This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help remove click.livesearchnow.com [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I am having the worst time with chrome and firefox, when I click on any links it sends me to click.livesearchnow sometimes it send to butterfly search and other click.search pages I have run malwarebytes, search and destroy, combofix and nothing will remove it any help would be great' Thanks
Hello Matt24 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested


A note about ComboFix - while you may see ComboFix being used quite often, it should never be run unsupervised (as stated in the disclaimer that is first displayed by ComboFix when you run it)

All diagnostic and “fixing” programs/tools are used to search for or target specific malware. Throwing these randomly at your computer in the hope of a quick cure may render your machine a doorstop.

That said, let’s sort your problem out. :)

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Thanks for helping:



OTL:

OTL logfile created on: 2/11/2013 6:27:48 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Matt\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.93 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 56.23% Memory free
7.86 Gb Paging File | 5.97 Gb Available in Paging File | 75.94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.37 Gb Total Space | 160.52 Gb Free Space | 56.05% Space Free | Partition Type: NTFS
Drive D: | 7.44 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: MATT-PC | User Name: Matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/02/11 18:08:37 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Matt\Desktop\OTL.exe
PRC - [2013/02/10 15:51:53 | 001,124,016 | —- | M] () – C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2013/02/08 15:42:32 | 000,965,296 | —- | M] () – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/12/09 04:51:30 | 000,336,992 | —- | M] (Power Software Ltd) – C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2012/11/01 15:34:28 | 002,717,816 | —- | M] (PC Tools) – C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe
PRC - [2012/10/24 15:13:26 | 000,168,384 | —- | M] (Safer-Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2012/10/23 17:40:06 | 000,580,728 | —- | M] (Threat Expert Ltd.) – C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2012/08/09 22:12:18 | 000,055,184 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
PRC - [2009/03/10 00:53:06 | 000,232,192 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/03/10 00:53:02 | 000,044,800 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/02/18 22:42:50 | 000,866,824 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe


========== Modules (No Company Name) ==========

MOD - [2013/02/10 15:51:53 | 001,124,016 | —- | M] () – C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2013/02/08 15:42:33 | 000,156,848 | —- | M] () – C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\SiteSafety.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/02/01 22:28:14 | 000,460,199 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\sqlite3.dll
MOD - [2003/06/07 16:30:08 | 000,057,344 | —- | M] () – C:\Program Files (x86)\Launch Manager\PowerUtl.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/07/11 13:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/03/11 02:10:42 | 000,738,336 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerSvc.exe – (ePowerSvc)
SRV - [2013/02/08 15:42:32 | 000,965,296 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe – (vToolbarUpdater14.1.7)
SRV - [2013/02/08 00:25:31 | 000,251,248 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/02/06 12:51:00 | 000,115,608 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/10/23 17:40:06 | 000,580,728 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2012/07/13 13:14:14 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/10 00:53:02 | 000,044,800 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2008/11/03 22:41:00 | 000,437,248 | —- | M] (Conexant Systems, Inc.) [Auto | Running] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/02/08 15:42:34 | 000,039,768 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtpx64.sys – (avgtp)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/12/09 04:51:20 | 000,126,944 | —- | M] (Power Software Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\scdemu.sys – (SCDEmu)
DRV:64bit: - [2012/11/01 15:35:14 | 000,253,256 | —- | M] (PC Tools) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\PCTSD64.sys – (PCTSD)
DRV:64bit: - [2012/10/23 17:40:32 | 000,077,144 | —- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PCTBD64.sys – (PCTBD)
DRV:64bit: - [2012/09/28 10:32:56 | 000,053,760 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/03/08 17:40:52 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/28 11:43:18 | 001,096,176 | —- | M] (PC Tools) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\pctEFA64.sys – (pctEFA)
DRV:64bit: - [2012/02/28 11:43:12 | 000,453,896 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\pctDS64.sys – (pctDS)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/01/13 16:37:18 | 007,675,392 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NETw5s64.sys – (NETw5s64)
DRV:64bit: - [2009/08/11 12:59:50 | 000,686,080 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CHDRT64.sys – (CnxtHdAudService)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 15:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64)
DRV:64bit: - [2009/06/10 15:34:36 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 05:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/02/24 17:35:44 | 000,255,552 | —- | M] (MagicISO, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mcdbus.sys – (mcdbus)
DRV:64bit: - [2009/02/13 16:24:56 | 001,485,824 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_DPV.sys – (HSF_DPV)
DRV:64bit: - [2009/02/13 16:20:56 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAXHWAZL.sys – (CAXHWAZL)
DRV:64bit: - [2009/02/13 16:19:34 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_CNXT.sys – (winachsf)
DRV:64bit: - [2009/02/06 13:33:04 | 000,262,192 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2008/11/03 22:40:46 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2008/09/22 08:49:58 | 000,126,464 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2008/01/30 21:48:32 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2008/01/30 21:48:16 | 000,016,384 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2006/06/19 00:27:24 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACGW


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7ACGW_enUS460
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-results.com/web?q={searc…;ver=4.0.0.1884
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{D917CE67-50C0-430E-B202-735691AEB904}: "URL" = http://search.conduit.com/ResultsExt.aspx?…143613826712313
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: ifgttglwxp%40ifgttglwxp.org:2.5
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..extensions.enabledAddons: extension21804%40extension21804.com:0.87.24
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\Firefox\ [2013/02/06 01:15:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.1.0.10 [2013/02/10 15:52:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/02/06 12:51:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/11/30 09:02:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Extensions
[2013/02/06 13:51:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions
[2013/02/06 01:14:51 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2013/02/05 23:58:47 | 000,000,000 | —D | M] ("Coupon Companion Plugin") – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]
[2013/02/05 23:58:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]\chrome
[2013/02/05 23:58:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]\defaults
[2013/02/05 23:58:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]\locale
[2013/02/05 23:58:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]\skin
[2013/02/05 23:58:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]\chrome\content\extensionCode
[2012/12/20 15:56:08 | 000,216,743 | —- | M] () (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]
[1635/10/07 13:32:31 | 000,004,816 | —- | M] () (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]
[2013/02/01 00:38:53 | 000,817,973 | —- | M] () (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/02/06 12:50:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/02/06 12:50:19 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/02/06 12:51:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/02/10 15:52:12 | 000,003,593 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/09/11 08:50:15 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/10/13 15:26:34 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.10 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Dark Vibe = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkckeanhmkjaechlhllmapjaaglgpcbj\1.1_0\
CHR - Extension: AdBlock = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.58_0\
CHR - Extension: Coupon Companion Plugin = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jneaojaoiajhnemidnjhoempalnidbhj\1.21.11_0\crossrider
CHR - Extension: Coupon Companion Plugin = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jneaojaoiajhnemidnjhoempalnidbhj\1.21.11_0\
CHR - Extension: Gmail = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/02/04 21:55:00 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000..\Run: [Spybot-S&D; Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{163932E9-DD24-42A6-8F94-69271578A8DB}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.1.7\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\GTW3_Wide.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/18 12:16:41 | 000,000,031 | R— | M] () - D:\AUTORUN.INF – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/02/11 18:08:30 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Matt\Desktop\OTL.exe
[2013/02/11 13:00:51 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2013/02/11 13:00:43 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\AVS4YOU
[2013/02/11 12:53:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2013/02/11 12:52:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2013/02/11 12:52:10 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\GdiPlus.dll
[2013/02/11 12:52:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2013/02/11 02:27:04 | 000,000,000 | —D | C] – C:\Users\Matt\Desktop\Doom 3
[2013/02/11 02:19:38 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{CC64EB07-E325-4244-9FE6-4F3659DE0E8C}
[2013/02/11 01:45:49 | 000,000,000 | —D | C] – C:\Users\Matt\Desktop\cyst show
[2013/02/11 00:48:17 | 000,000,000 | —D | C] – C:\ProgramData\Protexis64
[2013/02/11 00:48:11 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\Corel
[2013/02/11 00:44:27 | 000,000,000 | —D | C] – C:\Users\Matt\Documents\Visual Studio 2008
[2013/02/11 00:40:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SDKs
[2013/02/11 00:40:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 9.0
[2013/02/11 00:39:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel
[2013/02/11 00:33:53 | 000,000,000 | —D | C] – C:\ProgramData\Corel
[2013/02/11 00:24:13 | 000,000,000 | —D | C] – C:\Program Files\Corel
[2013/02/11 00:18:33 | 000,000,000 | —D | C] – C:\ProgramData\CorelDRAW Graphics Suite X6
[2013/02/10 21:55:31 | 000,000,000 | —D | C] – C:\Users\Matt\Desktop\Californication Complete (MKV Compression)
[2013/02/08 15:44:03 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\PowerISO
[2013/02/08 15:43:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
[2013/02/08 15:42:58 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\AVG Secure Search
[2013/02/08 15:42:52 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/02/08 15:42:46 | 000,039,768 | —- | C] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/02/08 15:42:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2013/02/08 15:42:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2013/02/08 15:42:01 | 000,126,944 | —- | C] (Power Software Ltd) – C:\Windows\SysNative\drivers\scdemu.sys
[2013/02/08 15:42:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\PowerISO
[2013/02/08 15:40:55 | 000,000,000 | —D | C] – C:\Users\Matt\Documents\Power iso 5.5 with key
[2013/02/06 20:05:00 | 005,029,686 | R— | C] (Swearware) – C:\Users\Matt\Documents\ComboFix.exe
[2013/02/06 13:36:22 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Matt\Documents\aswMBR.exe
[2013/02/06 13:26:10 | 000,000,000 | —D | C] – C:\_OTL
[2013/02/06 13:10:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Matt\Documents\OTL.exe
[2013/02/06 12:50:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/02/06 00:00:15 | 013,529,576 | —- | C] (Microsoft Corporation) – C:\Users\Matt\Documents\mseinstall.exe
[2013/02/05 23:45:33 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\SUPERAntiSpyware.com
[2013/02/05 23:45:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013/02/05 23:45:25 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/02/05 23:45:25 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/02/05 23:40:36 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/05 22:38:49 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/02/05 22:27:11 | 000,000,000 | —D | C] – C:\ComboFix
[2013/02/05 18:21:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2013/02/05 18:02:10 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2013/02/05 17:52:33 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\QuickScan
[2013/02/04 22:35:35 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/02/04 22:35:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/02/04 22:35:25 | 000,017,272 | —- | C] (Safer Networking Limited) – C:\Windows\SysNative\sdnclean64.exe
[2013/02/04 22:35:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/02/04 22:10:10 | 054,304,848 | —- | C] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\spybotsd 2.0.11.exe
[2013/02/04 22:07:07 | 055,454,464 | —- | C] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\SpybotSD2.exe
[2013/02/04 21:45:32 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[2013/02/04 16:10:27 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\libimobiledevice
[2013/02/04 11:31:49 | 000,000,000 | —D | C] – C:\Users\Matt\Documents\Malwarebytes Anti-Malware 1.70.0.1100 {2013} With Serial Key By Raj's
[2013/02/04 11:29:31 | 001,752,992 | —- | C] (Bleeping Computer, LLC) – C:\Users\Matt\Documents\rkill.exe
[2013/02/04 11:29:07 | 010,754,080 | —- | C] (McAfee Inc.) – C:\Users\Matt\Documents\Stinger.exe
[2013/02/04 11:28:51 | 000,544,360 | —- | C] (McAfee, Inc.) – C:\Users\Matt\Documents\rootkitremover.exe
[2013/02/03 23:40:47 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{C18720FD-5FA9-4137-8F48-09CD72D4FF4C}
[2013/01/30 08:50:34 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\Threat Expert
[2013/01/30 08:45:02 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/01/30 08:45:02 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/01/30 08:45:02 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/01/30 08:44:51 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/30 08:44:18 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/01/30 08:44:12 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\Strongvault
[2013/01/30 08:43:59 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\VisualBeeClient
[2013/01/30 08:43:51 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\Stronghold_LLC
[2013/01/30 08:43:49 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\VisualBeeExe
[2013/01/30 08:43:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strongvault Online Backup
[2013/01/30 08:43:23 | 000,000,000 | —D | C] – C:\ProgramData\VisualBee
[2013/01/30 08:42:37 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\Updater21804
[2013/01/29 23:58:52 | 000,150,648 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2013/01/29 23:58:52 | 000,077,144 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTBD64.sys
[2013/01/29 23:58:51 | 002,280,568 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2013/01/29 23:58:51 | 001,690,744 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2013/01/29 23:57:50 | 000,016,392 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctBTFix64.sys
[2013/01/29 23:57:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2013/01/29 23:57:46 | 000,093,600 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsg64.sys
[2013/01/29 23:57:46 | 000,087,968 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsm64.sys
[2013/01/29 23:57:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Tools
[2013/01/29 23:55:03 | 001,096,176 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctEFA64.sys
[2013/01/29 23:55:03 | 000,453,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctDS64.sys
[2013/01/29 23:54:58 | 000,253,256 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTSD64.sys
[2013/01/29 23:54:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2013/01/29 23:53:06 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2013/01/29 23:53:05 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\TestApp
[2013/01/28 23:06:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Setup Helper
[2013/01/28 23:06:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Hobbyist Software
[2013/01/28 20:45:06 | 000,000,000 | —D | C] – C:\Users\Matt\.shsh
[2013/01/18 15:12:39 | 000,000,000 | —D | C] – C:\Users\Matt\Documents\A+ Tests
[2013/01/17 11:21:54 | 000,016,200 | —- | C] (McAfee, Inc.) – C:\Windows\stinger.sys
[2013/01/17 11:21:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\stinger
[2013/01/17 01:34:56 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{984965D3-CA96-4651-A736-6CBB263355AB}
[2013/01/16 13:34:33 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{57427291-9942-4F65-A80D-CA37B0AC663D}
[2013/01/13 22:24:37 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{83BE3601-9BA6-4822-96E6-00DA2D3A6ED3}
[2013/01/13 07:41:53 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{55FDE6C1-FDF3-4E82-B51F-3A43DAE4778A}
[2012/01/29 19:08:28 | 000,397,824 | —- | C] (RealWorld Graphics) – C:\Program Files (x86)\PhotoResize400.exe

