:44 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .
Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Eraser Control driver. System Error: The system cannot find the
file specified. .
Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Iron Driver. System Error: The system cannot find the file specified.
.
Error - 11/16/2012 6:05:37 AM | Computer Name = Family | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image
of binary Symantec Network Security WFP Driver. System Error: The system cannot find
the file specified. .
Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 13
Description =
Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 13
Description =
Error - 11/16/2012 1:16:52 PM | Computer Name = Family | Source = VSS | ID = 8193
Description =
Error - 11/16/2012 7:29:59 PM | Computer Name = Family | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
[ System Events ]
Error - 11/16/2012 1:32:58 PM | Computer Name = Family | Source = Service Control Manager | ID = 7000
Description = The avast! Firewall service failed to start due to the following error:
%%1053
Error - 11/16/2012 1:42:54 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.
Error - 11/16/2012 9:51:00 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.
Error - 11/16/2012 10:21:27 PM | Computer Name = Family | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:18:00 PM on ?11/?16/?2012 was unexpected.
Error - 11/16/2012 10:21:05 PM | Computer Name = Family | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.
Error - 11/17/2012 12:23:46 AM | Computer Name = Family | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.
Error - 11/17/2012 12:33:49 PM | Computer Name = Family | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Netman service.
Error - 11/17/2012 8:01:41 PM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.
Error - 11/17/2012 11:45:44 PM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.
Error - 11/18/2012 12:25:58 AM | Computer Name = Family | Source = Schannel | ID = 36887
Description = The following fatal alert was received: 40.
< End of report >
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-11-18 02:05:01
—————————–
02:05:01.676 OS Version: Windows x64 6.1.7601 Service Pack 1
02:05:01.676 Number of processors: 2 586 0x602
02:05:01.677 ComputerName: FAMILY UserName: Bryan
02:05:03.355 Initialize success
02:05:03.428 AVAST engine defs: 12111800
02:05:36.962 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000070
02:05:36.964 Disk 0 Vendor: ST375052 CC44 Size: 715404MB BusType: 3
02:05:36.984 Disk 0 MBR read successfully
02:05:36.986 Disk 0 MBR scan
02:05:36.989 Disk 0 unknown MBR code
02:05:36.999 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 14000 MB offset 2048
02:05:37.014 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 28674048
02:05:37.019 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 701302 MB offset 28878848
02:05:37.032 Disk 0 scanning C:\Windows\system32\drivers
02:05:46.645 Service scanning
02:06:02.718 Modules scanning
02:06:02.724 Disk 0 trace - called modules:
02:06:02.748 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys
02:06:02.752 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004962790]
02:06:02.756 3 CLASSPNP.SYS[fffff88001bc743f] -> nt!IofCallDriver -> [0xfffffa80046a4e40]
02:06:02.761 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\00000070[0xfffffa8004699530]
02:06:04.358 AVAST engine scan C:\Windows
02:06:06.480 AVAST engine scan C:\Windows\system32
02:08:20.831 AVAST engine scan C:\Windows\system32\drivers
02:08:33.052 AVAST engine scan C:\Users\Bryan
02:10:18.374 Disk 0 MBR has been saved successfully to "C:\Users\Bryan\Desktop\MBR.dat"
02:10:18.383 The log file has been saved successfully to "C:\Users\Bryan\Desktop\aswMBR.txt"
The attachment is also added in the manage current attahcments menu. THank You.