========== Files - Modified Within 30 Days ==========

[2013/02/11 18:25:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/11 18:15:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/11 18:08:37 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Matt\Desktop\OTL.exe
[2013/02/11 15:45:00 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8b4e4cde-0e0b-40fd-9c76-8f8d5b8df0b9.job
[2013/02/11 04:15:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/11 02:11:30 | 000,019,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/11 02:11:30 | 000,019,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/11 02:06:44 | 000,000,266 | —- | M] () – C:\Windows\tasks\AutoKMS.job
[2013/02/11 02:04:42 | 000,504,208 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/11 02:04:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/11 02:04:14 | 3165,265,920 | -HS- | M] () – C:\hiberfil.sys
[2013/02/11 02:00:02 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 7c5c55eb-54b3-40f4-be83-7776230db07c.job
[2013/02/10 20:08:12 | 000,002,207 | —- | M] () – C:\Windows\diagwrn.xml
[2013/02/10 20:08:12 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2013/02/10 18:04:33 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/02/08 15:42:34 | 000,039,768 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/02/08 00:25:30 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/02/08 00:25:30 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/02/06 16:05:09 | 000,001,142 | —- | M] () – C:\Users\Matt\Documents\ComboFix - Shortcut.lnk
[2013/02/06 13:57:44 | 000,016,200 | —- | M] (McAfee, Inc.) – C:\Windows\stinger.sys
[2013/02/06 13:37:46 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Matt\Documents\aswMBR.exe
[2013/02/06 13:10:11 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Matt\Documents\OTL.exe
[2013/02/06 11:43:04 | 000,001,007 | —- | M] () – C:\Users\Matt\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/02/06 00:01:32 | 002,275,785 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2013/02/06 00:00:48 | 013,529,576 | —- | M] (Microsoft Corporation) – C:\Users\Matt\Documents\mseinstall.exe
[2013/02/05 22:25:46 | 005,029,686 | R— | M] (Swearware) – C:\Users\Matt\Documents\ComboFix.exe
[2013/02/05 18:00:24 | 000,807,609 | —- | M] () – C:\Users\Matt\AppData\Local\census.cache
[2013/02/05 17:59:35 | 000,102,540 | —- | M] () – C:\Users\Matt\AppData\Local\ars.cache
[2013/02/05 17:50:25 | 000,000,036 | —- | M] () – C:\Users\Matt\AppData\Local\housecall.guid.cache
[2013/02/04 22:50:52 | 055,454,464 | —- | M] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\SpybotSD2.exe
[2013/02/04 22:32:55 | 054,304,848 | —- | M] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\spybotsd 2.0.11.exe
[2013/02/04 21:55:00 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/02/04 11:29:33 | 001,752,992 | —- | M] (Bleeping Computer, LLC) – C:\Users\Matt\Documents\rkill.exe
[2013/02/04 11:29:20 | 010,754,080 | —- | M] (McAfee Inc.) – C:\Users\Matt\Documents\Stinger.exe
[2013/02/04 11:28:51 | 000,544,360 | —- | M] (McAfee, Inc.) – C:\Users\Matt\Documents\rootkitremover.exe
[2013/01/30 21:04:45 | 000,133,243 | —- | M] () – C:\Users\Matt\Documents\FTF_2013-01-30_1359597892851.pdf
[2013/01/29 23:58:48 | 000,000,814 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.umbrella
[2013/01/29 12:21:32 | 000,730,532 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/29 12:21:32 | 000,627,354 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/29 12:21:32 | 000,107,638 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/28 20:31:08 | 1037,222,452 | —- | M] () – C:\Users\Matt\Documents\iPhone5,1_6.1_10B143_Restore.ipsw
[2013/01/16 09:52:15 | 000,744,030 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== Files Created - No Company Name ==========

[2013/02/11 02:04:16 | 000,504,208 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/10 14:55:44 | 1037,222,452 | —- | C] () – C:\Users\Matt\Documents\iPhone5,1_6.1_10B143_Restore.ipsw
[2013/02/06 16:05:09 | 000,001,142 | —- | C] () – C:\Users\Matt\Documents\ComboFix - Shortcut.lnk
[2013/02/06 00:01:50 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/02/05 23:45:47 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8b4e4cde-0e0b-40fd-9c76-8f8d5b8df0b9.job
[2013/02/05 23:45:46 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 7c5c55eb-54b3-40f4-be83-7776230db07c.job
[2013/02/05 18:00:24 | 000,807,609 | —- | C] () – C:\Users\Matt\AppData\Local\census.cache
[2013/02/05 17:59:35 | 000,102,540 | —- | C] () – C:\Users\Matt\AppData\Local\ars.cache
[2013/02/05 17:50:25 | 000,000,036 | —- | C] () – C:\Users\Matt\AppData\Local\housecall.guid.cache
[2013/02/04 22:35:32 | 000,002,147 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
[2013/01/30 21:04:42 | 000,133,243 | —- | C] () – C:\Users\Matt\Documents\FTF_2013-01-30_1359597892851.pdf
[2013/01/30 08:45:02 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/01/30 08:45:02 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/01/30 08:45:02 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/01/30 08:45:02 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/01/30 08:45:02 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/30 07:22:47 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2013/01/29 23:58:52 | 000,769,144 | —- | C] () – C:\Windows\BDTSupport.dll
[2013/01/29 23:58:52 | 000,003,488 | —- | C] () – C:\Windows\UDB.zip
[2013/01/29 23:58:52 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2013/01/29 23:58:52 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2013/01/29 23:58:52 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2013/01/29 23:55:04 | 002,275,785 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2013/01/16 09:52:15 | 000,744,030 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/10 12:54:59 | 000,193,576 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/12/01 21:04:50 | 000,013,082 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/12/01 21:04:42 | 004,022,504 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2011/12/01 21:04:42 | 000,017,950 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/12/01 19:35:21 | 000,000,000 | —- | C] () – C:\Users\Matt\AppData\Roaming\.NANotifyHere
[2011/11/30 11:23:21 | 000,021,236 | —- | C] () – C:\Users\Matt\AppData\Roaming\UserTile.png

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 00:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2012/10/24 15:13:56 | 003,899,928 | —- | M] (Safer-Networking Ltd.) MD5=BDE07AF546A54F26C6669C3762C22113 – C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache86\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\erdnt\cache64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\erdnt\cache86\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\erdnt\cache64\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD3200BEVT-22ZCT0
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 12.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 286.00GB
Starting Offset: 12583960576
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 170 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84

< End of report >
aswMBR: aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-02-11 18:41:45 —————————– 18:41:45.692 OS Version: Windows x64 6.1.7601 Service Pack 1 18:41:45.692 Number of processors: 2 586 0x170A 18:41:45.693 ComputerName: MATT-PC UserName: Matt 18:41:47.090 Initialize success 18:43:11.289 AVAST engine defs: 13021100 18:43:15.943 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 18:43:15.946 Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 3 18:43:15.966 Disk 0 MBR read successfully 18:43:15.968 Disk 0 MBR scan 18:43:15.973 Disk 0 Windows 7 default MBR code 18:43:15.980 Disk 0 Partition 1 00 27 Hidden NTFS WinRE MSDOS5.0 12000 MB offset 2048 18:43:16.002 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 293243 MB offset 24578048 18:43:16.032 Disk 0 scanning C:\Windows\system32\drivers 18:43:27.729 Service scanning 18:43:55.627 Modules scanning 18:43:55.635 Disk 0 trace - called modules: 18:43:55.679 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 18:43:55.683 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80057a2410] 18:43:56.018 3 CLASSPNP.SYS[fffff88001a0143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80046ce050] 18:43:57.722 AVAST engine scan C:\Windows 18:44:02.280 AVAST engine scan C:\Windows\system32 18:47:26.775 AVAST engine scan C:\Windows\system32\drivers 18:47:41.773 AVAST engine scan C:\Users\Matt 18:49:13.628 Disk 0 MBR has been saved successfully to "C:\Users\Matt\Desktop\MBR.dat" 18:49:13.634 The log file has been saved successfully to "C:\Users\Matt\Desktop\aswMBR.txt"
OTL Extras log

You didn’t get an Extras log because that is the third time you’ve run OTL.
  • open OTL again, click on Extra Registry -> Use Safelist
  • then click Run Scan
You should now get an Extras log.


Please send the log from when you ran ComboFix. ComboFix logs are located at c:\combofix.txt, older logs are at c:\qoobox\combofix2.txt, c:\qoobox\ComboFix3.txt etc

Thanks

satchfan
extras:

OTL Extras logfile created on: 2/12/2013 12:47:12 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Matt\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.93 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 32.74% Memory free
7.86 Gb Paging File | 5.03 Gb Available in Paging File | 64.04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.37 Gb Total Space | 163.43 Gb Free Space | 57.07% Space Free | Partition Type: NTFS
Drive D: | 7.44 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: MATT-PC | User Name: Matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{070433D5-57DB-4981-BB3A-ABC98245BBB2}" = lport=445 | protocol=6 | dir=in | app=system |
"{0880470E-A167-48A9-A0F8-6D1961CB682F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1EF32B45-39D7-46AB-B50E-442C4B697568}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{20F35337-B3EF-4889-808E-4FB4972BD562}" = lport=2869 | protocol=6 | dir=in | app=system |
"{23867563-F137-4A89-A5E0-9C618313561C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2B487058-E229-4D2A-8BF9-77C22BC83094}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2B5D5AA7-A8F7-4745-B2E5-88A5B2A2B1AB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{31689D8C-4D78-47CE-BC0B-8073E8014E69}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{32E0B84A-AA4C-4921-885C-0BFAC75A377A}" = lport=138 | protocol=17 | dir=in | app=system |
"{360D936A-9EE5-4AFF-AD72-B410CCF9D995}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5565EF5A-3EFA-4230-A131-6C758EC55B31}" = rport=137 | protocol=17 | dir=out | app=system |
"{5A48720E-FCB8-4883-898B-0F3027AC1F7F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{70B60D67-54E8-4465-986E-53B3F8312B18}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{84460B80-2E6F-4B41-B8AB-EF7EF7CADDF3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9B741BAC-BE46-41EC-9DA3-1E3DDA66CD4E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A47EBF00-6F99-407A-BCB0-E3B7940854E6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BCCE59B1-DDD0-42ED-B699-311BDD0B85D0}" = lport=10243 | protocol=6 | dir=in | app=system |
"{C4455FF6-958D-4482-808B-726FE1F40161}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{C49AE40B-E495-4EAB-869F-EA386315878B}" = rport=138 | protocol=17 | dir=out | app=system |
"{C6D3452D-A373-4DAA-BCBB-13EDC2C64BB1}" = rport=445 | protocol=6 | dir=out | app=system |
"{CB1FEA7F-D1C3-43E1-91CC-E93E35E53F95}" = lport=139 | protocol=6 | dir=in | app=system |
"{D4E9809A-D104-4496-B1BC-DAAB4DE5B0C5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D5CA36DA-6DAA-47F8-92B5-9FAE0FD6E8E6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D827F9DA-64AE-4CAA-ABEE-1597478A867A}" = lport=137 | protocol=17 | dir=in | app=system |
"{ED299DEE-D6E9-4C46-AEED-4EF64C4E0CEC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F8626BA7-C456-41AF-8BDA-DF3353140115}" = rport=139 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{076D21D7-0935-4272-9A2A-C6411D5BD431}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{08F90AC0-D111-4203-9F3A-E1013D119240}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{09B5EA26-BFC8-4F1A-BC71-27897646A2D8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{10A82503-E3AD-405F-88D6-E9D82797101E}" = protocol=17 | dir=in | app=c:\users\matt\appdata\roaming\utorrent\utorrent.exe |
"{16D044C2-29F1-4BB7-AB0A-0E9D3078D2BC}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{188D1ACB-826C-43CB-91DE-3F11A4C2983C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{18ECD2CD-ED79-40D9-BF9F-D0A49445554F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2218F318-E5AA-4E47-A627-A205E4CA4E7F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{39E93102-339D-47BB-9885-9FB6311F6E0D}" = protocol=6 | dir=out | app=system |
"{3FD89447-A0F3-43FA-B770-82E97C1675A5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{447C5FD2-CF1F-44DD-9F93-5D0E41788B55}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{49858B2A-6313-4980-A26B-2172B1C97F64}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5078DD9C-5619-408C-A8D8-643C5F0772EA}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{533E9B1F-100C-40D2-A4DB-2329E637935C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6634521E-59EB-47B3-BE2F-B4F8510EC863}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{6AFAF130-5E6D-441D-AC5A-129B81D9D5FC}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{6F6AEC64-4848-4B23-900D-5CE5BAD21AA8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8923837A-6781-40BD-9704-AA525C7C912D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{96A7D7BF-AF7F-4522-8EEF-56157CE4C6E7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A2A66999-8D19-49B9-8390-A03C2688C70C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A3C58EFD-9B23-4182-A885-751295ADD6A8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AAA7E329-BC9E-4DBC-98FA-22CBFA84887C}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{ABFB9275-8FD7-497C-A160-1999A77E3AC7}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{B17A5E27-F080-49FF-99D6-9064C30E6AD7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{B3FC62A4-5833-4F39-9613-0AE04170ED7C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BCAE81D4-A649-4ACB-99E6-249CF10EA236}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{BECEA987-4C61-4D1C-ABC9-58C5E790EF3D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C2AAEC63-DE5A-4AB7-8CC6-F0A17C8F486B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{C2F34CC0-921E-4DBE-87B2-04D3066E4A1C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CBABD266-0854-4D0E-9319-69D2F6BA8418}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{CEDD061E-06CE-4C33-994F-F91512B38937}" = protocol=6 | dir=in | app=c:\users\matt\appdata\roaming\utorrent\utorrent.exe |
"{E2193580-B8C1-4771-A726-E21F72BC4BAF}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EADA453D-6BC6-4431-96C8-E0048E1A45BA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F35DBFB8-E2C9-4CE7-A634-1A0468F6E60A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{21EE3C26-D703-48F9-A9F5-0FD8F836644A}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"UDP Query User{E2E22E6B-0D06-45F1-BFFF-EACC8105D2CA}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9AF0B106-56F1-461B-A270-95BC1682E282}" = Broadcom Gigabit NetLink Controller
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway PowerSave Solution
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2437C5C-2D8C-40D2-8059-689AD7239FA3}" = Intel® C++ Redistributables for Windows* on Intel® 64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG Secure Search" = AVG Security Toolbar
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"Browser Defender_is1" = Browser Guard 4.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Companion Plugin" = Coupon Companion Plugin
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"Gateway Screensaver" = Gateway ScreenSaver
"Google Chrome" = Google Chrome
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Gateway MyBackup
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 18.0.2 (x86 en-US)" = Mozilla Firefox 18.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.SingleImage" = Microsoft Office Professional 2010
"PowerISO" = PowerISO
"PS3 Media Server" = PS3 Media Server
"Spyware Doctor" = PC Tools Spyware Doctor 9.1
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.3
"VLC Setup Helper_is1" = VLC Setup Helper
"WinLiveSuite" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Ccleaner Business Edition x64 x86 Tom_Da_Man" = Ccleaner Business Edition x64 x86 Tom_Da_Man
"VisualBee for Microsoft PowerPoint" = VisualBee for Microsoft PowerPoint

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/8/2013 12:55:15 PM | Computer Name = Matt-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Faulting module name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Exception code: 0xc0000005 Fault offset: 0x0000000000012745 Faulting
process id: 0x794 Faulting application start time: 0x01ce061cfa51094e Faulting application
path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe Faulting
module path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe
Report
Id: 4f4aa8b8-7210-11e2-9d5c-001f16ab50fb

Error - 2/8/2013 4:50:34 PM | Computer Name = Matt-PC | Source = WinMgmt | ID = 10
Description =

Error - 2/8/2013 4:50:49 PM | Computer Name = Matt-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Faulting module name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Exception code: 0xc0000005 Fault offset: 0x0000000000012745 Faulting
process id: 0x67c Faulting application start time: 0x01ce063de0e0946f Faulting application
path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe Faulting
module path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe
Report
Id: 37c88d41-7231-11e2-8b63-001f16ab50fb

Error - 2/9/2013 1:31:26 AM | Computer Name = Matt-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 2/10/2013 3:09:13 AM | Computer Name = Matt-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 2/11/2013 3:05:17 AM | Computer Name = Matt-PC | Source = WinMgmt | ID = 10
Description =

Error - 2/11/2013 3:05:27 AM | Computer Name = Matt-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Faulting module name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Exception code: 0xc0000005 Fault offset: 0x0000000000012745 Faulting
process id: 0x5c8 Faulting application start time: 0x01ce0826161dc7e5 Faulting application
path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe Faulting
module path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe
Report
Id: 695700ad-7419-11e2-8e4e-001f16ab50fb

Error - 2/11/2013 6:10:25 AM | Computer Name = Matt-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 2/12/2013 5:59:02 AM | Computer Name = Matt-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 2/12/2013 6:23:43 AM | Computer Name = Matt-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

[ Media Center Events ]
Error - 12/1/2011 8:27:13 PM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 7:27:13 PM - Error connecting to the internet. 7:27:13 PM - Unable
to contact server..

Error - 12/14/2011 10:42:25 PM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 9:42:25 PM - Error connecting to the internet. 9:42:25 PM - Unable
to contact server..

Error - 12/14/2011 10:42:41 PM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 9:42:31 PM - Error connecting to the internet. 9:42:31 PM - Unable
to contact server..

Error - 12/15/2011 1:52:45 AM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 12:52:45 AM - Error connecting to the internet. 12:52:45 AM - Unable
to contact server..

Error - 1/6/2012 7:27:45 AM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 6:27:44 AM - Error connecting to the internet. 6:27:44 AM - Unable
to contact server..

Error - 1/6/2012 7:28:07 AM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 6:27:50 AM - Error connecting to the internet. 6:27:50 AM - Unable
to contact server..

Error - 1/6/2012 11:10:40 AM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 10:10:40 AM - Error connecting to the internet. 10:10:40 AM - Unable
to contact server..

Error - 1/6/2012 11:10:46 AM | Computer Name = Matt-PC | Source = MCUpdate | ID = 0
Description = 10:10:45 AM - Error connecting to the internet. 10:10:45 AM - Unable
to contact server..


< End of report >
combofix: ComboFix 13-02-03.03 - Matt 02/05/2013 22:28:20.3.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4025.2311 [GMT -5:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2013-01-06 to 2013-02-06 ))))))))))))))))))))))))))))))) . . 2013-02-06 03:36 . 2013-02-06 03:36 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-02-06 03:29 . 2013-02-06 03:29 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{94FDE3AC-030A-4FFC-8397-369F21D94562}\offreg.dll 2013-02-06 03:24 . 2013-01-15 07:45 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{94FDE3AC-030A-4FFC-8397-369F21D94562}\mpengine.dll 2013-02-05 23:21 . 2013-02-05 23:21 ——– d—–w- c:\program files (x86)\Kaspersky Lab 2013-02-05 23:02 . 2013-02-06 02:59 ——– d—–w- c:\programdata\Kaspersky Lab 2013-02-05 22:52 . 2013-02-05 22:52 ——– d—–w- c:\users\Matt\AppData\Roaming\QuickScan 2013-02-05 03:35 . 2013-02-05 05:33 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2013-02-05 03:35 . 2009-01-25 18:14 17272 —-a-w- c:\windows\system32\sdnclean64.exe 2013-02-05 03:35 . 2013-02-06 06:15 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2 2013-02-04 21:10 . 2013-02-04 21:10 ——– d—–w- c:\users\Matt\AppData\Local\libimobiledevice 2013-01-30 13:50 . 2013-01-30 13:50 ——– d—–w- c:\users\Matt\AppData\Local\Threat Expert 2013-01-30 13:44 . 2013-02-06 06:15 ——– d—–w- c:\program files (x86)\SearchProtect 2013-01-30 13:44 . 2013-02-06 06:15 ——– d—–w- c:\users\Matt\AppData\Roaming\SearchProtect 2013-01-30 13:44 . 2013-01-30 13:44 ——– d—–w- c:\users\Matt\AppData\Roaming\Strongvault 2013-01-30 13:43 . 2013-02-06 06:15 ——– d—–w- c:\users\Matt\AppData\Local\VisualBeeClient 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\users\Matt\AppData\Local\Stronghold_LLC 2013-01-30 13:43 . 2013-02-06 06:15 ——– d—–w- c:\users\Matt\AppData\Local\VisualBeeExe 2013-01-30 13:43 . 2013-02-06 06:15 ——– d—–w- c:\program files (x86)\VisualBee_V.1 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\programdata\VisualBee 2013-01-30 13:42 . 2013-01-30 13:42 ——– d—–w- c:\users\Matt\AppData\Local\Coupon Companion Plugin 2013-01-30 13:42 . 2013-01-30 13:42 ——– d—–w- c:\users\Matt\AppData\Local\Updater21804 2013-01-30 13:42 . 2013-02-05 02:54 ——– d—–w- c:\program files (x86)\Coupon Companion Plugin 2013-01-30 04:58 . 2012-10-23 22:40 77144 —-a-w- c:\windows\system32\drivers\PCTBD64.sys 2013-01-30 04:58 . 2012-10-23 22:40 150648 —-a-w- c:\windows\SGDetectionTool.dll 2013-01-30 04:58 . 2012-10-23 22:40 769144 —-a-w- c:\windows\BDTSupport.dll 2013-01-30 04:58 . 2012-10-23 22:40 2280568 —-a-w- c:\windows\PCTBDCore.dll 2013-01-30 04:58 . 2012-10-23 22:40 1690744 —-a-w- c:\windows\PCTBDRes.dll 2013-01-30 04:57 . 2012-11-01 20:35 16392 —-a-w- c:\windows\system32\drivers\pctBTFix64.sys 2013-01-30 04:57 . 2012-11-01 20:35 87968 —-a-w- c:\windows\system32\drivers\pctplsm64.sys 2013-01-30 04:57 . 2012-11-01 20:35 93600 —-a-w- c:\windows\system32\drivers\pctplsg64.sys 2013-01-30 04:57 . 2013-01-30 04:57 ——– d—–w- c:\program files (x86)\PC Tools 2013-01-30 04:55 . 2012-02-28 16:43 1096176 —-a-w- c:\windows\system32\drivers\pctEFA64.sys 2013-01-30 04:55 . 2012-02-28 16:43 453896 —-a-w- c:\windows\system32\drivers\pctDS64.sys 2013-01-30 04:54 . 2013-01-30 04:59 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2013-01-30 04:54 . 2012-11-01 20:35 253256 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2013-01-30 04:53 . 2013-01-30 04:57 ——– d—–w- c:\programdata\PC Tools 2013-01-30 04:53 . 2013-01-30 04:53 ——– d—–w- c:\users\Matt\AppData\Roaming\TestApp 2013-01-29 04:06 . 2013-01-29 04:06 ——– d—–w- c:\program files (x86)\Hobbyist Software 2013-01-29 01:45 . 2013-01-29 01:45 ——– d—–w- c:\users\Matt\.shsh 2013-01-17 16:21 . 2013-01-17 16:41 16200 —-a-w- c:\windows\stinger.sys 2013-01-17 16:21 . 2013-01-30 01:36 ——– d—–w- c:\program files (x86)\stinger 2013-01-09 11:49 . 2012-11-23 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 11:49 . 2012-11-23 03:13 68608 —-a-w- c:\windows\system32\taskhost.exe 2013-01-07 20:26 . 2013-01-07 20:26 ——– d—–w- c:\users\Matt\AppData\Local\Programs . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-17 06:28 . 2011-11-30 15:49 273840 ——w- c:\windows\system32\MpSigStub.exe 2013-01-11 20:19 . 2011-11-30 22:07 67599240 —-a-w- c:\windows\system32\MRT.exe 2013-01-09 18:25 . 2012-08-24 00:33 697864 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-01-09 18:25 . 2011-11-30 14:32 74248 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-16 17:11 . 2012-12-21 16:35 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 16:35 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:35 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:35 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-14 21:49 . 2012-02-02 12:56 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-11-30 04:45 . 2013-01-09 11:50 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-11-14 07:06 . 2012-12-12 08:01 17811968 —-a-w- c:\windows\system32\mshtml.dll 2012-11-14 06:32 . 2012-12-12 08:01 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-11-14 06:11 . 2012-12-12 08:01 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 06:04 . 2012-12-12 08:01 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-11-14 06:04 . 2012-12-12 08:01 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 06:02 . 2012-12-12 08:01 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 06:02 . 2012-12-12 08:01 237056 —-a-w- c:\windows\system32\url.dll 2012-11-14 05:59 . 2012-12-12 08:01 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-11-14 05:58 . 2012-12-12 08:01 816640 —-a-w- c:\windows\system32\jscript.dll 2012-11-14 05:57 . 2012-12-12 08:01 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 05:57 . 2012-12-12 08:01 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 05:55 . 2012-12-12 08:01 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-11-14 05:55 . 2012-12-12 08:01 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-11-14 05:53 . 2012-12-12 08:01 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-11-14 05:52 . 2012-12-12 08:01 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-14 05:46 . 2012-12-12 08:01 248320 —-a-w- c:\windows\system32\ieui.dll 2012-11-14 02:09 . 2012-12-12 08:01 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-11-14 01:58 . 2012-12-12 08:01 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57 . 2012-12-12 08:01 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-11-14 01:49 . 2012-12-12 08:01 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48 . 2012-12-12 08:01 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-11-14 01:44 . 2012-12-12 08:01 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-12 02:16 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-12 02:16 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-01-30 00:00 . 2012-01-30 00:08 397824 —-a-w- c:\program files (x86)\PhotoResize400.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll" [2012-11-06 183112] . [HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110211181104}] c:\program files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] 2012-11-06 12:01 183112 —-a-w- c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll" [2012-11-06 183112] . [HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-30 68856] "SearchProtect"="c:\users\Matt\AppData\Roaming\SearchProtect\bin\cltmng.exe" [2013-01-24 2231040] "Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-10-24 3708936] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" [2009-03-10 232192] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-02-19 866824] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "ISTray"="c:\program files (x86)\PC Tools\PC Tools Security\pctsGui.exe" [2012-11-01 2717816] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "SearchProtectAll"="c:\program files (x86)\SearchProtect\bin\cltmng.exe" [2013-01-24 2231040] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-10-24 3821592] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [2012-11-01 253256] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-10-24 1100320] R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-10-24 1367576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368] R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys [2012-10-23 77144] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-01 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2012-02-28 453896] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2012-02-28 1096176] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-10-23 580728] S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway PowerSave Solution\ePowerSvc.exe [2009-03-11 738336] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2009-03-10 44800] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-10-24 168384] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [2009-02-13 292864] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-22 126464] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2010-01-13 7675392] S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-02-01 11:15 1607120 —-a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-02-06 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-24 18:25] . 2013-02-06 c:\windows\Tasks\AutoKMS.job - c:\windows\AutoKMS\AutoKMS.exe [2012-10-10 15:55] . 2013-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 17:54] . 2013-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 17:54] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1684264] "Acer ePower Management"="c:\program files\Gateway\Gateway PowerSave Solution\ePowerTray.exe" [2009-03-11 838176] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-07-20 503864] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI=UN44143613826712313&ctid=CT3268494 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\ FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - google.com FF - ExtSQL: 2012-12-23 12:02; [removed]; c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed] FF - ExtSQL: 2013-01-09 09:56; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-01-30 08:42; [removed]; c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed] FF - ExtSQL: 2013-02-05 17:51; {e001c731-5e37-4538-a5cb-8168736a2360}; c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} FF - user.js: extentions.y2layers.installId - e9611a9e-f20a-402a-b3cd-fa7d96c29719 FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=206a180b0000000000000022fa5668c7&q= FF - user.js: extensions.BabylonToolbar.id - 206a180b0000000000000022fa5668c7 FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB} FF - user.js: extensions.BabylonToolbar.instlDay - 15697 FF - user.js: extensions.BabylonToolbar.vrsn - [removed] FF - user.js: extensions.BabylonToolbar.vrsni - [removed] FF - user.js: extensions.BabylonToolbar_i.vrsnTs - [removed]:02 FF - user.js: extensions.BabylonToolbar.prtnrId - babylon FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar.tlbrId - base FF - user.js: extensions.BabylonToolbar.instlRef - sst FF - user.js: extensions.BabylonToolbar.dfltLng - en FF - user.js: extensions.BabylonToolbar_i.excTlbr - false FF - user.js: extensions.BabylonToolbar.excTlbr - false FF - user.js: extensions.BabylonToolbar.admin - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109220&tt=5112_6 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar.autoRvrt - false FF - user.js: extensions.BabylonToolbar.rvrt - false FF - user.js: extensions.BabylonToolbar_i.newTab - false . - - - - ORPHANS REMOVED - - - - . Notify-SDWinLogon - SDWinLogon.dll WebBrowser-{7AEAE561-714B-45F6-ACE3-4A8AED6E227B} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariDownload" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariExtension" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] @Denied: (A 2) (Everyone) @SACL= @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10a.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] @SACL= "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10a.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] @SACL= @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @SACL= @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @SACL= @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @SACL= @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @SACL= @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @SACL= @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @SACL= @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @SACL= @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @SACL= @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @SACL= @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @SACL= @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @SACL= @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] @Denied: (A 2) (Everyone) @SACL= @="IFlashBroker2" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] @SACL= @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] @SACL= @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-02-05 22:38:46 ComboFix-quarantined-files.txt 2013-02-06 03:38 ComboFix2.txt 2013-02-05 02:58 ComboFix3.txt 2013-01-30 14:34 . Pre-Run: 135,827,275,776 bytes free Post-Run: 135,680,872,448 bytes free . - - End Of File - - 3FF4F20AC6CE494B66CBB2C64A74D043 cbf2: ComboFix 13-02-03.03 - Matt 02/04/2013 21:48:04.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4025.2045 [GMT -5:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Coupon Companion Plugin\CoUPon companion plugin.dll . . ((((((((((((((((((((((((( Files Created from 2013-01-05 to 2013-02-05 ))))))))))))))))))))))))))))))) . . 2013-02-05 02:54 . 2013-02-05 02:54 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-02-04 21:10 . 2013-02-04 21:10 ——– d—–w- c:\users\Matt\AppData\Local\libimobiledevice 2013-02-03 06:56 . 2013-02-04 04:29 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2C53817E-1908-42A2-9358-848931777DA1}\offreg.dll 2013-02-01 14:22 . 2013-01-15 07:45 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2C53817E-1908-42A2-9358-848931777DA1}\mpengine.dll 2013-01-30 13:50 . 2013-01-30 13:50 ——– d—–w- c:\users\Matt\AppData\Local\Threat Expert 2013-01-30 13:44 . 2013-01-30 13:44 ——– d—–w- c:\program files (x86)\SearchProtect 2013-01-30 13:44 . 2013-01-30 14:10 ——– d—–w- c:\users\Matt\AppData\Roaming\SearchProtect 2013-01-30 13:44 . 2013-01-30 13:44 ——– d—–w- c:\users\Matt\AppData\Roaming\Strongvault 2013-01-30 13:43 . 2013-01-30 13:44 ——– d—–w- c:\users\Matt\AppData\Local\VisualBeeClient 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\users\Matt\AppData\Local\Stronghold_LLC 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\users\Matt\AppData\Local\VisualBeeExe 2013-01-30 13:43 . 2013-01-30 13:44 ——– d—–w- c:\program files (x86)\VisualBee_V.1 2013-01-30 13:43 . 2013-01-30 13:50 ——– d-sh–w- c:\windows\SysWow64\AI_RecycleBin 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\programdata\VisualBee 2013-01-30 13:42 . 2013-01-30 13:42 ——– d—–w- c:\users\Matt\AppData\Local\Coupon Companion Plugin 2013-01-30 13:42 . 2013-01-30 13:42 ——– d—–w- c:\users\Matt\AppData\Local\Updater21804 2013-01-30 13:42 . 2013-02-05 02:54 ——– d—–w- c:\program files (x86)\Coupon Companion Plugin 2013-01-30 04:58 . 2012-10-23 22:40 77144 —-a-w- c:\windows\system32\drivers\PCTBD64.sys 2013-01-30 04:58 . 2012-10-23 22:40 150648 —-a-w- c:\windows\SGDetectionTool.dll 2013-01-30 04:58 . 2012-10-23 22:40 769144 —-a-w- c:\windows\BDTSupport.dll 2013-01-30 04:58 . 2012-10-23 22:40 2280568 —-a-w- c:\windows\PCTBDCore.dll 2013-01-30 04:58 . 2012-10-23 22:40 1690744 —-a-w- c:\windows\PCTBDRes.dll 2013-01-30 04:57 . 2012-11-01 20:35 16392 —-a-w- c:\windows\system32\drivers\pctBTFix64.sys 2013-01-30 04:57 . 2012-11-01 20:35 87968 —-a-w- c:\windows\system32\drivers\pctplsm64.sys 2013-01-30 04:57 . 2012-11-01 20:35 93600 —-a-w- c:\windows\system32\drivers\pctplsg64.sys 2013-01-30 04:57 . 2013-01-30 04:57 ——– d—–w- c:\program files (x86)\PC Tools 2013-01-30 04:55 . 2012-02-28 16:43 1096176 —-a-w- c:\windows\system32\drivers\pctEFA64.sys 2013-01-30 04:55 . 2012-02-28 16:43 453896 —-a-w- c:\windows\system32\drivers\pctDS64.sys 2013-01-30 04:54 . 2013-01-30 04:59 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2013-01-30 04:54 . 2012-11-01 20:35 253256 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2013-01-30 04:53 . 2013-01-30 04:57 ——– d—–w- c:\programdata\PC Tools 2013-01-30 04:53 . 2013-01-30 04:53 ——– d—–w- c:\users\Matt\AppData\Roaming\TestApp 2013-01-29 04:06 . 2013-01-29 04:06 ——– d—–w- c:\program files (x86)\Hobbyist Software 2013-01-29 01:45 . 2013-01-29 01:45 ——– d—–w- c:\users\Matt\.shsh 2013-01-17 16:21 . 2013-01-17 16:41 16200 —-a-w- c:\windows\stinger.sys 2013-01-17 16:21 . 2013-01-30 01:36 ——– d—–w- c:\program files (x86)\stinger 2013-01-09 11:49 . 2012-11-23 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 11:49 . 2012-11-23 03:13 68608 —-a-w- c:\windows\system32\taskhost.exe 2013-01-07 20:26 . 2013-01-07 20:26 ——– d—–w- c:\users\Matt\AppData\Local\Programs . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-17 06:28 . 2011-11-30 15:49 273840 ——w- c:\windows\system32\MpSigStub.exe 2013-01-11 20:19 . 2011-11-30 22:07 67599240 —-a-w- c:\windows\system32\MRT.exe 2013-01-09 18:25 . 2012-08-24 00:33 697864 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-01-09 18:25 . 2011-11-30 14:32 74248 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-16 17:11 . 2012-12-21 16:35 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 16:35 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:35 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:35 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-14 21:49 . 2012-02-02 12:56 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-11-30 04:45 . 2013-01-09 11:50 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-11-14 07:06 . 2012-12-12 08:01 17811968 —-a-w- c:\windows\system32\mshtml.dll 2012-11-14 06:32 . 2012-12-12 08:01 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-11-14 06:11 . 2012-12-12 08:01 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 06:04 . 2012-12-12 08:01 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-11-14 06:04 . 2012-12-12 08:01 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 06:02 . 2012-12-12 08:01 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 06:02 . 2012-12-12 08:01 237056 —-a-w- c:\windows\system32\url.dll 2012-11-14 05:59 . 2012-12-12 08:01 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-11-14 05:58 . 2012-12-12 08:01 816640 —-a-w- c:\windows\system32\jscript.dll 2012-11-14 05:57 . 2012-12-12 08:01 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 05:57 . 2012-12-12 08:01 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 05:55 . 2012-12-12 08:01 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-11-14 05:55 . 2012-12-12 08:01 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-11-14 05:53 . 2012-12-12 08:01 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-11-14 05:52 . 2012-12-12 08:01 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-14 05:46 . 2012-12-12 08:01 248320 —-a-w- c:\windows\system32\ieui.dll 2012-11-14 02:09 . 2012-12-12 08:01 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-11-14 01:58 . 2012-12-12 08:01 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57 . 2012-12-12 08:01 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-11-14 01:49 . 2012-12-12 08:01 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48 . 2012-12-12 08:01 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-11-14 01:44 . 2012-12-12 08:01 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-12 02:16 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-12 02:16 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-01-30 00:00 . 2012-01-30 00:08 397824 —-a-w- c:\program files (x86)\PhotoResize400.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll" [2012-11-06 183112] . [HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] 2012-11-06 12:01 183112 —-a-w- c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll" [2012-11-06 183112] . [HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-30 68856] "SearchProtect"="c:\users\Matt\AppData\Roaming\SearchProtect\bin\cltmng.exe" [2013-01-24 2231040] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" [2009-03-10 232192] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-02-19 866824] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "ISTray"="c:\program files (x86)\PC Tools\PC Tools Security\pctsGui.exe" [2012-11-01 2717816] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "SearchProtectAll"="c:\program files (x86)\SearchProtect\bin\cltmng.exe" [2013-01-24 2231040] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [2012-11-01 253256] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368] R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys [2012-10-23 77144] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-01 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2012-02-28 453896] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2012-02-28 1096176] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-10-23 580728] S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway PowerSave Solution\ePowerSvc.exe [2009-03-11 738336] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2009-03-10 44800] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [2009-02-13 292864] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-22 126464] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2010-01-13 7675392] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-02-01 11:15 1607120 —-a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-02-05 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-24 18:25] . 2013-02-04 c:\windows\Tasks\AutoKMS.job - c:\windows\AutoKMS\AutoKMS.exe [2012-10-10 15:55] . 2013-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 17:54] . 2013-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 17:54] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1684264] "Acer ePower Management"="c:\program files\Gateway\Gateway PowerSave Solution\ePowerTray.exe" [2009-03-11 838176] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-07-20 503864] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI=UN44143613826712313&ctid=CT3268494 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\ FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - google.com FF - ExtSQL: 2012-12-23 12:02; [removed]; c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed] FF - ExtSQL: 2013-01-09 09:56; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-01-29 23:58; {cb84136f-9c44-433a-9048-c5cd9df1dc16}; c:\program files (x86)\PC Tools\PC Tools Security\BDT\Firefox FF - ExtSQL: 2013-01-30 08:42; [removed]; c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed] FF - user.js: extentions.y2layers.installId - e9611a9e-f20a-402a-b3cd-fa7d96c29719 FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=206a180b0000000000000022fa5668c7&q= FF - user.js: extensions.BabylonToolbar.id - 206a180b0000000000000022fa5668c7 FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB} FF - user.js: extensions.BabylonToolbar.instlDay - 15697 FF - user.js: extensions.BabylonToolbar.vrsn - [removed] FF - user.js: extensions.BabylonToolbar.vrsni - [removed] FF - user.js: extensions.BabylonToolbar_i.vrsnTs - [removed]:02 FF - user.js: extensions.BabylonToolbar.prtnrId - babylon FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar.tlbrId - base FF - user.js: extensions.BabylonToolbar.instlRef - sst FF - user.js: extensions.BabylonToolbar.dfltLng - en FF - user.js: extensions.BabylonToolbar_i.excTlbr - false FF - user.js: extensions.BabylonToolbar.excTlbr - false FF - user.js: extensions.BabylonToolbar.admin - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109220&tt=5112_6 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar.autoRvrt - false FF - user.js: extensions.BabylonToolbar.rvrt - false FF - user.js: extensions.BabylonToolbar_i.newTab - false . - - - - ORPHANS REMOVED - - - - . BHO-{11111111-1111-1111-1111-110211181104} - c:\program files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll WebBrowser-{7AEAE561-714B-45F6-ACE3-4A8AED6E227B} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariDownload" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariExtension" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] @Denied: (A 2) (Everyone) @SACL= @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10a.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] @SACL= "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10a.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] @SACL= @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @SACL= @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @SACL= @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @SACL= @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @SACL= @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @SACL= @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @SACL= @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @SACL= @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @SACL= @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @SACL= @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @SACL= @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @SACL= @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] @Denied: (A 2) (Everyone) @SACL= @="IFlashBroker2" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] @SACL= @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] @SACL= @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-02-04 21:58:30 ComboFix-quarantined-files.txt 2013-02-05 02:58 ComboFix2.txt 2013-01-30 14:34 . Pre-Run: 128,056,709,120 bytes free Post-Run: 127,864,762,368 bytes free . - - End Of File - - 5D283D75E5E2532BB734975EEC510C2C cmbf3: ComboFix 12-07-31.03 - Matt 01/30/2013 8:47.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4025.1956 [GMT -5:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\StrongVaultApp.exe.lnk . . ((((((((((((((((((((((((( Files Created from 2012-12-28 to 2013-01-30 ))))))))))))))))))))))))))))))) . . 2013-01-30 14:01 . 2013-01-30 14:01 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-01-30 13:50 . 2013-01-30 13:50 ——– d—–w- c:\users\Matt\AppData\Local\Threat Expert 2013-01-30 13:44 . 2013-01-30 13:44 ——– d—–w- c:\program files (x86)\SearchProtect 2013-01-30 13:44 . 2013-01-30 13:44 ——– d—–w- c:\users\Matt\AppData\Roaming\SearchProtect 2013-01-30 13:44 . 2013-01-30 13:44 ——– d—–w- c:\users\Matt\AppData\Roaming\Strongvault 2013-01-30 13:43 . 2013-01-30 13:44 ——– d—–w- c:\users\Matt\AppData\Local\VisualBeeClient 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\users\Matt\AppData\Local\Stronghold_LLC 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\users\Matt\AppData\Local\VisualBeeExe 2013-01-30 13:43 . 2013-01-30 13:44 ——– d—–w- c:\program files (x86)\VisualBee_V.1 2013-01-30 13:43 . 2013-01-30 13:50 ——– d-sh–w- c:\windows\SysWow64\AI_RecycleBin 2013-01-30 13:43 . 2013-01-30 13:43 ——– d—–w- c:\programdata\VisualBee 2013-01-30 13:42 . 2013-01-30 13:42 ——– d—–w- c:\users\Matt\AppData\Local\Coupon Companion Plugin 2013-01-30 13:42 . 2013-01-30 13:42 ——– d—–w- c:\users\Matt\AppData\Local\Updater21804 2013-01-30 13:42 . 2013-01-30 13:42 ——– d—–w- c:\program files (x86)\Coupon Companion Plugin 2013-01-30 04:58 . 2012-10-23 22:40 77144 —-a-w- c:\windows\system32\drivers\PCTBD64.sys 2013-01-30 04:58 . 2012-10-23 22:40 150648 —-a-w- c:\windows\SGDetectionTool.dll 2013-01-30 04:58 . 2012-10-23 22:40 769144 —-a-w- c:\windows\BDTSupport.dll 2013-01-30 04:58 . 2012-10-23 22:40 2280568 —-a-w- c:\windows\PCTBDCore.dll 2013-01-30 04:58 . 2012-10-23 22:40 1690744 —-a-w- c:\windows\PCTBDRes.dll 2013-01-30 04:57 . 2012-11-01 20:35 16392 —-a-w- c:\windows\system32\drivers\pctBTFix64.sys 2013-01-30 04:57 . 2012-11-01 20:35 87968 —-a-w- c:\windows\system32\drivers\pctplsm64.sys 2013-01-30 04:57 . 2012-11-01 20:35 93600 —-a-w- c:\windows\system32\drivers\pctplsg64.sys 2013-01-30 04:57 . 2013-01-30 04:57 ——– d—–w- c:\program files (x86)\PC Tools 2013-01-30 04:55 . 2012-02-28 16:43 1096176 —-a-w- c:\windows\system32\drivers\pctEFA64.sys 2013-01-30 04:55 . 2012-02-28 16:43 453896 —-a-w- c:\windows\system32\drivers\pctDS64.sys 2013-01-30 04:54 . 2013-01-30 04:59 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2013-01-30 04:54 . 2012-11-01 20:35 253256 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2013-01-30 04:53 . 2013-01-30 04:57 ——– d—–w- c:\programdata\PC Tools 2013-01-30 04:53 . 2013-01-30 04:53 ——– d—–w- c:\users\Matt\AppData\Roaming\TestApp 2013-01-29 23:10 . 2013-01-15 07:45 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E695DA9F-D8EB-4D61-86EF-B529B5027ED0}\mpengine.dll 2013-01-29 04:06 . 2013-01-29 04:06 ——– d—–w- c:\program files (x86)\Hobbyist Software 2013-01-29 01:45 . 2013-01-29 01:45 ——– d—–w- c:\users\Matt\.shsh 2013-01-17 16:21 . 2013-01-17 16:41 16200 —-a-w- c:\windows\stinger.sys 2013-01-17 16:21 . 2013-01-30 01:36 ——– d—–w- c:\program files (x86)\stinger 2013-01-09 11:49 . 2012-11-23 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 11:49 . 2012-11-23 03:13 68608 —-a-w- c:\windows\system32\taskhost.exe 2013-01-07 20:26 . 2013-01-07 20:26 ——– d—–w- c:\users\Matt\AppData\Local\Programs . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-11 20:19 . 2011-11-30 22:07 67599240 —-a-w- c:\windows\system32\MRT.exe 2013-01-09 18:25 . 2012-08-24 00:33 697864 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-01-09 18:25 . 2011-11-30 14:32 74248 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-16 17:11 . 2012-12-21 16:35 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 16:35 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:35 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 16:35 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-14 21:49 . 2012-02-02 12:56 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-11-30 04:45 . 2013-01-09 11:50 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-11-14 07:06 . 2012-12-12 08:01 17811968 —-a-w- c:\windows\system32\mshtml.dll 2012-11-14 06:32 . 2012-12-12 08:01 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-11-14 06:11 . 2012-12-12 08:01 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 06:04 . 2012-12-12 08:01 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-11-14 06:04 . 2012-12-12 08:01 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 06:02 . 2012-12-12 08:01 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 06:02 . 2012-12-12 08:01 237056 —-a-w- c:\windows\system32\url.dll 2012-11-14 05:59 . 2012-12-12 08:01 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-11-14 05:58 . 2012-12-12 08:01 816640 —-a-w- c:\windows\system32\jscript.dll 2012-11-14 05:57 . 2012-12-12 08:01 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 05:57 . 2012-12-12 08:01 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 05:55 . 2012-12-12 08:01 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-11-14 05:55 . 2012-12-12 08:01 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-11-14 05:53 . 2012-12-12 08:01 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-11-14 05:52 . 2012-12-12 08:01 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-14 05:46 . 2012-12-12 08:01 248320 —-a-w- c:\windows\system32\ieui.dll 2012-11-14 02:09 . 2012-12-12 08:01 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-11-14 01:58 . 2012-12-12 08:01 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57 . 2012-12-12 08:01 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-11-14 01:49 . 2012-12-12 08:01 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48 . 2012-12-12 08:01 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-11-14 01:44 . 2012-12-12 08:01 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-12 02:16 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-12 02:16 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-11-04 15:23 . 2012-11-04 15:23 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-11-04 15:23 . 2012-11-04 15:23 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-11-04 15:23 . 2012-11-04 15:23 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-11-04 15:23 . 2012-11-04 15:23 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-11-04 15:23 . 2012-11-04 15:23 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-11-04 15:23 . 2012-11-04 15:23 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-11-04 15:23 . 2012-11-04 15:23 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-11-04 15:23 . 2012-11-04 15:23 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-11-04 15:23 . 2012-11-04 15:23 89088 —-a-w- c:\windows\system32\ie4uinit.exe 2012-11-04 15:23 . 2012-11-04 15:23 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-11-04 15:23 . 2012-11-04 15:23 82432 —-a-w- c:\windows\system32\icardie.dll 2012-11-04 15:23 . 2012-11-04 15:23 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-11-04 15:23 . 2012-11-04 15:23 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-11-04 15:23 . 2012-11-04 15:23 65024 —-a-w- c:\windows\system32\pngfilt.dll 2012-11-04 15:23 . 2012-11-04 15:23 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-11-04 15:23 . 2012-11-04 15:23 55296 —-a-w- c:\windows\system32\msfeedsbs.dll 2012-11-04 15:23 . 2012-11-04 15:23 534528 —-a-w- c:\windows\system32\ieapfltr.dll 2012-11-04 15:23 . 2012-11-04 15:23 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-11-04 15:23 . 2012-11-04 15:23 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-11-04 15:23 . 2012-11-04 15:23 452608 —-a-w- c:\windows\system32\dxtmsft.dll 2012-11-04 15:23 . 2012-11-04 15:23 448512 —-a-w- c:\windows\system32\html.iec 2012-11-04 15:23 . 2012-11-04 15:23 403248 —-a-w- c:\windows\system32\iedkcs32.dll 2012-11-04 15:23 . 2012-11-04 15:23 39936 —-a-w- c:\windows\system32\iernonce.dll 2012-11-04 15:23 . 2012-11-04 15:23 3695416 —-a-w- c:\windows\system32\ieapfltr.dat 2012-11-04 15:23 . 2012-11-04 15:23 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-11-04 15:23 . 2012-11-04 15:23 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-11-04 15:23 . 2012-11-04 15:23 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-11-04 15:23 . 2012-11-04 15:23 282112 —-a-w- c:\windows\system32\dxtrans.dll 2012-11-04 15:23 . 2012-11-04 15:23 267776 —-a-w- c:\windows\system32\ieaksie.dll 2012-11-04 15:23 . 2012-11-04 15:23 249344 —-a-w- c:\windows\system32\webcheck.dll 2012-11-04 15:23 . 2012-11-04 15:23 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-11-04 15:23 . 2012-11-04 15:23 222208 —-a-w- c:\windows\system32\msls31.dll 2012-11-04 15:23 . 2012-11-04 15:23 197120 —-a-w- c:\windows\system32\msrating.dll 2012-11-04 15:23 . 2012-11-04 15:23 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-11-04 15:23 . 2012-11-04 15:23 163840 —-a-w- c:\windows\system32\ieakui.dll 2012-11-04 15:23 . 2012-11-04 15:23 160256 —-a-w- c:\windows\system32\wextract.exe 2012-11-04 15:23 . 2012-11-04 15:23 160256 —-a-w- c:\windows\system32\ieakeng.dll 2012-11-04 15:23 . 2012-11-04 15:23 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-11-04 15:23 . 2012-11-04 15:23 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-11-04 15:23 . 2012-11-04 15:23 149504 —-a-w- c:\windows\system32\occache.dll 2012-11-04 15:23 . 2012-11-04 15:23 145920 —-a-w- c:\windows\system32\iepeers.dll 2012-11-04 15:23 . 2012-11-04 15:23 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-11-04 15:23 . 2012-11-04 15:23 12288 —-a-w- c:\windows\system32\mshta.exe 2012-11-04 15:23 . 2012-11-04 15:23 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-11-04 15:23 . 2012-11-04 15:23 114176 —-a-w- c:\windows\system32\admparse.dll 2012-11-04 15:23 . 2012-11-04 15:23 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-11-04 15:23 . 2012-11-04 15:23 10752 —-a-w- c:\windows\system32\msfeedssync.exe 2012-11-04 15:23 . 2012-11-04 15:23 103936 —-a-w- c:\windows\system32\inseng.dll 2012-11-04 15:23 . 2012-11-04 15:23 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-11-02 05:59 . 2012-12-12 02:12 478208 —-a-w- c:\windows\system32\dpnet.dll 2012-11-02 05:11 . 2012-12-12 02:12 376832 —-a-w- c:\windows\SysWow64\dpnet.dll 2012-01-30 00:00 . 2012-01-30 00:08 397824 —-a-w- c:\program files (x86)\PhotoResize400.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll" [2012-11-06 183112] . [HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110211181104}] 2013-01-30 13:42 637952 —-a-w- c:\program files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] 2012-11-06 12:01 183112 —-a-w- c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{7aeae561-714b-45f6-ace3-4a8aed6e227b}"= "c:\program files (x86)\VisualBee_V.1\prxtbVisu.dll" [2012-11-06 183112] . [HKEY_CLASSES_ROOT\clsid\{7aeae561-714b-45f6-ace3-4a8aed6e227b}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-30 68856] "SearchProtect"="c:\users\Matt\AppData\Roaming\SearchProtect\bin\cltmng.exe" [2013-01-24 2231040] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" [2009-03-10 232192] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-02-19 866824] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "ISTray"="c:\program files (x86)\PC Tools\PC Tools Security\pctsGui.exe" [2012-11-01 2717816] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "SearchProtectAll"="c:\program files (x86)\SearchProtect\bin\cltmng.exe" [2013-01-24 2231040] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD64.sys [2012-11-01 253256] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 135664] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-09 251400] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 135664] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-01-19 115608] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368] R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\Drivers\PCTBD64.sys [2012-10-23 77144] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-01 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [2012-02-28 453896] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [2012-02-28 1096176] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-10-23 580728] S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway PowerSave Solution\ePowerSvc.exe [2009-03-11 738336] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2009-03-10 44800] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [2009-02-13 292864] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-22 126464] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2010-01-13 7675392] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-01-23 20:15 1607120 —-a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.56\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-01-30 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-24 18:25] . 2013-01-30 c:\windows\Tasks\AutoKMS.job - c:\windows\AutoKMS\AutoKMS.exe [2012-10-10 15:55] . 2013-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 17:54] . 2013-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-10 17:54] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1684264] "Acer ePower Management"="c:\program files\Gateway\Gateway PowerSave Solution\ePowerTray.exe" [2009-03-11 838176] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-07-20 503864] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI=UN44143613826712313&ctid=CT3268494 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\ FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - google.com FF - user.js: extentions.y2layers.installId - e9611a9e-f20a-402a-b3cd-fa7d96c29719 FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=206a180b0000000000000022fa5668c7&q= FF - user.js: extensions.BabylonToolbar.id - 206a180b0000000000000022fa5668c7 FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB} FF - user.js: extensions.BabylonToolbar.instlDay - 15697 FF - user.js: extensions.BabylonToolbar.vrsn - [removed] FF - user.js: extensions.BabylonToolbar.vrsni - [removed] FF - user.js: extensions.BabylonToolbar_i.vrsnTs - [removed]:02 FF - user.js: extensions.BabylonToolbar.prtnrId - babylon FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar.tlbrId - base FF - user.js: extensions.BabylonToolbar.instlRef - sst FF - user.js: extensions.BabylonToolbar.dfltLng - en FF - user.js: extensions.BabylonToolbar_i.excTlbr - false FF - user.js: extensions.BabylonToolbar.excTlbr - false FF - user.js: extensions.BabylonToolbar.admin - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109220&tt=5112_6 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar.autoRvrt - false FF - user.js: extensions.BabylonToolbar.rvrt - false FF - user.js: extensions.BabylonToolbar_i.newTab - false . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file) WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) WebBrowser-{7AEAE561-714B-45F6-ACE3-4A8AED6E227B} - (no file) AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariDownload" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariExtension" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice] @Denied: (2) (S-1-5-21-1026007817-671561051-2026392895-1000) @Denied: (2) (LocalSystem) "Progid"="SafariHTML" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] @Denied: (A 2) (Everyone) @SACL= @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10a.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] @SACL= "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10a.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] @SACL= @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @SACL= @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @SACL= @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @SACL= @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @SACL= @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @SACL= @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @SACL= @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @SACL= @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @SACL= @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable] @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @SACL= @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @SACL= @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @SACL= @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @SACL= @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] @Denied: (A 2) (Everyone) @SACL= @="IFlashBroker2" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] @SACL= @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] @SACL= @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe . ************************************************************************** . Completion time: 2013-01-30 09:34:34 - machine was rebooted ComboFix-quarantined-files.txt 2013-01-30 14:34 . Pre-Run: 144,141,418,496 bytes free Post-Run: 144,247,169,024 bytes free . - - End Of File - - 7F1C0ABD0965A7AD3BD00E3C85B97608
I’d like a couple more scans because some of the things that showed up have obviously not been dealt with – plus, there are some entries that need explanation.


Run Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
==========================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • doubleclick CKScanner.exe then click Search For Files
  • when the cursor hourglass disappears, click Save List To File
  • a message box will verify the file saved
  • double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Satchfan
SecurityCheck:

Results of screen317's Security Check version 0.99.57
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
PC Tools Spyware Doctor with AntiVirus
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
PC Tools Spyware Doctor 9.1
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.70.0.1100
Java™ 6 Update 24
Java 7 Update 7
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.5.502.149
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (18.0.2)
Google Chrome 24.0.1312.56
Google Chrome 24.0.1312.57
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Spybot Teatimer.exe is disabled!
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 3%
````````````````````End of Log``````````````````````












CKscanner:


CKScanner 2.1 - Additional Security Risks - These are not necessarily bad
scanner sequence 3.MN.11.COLBBL
—– EOF —–
That appears to be the second run of CKScanner; please send the result of the first run.

Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-results.com/web?q={searc…;ver=4.0.0.1884
    IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{D917CE67-50C0-430E-B202-735691AEB904}: "URL" = http://search.conduit.com/ResultsExt.aspx?…143613826712313
    [2013/02/05 23:58:47 | 000,000,000 | —D | M] ("Coupon Companion Plugin") – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]
    O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
    [2013/02/03 23:40:47 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{C18720FD-5FA9-4137-8F48-09CD72D4FF4C}
    [2013/02/11 02:19:38 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{CC64EB07-E325-4244-9FE6-4F3659DE0E8C}
    [2013/01/17 01:34:56 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{984965D3-CA96-4651-A736-6CBB263355AB}
    [2013/01/16 13:34:33 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{57427291-9942-4F65-A80D-CA37B0AC663D}
    [2013/01/13 22:24:37 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{83BE3601-9BA6-4822-96E6-00DA2D3A6ED3}
    [2013/01/13 07:41:53 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\{55FDE6C1-FDF3-4E82-B51F-3A43DAE4778A}
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log
NOTE – please do not run OTL again until you have followed the next set of instructions.

===================================================

Download and run Junkware Removal Tool

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.
Please now run OTL again and send a new log.

Logs to include in the next post:

Log from the first CKScanner run
OTL fix log
JRT.txt
New OTL log


Thanks

Satchfan
Ok I guess I got confused a few times. The first CK scan file I never saw it, so thats when I ran it again and posted the 2nd run.

then on accident I closed the OTL fix log with the results of the code you gave me……I did see that it had removed it all before I closed it.
I repeated the same thing and got this:


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Internet Explorer\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}\ not found.
Registry key HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Internet Explorer\SearchScopes\{D917CE67-50C0-430E-B202-735691AEB904}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D917CE67-50C0-430E-B202-735691AEB904}\ not found.
Folder C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Folder C:\Users\Matt\AppData\Local\{C18720FD-5FA9-4137-8F48-09CD72D4FF4C}\ not found.
Folder C:\Users\Matt\AppData\Local\{CC64EB07-E325-4244-9FE6-4F3659DE0E8C}\ not found.
Folder C:\Users\Matt\AppData\Local\{984965D3-CA96-4651-A736-6CBB263355AB}\ not found.
Folder C:\Users\Matt\AppData\Local\{57427291-9942-4F65-A80D-CA37B0AC663D}\ not found.
Folder C:\Users\Matt\AppData\Local\{83BE3601-9BA6-4822-96E6-00DA2D3A6ED3}\ not found.
Folder C:\Users\Matt\AppData\Local\{55FDE6C1-FDF3-4E82-B51F-3A43DAE4778A}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Matt\Desktop\cmd.bat deleted successfully.
C:\Users\Matt\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Matt
->Temp folder emptied: 306557 bytes
->Temporary Internet Files folder emptied: 36470 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 7607920 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10292 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 8.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 02132013_112046

Files\Folders moved on Reboot…
File\Folder C:\Users\Matt\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

PendingFileRenameOperations files…

Registry entries deleted on Reboot…






JRT LOG


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.6.3 (02.12.2013:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Wed 02/13/2013 at 10:50:20.24
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\sweetim
Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim
Successfully deleted: [Registry Key] hkey_current_user\software\visualbee
Successfully deleted: [Registry Key] hkey_local_machine\software\visualbee
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\scripthelper.exe
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\viprotocol.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\protocols\handler\viprotocol
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole.1



~~~ Files

Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\visualbee"
Successfully deleted: [Folder] "C:\Users\Matt\AppData\Roaming\strongvault"
Successfully deleted: [Folder] "C:\Users\Matt\appdata\local\stronghold_llc"
Successfully deleted: [Folder] "C:\Users\Matt\appdata\local\updater21804"
Successfully deleted: [Folder] "C:\Users\Matt\appdata\local\visualbeeclient"
Successfully deleted: [Folder] "C:\Users\Matt\appdata\local\visualbeeexe"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\strongvault online backup"



~~~ FireFox

Successfully deleted: [File] C:\Users\Matt\AppData\Roaming\mozilla\firefox\profiles\r71glmkl.default\extensions\[removed] [Tracur]
Successfully deleted the following from C:\Users\Matt\AppData\Roaming\mozilla\firefox\profiles\r71glmkl.default\prefs.js

user_pref("extensions.crossrider.bic", "139d0dcebf54ff0625094cf5705d9c3b");
user_pref("extensions.crossriderapp21804.21804.InstallationTime", 1360356200);
user_pref("extensions.crossriderapp21804.21804.active", true);
user_pref("extensions.crossriderapp21804.21804.addressbar", "");
user_pref("extensions.crossriderapp21804.21804.addressbarenhanced", "");
user_pref("extensions.crossriderapp21804.21804.backgroundjs", "\n\n//\n");
user_pref("extensions.crossriderapp21804.21804.backgroundver", 30);
user_pref("extensions.crossriderapp21804.21804.can_run_bg_code", true);
user_pref("extensions.crossriderapp21804.21804.certdomaininstaller", "");
user_pref("extensions.crossriderapp21804.21804.changeprevious", false);
user_pref("extensions.crossriderapp21804.21804.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie.InstallationTime.value", "1360356200");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_country_code.expiration", "Fri Feb 15 2013 15:46:59 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie._GPL_country_code.value", "%22US%22");
user_pref("extensions.crossriderapp21804.21804.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.cookie.dbtest.value", "1360356418220");
user_pref("extensions.crossriderapp21804.21804.description", "Coupon Companion");
user_pref("extensions.crossriderapp21804.21804.domain", "");
user_pref("extensions.crossriderapp21804.21804.enablesearch", false);
user_pref("extensions.crossriderapp21804.21804.fbremoteurl", "");
user_pref("extensions.crossriderapp21804.21804.group", 0);
user_pref("extensions.crossriderapp21804.21804.homepage", "");
user_pref("extensions.crossriderapp21804.21804.iframe", false);
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_appVer.value", "44");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_lastVersion.expira
tion", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_nextCheck.expirati
on", "Fri Feb 08 2013 21:43:25 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT-0500 (Eastern Standard Time)");
user_pref("extensions.crossriderapp21804.21804.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.crossriderapp21804.21804.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GPL_=function(){_GPL_PLUGIN.started||_GPL_PLUGIN.prepare({pid:1175,baseCDN:
user_pref("extensions.crossriderapp21804.21804.manifesturl", "");
user_pref("extensions.crossriderapp21804.21804.name", "Coupon Companion Plugin");
user_pref("extensions.crossriderapp21804.21804.newtab", "");
user_pref("extensions.crossriderapp21804.21804.opensearch", "");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return ap
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1.name", "base");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1.ver", 4);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000014.code", "Array.prototype.indexOf||(Array.prototype.indexOf=function(B){if(void 0===this||null===this)throw
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000014.ver", 15);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000015.code", "var a=appAPI.db.getList(),cf_ran=!1,_GPL_BG={vars:{},rules:{},started:!1,allowed:!1,log:function(
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000015.name", "GPL Background (BG)");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_1000015.ver", 32);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_13.code", "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelect
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_13.name", "CrossriderAppUtils");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_13.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined\"){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==\"undefined
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_14.name", "CrossriderUtils");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_14.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!=true)&&(typeof _firefoxVersion!==\"undefined\"&
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_16.name", "FFAppAPIWrapper");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_16.ver", 4);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1.4.2\n * hxxp://jquery.com/\n
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_17.name", "jQuery");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_17.ver", 3);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.d
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_21.name", "debug");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_21.ver", 3);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(B){this.queue.push(B);}};appAPI.ready=fun
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_22.name", "resources");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_22.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferre
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_28.name", "initializer");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_28.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_4.code", "var jQuery = $jquery_171 = $jquery = null;\n\nif (document && typeof document.getElementById !== \"unde
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_4.name", "jquery_1_7_1");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_4.ver", 3);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_47.name", "resources_background");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_47.ver", 1);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPTY_CHANNEL__\";var d=function(j){return(typeof j===\"object\"&&j;!==null);}
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_64.name", "appApiMessage");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_64.ver", 1);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_72.code", "if(appAPI.__should_activate_validation__===true){(function(){var k={};var f=appAPI.appInfo.name;var l=
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_72.name", "appApiValidation");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_72.ver", 1);
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_78.code", "if(typeof jQuery!==\"undefined\"&&(jQuery)&&typeof; navigator!==\"undefined\"&&typeof; navigator.userAge
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_78.name", "CrossriderInfo");
user_pref("extensions.crossriderapp21804.21804.plugins.plugin_78.ver", 2);
user_pref("extensions.crossriderapp21804.21804.plugins_lists.plugins_0", "4,14,78,16,64,47,72,1000015");
user_pref("extensions.crossriderapp21804.21804.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,22,72,1000014,28");
user_pref("extensions.crossriderapp21804.21804.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
user_pref("extensions.crossriderapp21804.21804.pluginsurl", "hxxp://app-static.crossrider.com/plugin/apps/21804/plugins/087/ff/plugins.json");
user_pref("extensions.crossriderapp21804.21804.pluginsversion", 41);
user_pref("extensions.crossriderapp21804.21804.publisher", "215 Apps");
user_pref("extensions.crossriderapp21804.21804.searchstatus", 0);
user_pref("extensions.crossriderapp21804.21804.setnewtab", false);
user_pref("extensions.crossriderapp21804.21804.settingsurl", "");
user_pref("extensions.crossriderapp21804.21804.thankyou", "");
user_pref("extensions.crossriderapp21804.21804.updateinterval", 360);
user_pref("extensions.crossriderapp21804.21804.ver", 44);
user_pref("extensions.crossriderapp21804.apps", "21804");
user_pref("extensions.crossriderapp21804.bic", "139d0dcebf54ff0625094cf5705d9c3b");
user_pref("extensions.crossriderapp21804.cid", 21804);
user_pref("extensions.crossriderapp21804.firstrun", false);
user_pref("extensions.crossriderapp21804.hadappinstalled", true);
user_pref("extensions.crossriderapp21804.installationdate", 1360356200);
user_pref("extensions.crossriderapp21804.lastcheck", 22672603);
user_pref("extensions.crossriderapp21804.lastcheckitem", 22672607);
user_pref("extensions.crossriderapp21804.modetype", "production");
user_pref("extensions.crossriderapp21804.reportInstall", true);
user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,buzzdock,YontooNewOffers");
user_pref("extentions.y2layers.installId", "e9611a9e-f20a-402a-b3cd-fa7d96c29719");
Emptied folder: C:\Users\Matt\AppData\Roaming\mozilla\firefox\profiles\r71glmkl.default\minidumps [115 files]



~~~ Chrome

Dumping contents of C:\Users\Matt\appdata\local\Google\Chrome\User Data\Default\Default
C:\Users\Matt\appdata\local\Google\Chrome\User Data\Default\Default\aagfdhdbdddegcdbgcdhdadidegcgddi
C:\Users\Matt\appdata\local\Google\Chrome\User Data\Default\Default\aagfdhdbdddegcdbgcdhdadidegcgddi\background.js
C:\Users\Matt\appdata\local\Google\Chrome\User Data\Default\Default\aagfdhdbdddegcdbgcdhdadidegcgddi\ContentScript.js
C:\Users\Matt\appdata\local\Google\Chrome\User Data\Default\Default\aagfdhdbdddegcdbgcdhdadidegcgddi\manifest.json

Failed to delete: [Folder] C:\Users\Matt\appdata\local\Google\Chrome\User Data\Default\Default [Default Extension 1.0]
Successfully deleted: [Folder] C:\Users\Matt\appdata\local\Google\Chrome\User Data\Default\Extensions\jneaojaoiajhnemidnjhoempalnidbhj



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 02/13/2013 at 11:07:46.23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
last otl run




OTL logfile created on: 2/13/2013 11:25:10 AM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Matt\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.93 Gb Total Physical Memory | 2.67 Gb Available Physical Memory | 67.96% Memory free
7.86 Gb Paging File | 6.39 Gb Available in Paging File | 81.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.37 Gb Total Space | 160.45 Gb Free Space | 56.03% Space Free | Partition Type: NTFS
Drive D: | 7.44 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: MATT-PC | User Name: Matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/02/11 18:08:37 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Matt\Desktop\OTL.exe
PRC - [2013/02/10 15:51:53 | 001,124,016 | —- | M] () – C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2013/02/08 15:42:32 | 000,965,296 | —- | M] () – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/12/09 04:51:30 | 000,336,992 | —- | M] (Power Software Ltd) – C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2012/11/01 15:34:28 | 002,717,816 | —- | M] (PC Tools) – C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe
PRC - [2012/10/24 15:13:26 | 000,168,384 | —- | M] (Safer-Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2012/10/23 17:40:06 | 000,580,728 | —- | M] (Threat Expert Ltd.) – C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2010/11/20 07:17:55 | 000,257,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2009/03/10 00:53:06 | 000,232,192 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/03/10 00:53:02 | 000,044,800 | —- | M] (NewTech Infosystems, Inc.) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/02/18 22:42:50 | 000,866,824 | —- | M] (Dritek System Inc.) – C:\Program Files (x86)\Launch Manager\LManager.exe


========== Modules (No Company Name) ==========

MOD - [2013/02/10 15:51:53 | 001,124,016 | —- | M] () – C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2013/02/08 15:42:33 | 000,156,848 | —- | M] () – C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\SiteSafety.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/02/01 22:28:14 | 000,460,199 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\sqlite3.dll
MOD - [2003/06/07 16:30:08 | 000,057,344 | —- | M] () – C:\Program Files (x86)\Launch Manager\PowerUtl.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/07/11 13:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/03/11 02:10:42 | 000,738,336 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerSvc.exe – (ePowerSvc)
SRV - [2013/02/08 15:42:32 | 000,965,296 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe – (vToolbarUpdater14.1.7)
SRV - [2013/02/08 00:25:31 | 000,251,248 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/02/06 12:51:00 | 000,115,608 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/10/23 17:40:06 | 000,580,728 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2012/07/13 13:14:14 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/10 00:53:02 | 000,044,800 | —- | M] (NewTech Infosystems, Inc.) [Auto | Running] – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe – (NTI IScheduleSvc)
SRV - [2008/11/03 22:41:00 | 000,437,248 | —- | M] (Conexant Systems, Inc.) [Auto | Running] – C:\Windows\SysWOW64\XAudio64.dll – (HsfXAudioService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/02/08 15:42:34 | 000,039,768 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtpx64.sys – (avgtp)
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/12/09 04:51:20 | 000,126,944 | —- | M] (Power Software Ltd) [Kernel | System | Running] – C:\Windows\SysNative\drivers\scdemu.sys – (SCDEmu)
DRV:64bit: - [2012/11/01 15:35:14 | 000,253,256 | —- | M] (PC Tools) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\PCTSD64.sys – (PCTSD)
DRV:64bit: - [2012/10/23 17:40:32 | 000,077,144 | —- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PCTBD64.sys – (PCTBD)
DRV:64bit: - [2012/09/28 10:32:56 | 000,053,760 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/03/08 17:40:52 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/28 11:43:18 | 001,096,176 | —- | M] (PC Tools) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\pctEFA64.sys – (pctEFA)
DRV:64bit: - [2012/02/28 11:43:12 | 000,453,896 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\pctDS64.sys – (pctDS)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/01/13 16:37:18 | 007,675,392 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NETw5s64.sys – (NETw5s64)
DRV:64bit: - [2009/08/11 12:59:50 | 000,686,080 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CHDRT64.sys – (CnxtHdAudService)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 15:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64)
DRV:64bit: - [2009/06/10 15:34:36 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 05:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/02/24 17:35:44 | 000,255,552 | —- | M] (MagicISO, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mcdbus.sys – (mcdbus)
DRV:64bit: - [2009/02/13 16:24:56 | 001,485,824 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_DPV.sys – (HSF_DPV)
DRV:64bit: - [2009/02/13 16:20:56 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAXHWAZL.sys – (CAXHWAZL)
DRV:64bit: - [2009/02/13 16:19:34 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CAX_CNXT.sys – (winachsf)
DRV:64bit: - [2009/02/06 13:33:04 | 000,262,192 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2008/11/03 22:40:46 | 000,010,240 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\XAudio64.sys – (XAudio)
DRV:64bit: - [2008/09/22 08:49:58 | 000,126,464 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2008/01/30 21:48:32 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2008/01/30 21:48:16 | 000,016,384 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV:64bit: - [2006/06/19 00:27:24 | 000,017,024 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACGW


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7ACGW_enUS460
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: ifgttglwxp%40ifgttglwxp.org:2.5
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..extensions.enabledAddons: extension21804%40extension21804.com:0.87.24
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.1.7\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\Firefox\ [2013/02/06 01:15:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.1.0.10 [2013/02/10 15:52:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/02/06 12:51:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/11/30 09:02:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Extensions
[2013/02/13 11:06:21 | 000,000,000 | —D | M] (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions
[2013/02/06 01:14:51 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/12/20 15:56:08 | 000,216,743 | —- | M] () (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\[removed]
[2013/02/01 00:38:53 | 000,817,973 | —- | M] () (No name found) – C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r71glmkl.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/02/06 12:50:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/02/06 12:50:19 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) – C:\USERS\MATT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R71GLMKL.DEFAULT\EXTENSIONS\[removed]
File not found (No name found) – C:\USERS\MATT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\R71GLMKL.DEFAULT\EXTENSIONS\[removed]
[2013/02/06 12:51:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/02/10 15:52:12 | 000,003,593 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/09/11 08:50:15 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/10/13 15:26:34 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.10 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Dark Vibe = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkckeanhmkjaechlhllmapjaaglgpcbj\1.1_0\
CHR - Extension: AdBlock = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.59_0\
CHR - Extension: Gmail = C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/02/04 21:55:00 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3:64bit: - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000..\Run: [Spybot-S&D; Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{163932E9-DD24-42A6-8F94-69271578A8DB}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\GTW3_Wide.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/18 12:16:41 | 000,000,031 | R— | M] () - D:\AUTORUN.INF – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/13 10:50:15 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/02/13 10:49:51 | 000,000,000 | —D | C] – C:\JRT
[2013/02/13 10:49:24 | 000,547,384 | —- | C] (Oleg N. Scherbakov) – C:\Users\Matt\Desktop\JRT.exe
[2013/02/12 21:30:55 | 000,000,000 | —D | C] – C:\Users\Matt\Desktop\New folder
[2013/02/11 21:44:45 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\uTorrent
[2013/02/11 18:40:20 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Matt\Desktop\aswMBR.exe
[2013/02/11 18:08:30 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Matt\Desktop\OTL.exe
[2013/02/11 13:00:51 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2013/02/11 13:00:43 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\AVS4YOU
[2013/02/11 12:53:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2013/02/11 12:52:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2013/02/11 12:52:10 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\GdiPlus.dll
[2013/02/11 12:52:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2013/02/11 01:45:49 | 000,000,000 | —D | C] – C:\Users\Matt\Desktop\cyst show
[2013/02/11 00:48:17 | 000,000,000 | —D | C] – C:\ProgramData\Protexis64
[2013/02/11 00:48:11 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\Corel
[2013/02/11 00:44:27 | 000,000,000 | —D | C] – C:\Users\Matt\Documents\Visual Studio 2008
[2013/02/11 00:40:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SDKs
[2013/02/11 00:40:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 9.0
[2013/02/11 00:39:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel
[2013/02/11 00:33:53 | 000,000,000 | —D | C] – C:\ProgramData\Corel
[2013/02/11 00:24:13 | 000,000,000 | —D | C] – C:\Program Files\Corel
[2013/02/11 00:18:33 | 000,000,000 | —D | C] – C:\ProgramData\CorelDRAW Graphics Suite X6
[2013/02/10 21:55:31 | 000,000,000 | —D | C] – C:\Users\Matt\Desktop\Californication Complete (MKV Compression)
[2013/02/08 15:44:03 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\PowerISO
[2013/02/08 15:43:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
[2013/02/08 15:42:58 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\AVG Secure Search
[2013/02/08 15:42:52 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2013/02/08 15:42:46 | 000,039,768 | —- | C] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/02/08 15:42:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2013/02/08 15:42:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2013/02/08 15:42:01 | 000,126,944 | —- | C] (Power Software Ltd) – C:\Windows\SysNative\drivers\scdemu.sys
[2013/02/08 15:42:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\PowerISO
[2013/02/06 20:05:00 | 005,029,686 | R— | C] (Swearware) – C:\Users\Matt\Documents\ComboFix.exe
[2013/02/06 13:36:22 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Matt\Documents\aswMBR.exe
[2013/02/06 13:26:10 | 000,000,000 | —D | C] – C:\_OTL
[2013/02/06 13:10:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Matt\Documents\OTL.exe
[2013/02/06 12:50:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/02/06 00:00:15 | 013,529,576 | —- | C] (Microsoft Corporation) – C:\Users\Matt\Documents\mseinstall.exe
[2013/02/05 23:45:33 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\SUPERAntiSpyware.com
[2013/02/05 23:45:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013/02/05 23:45:25 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/02/05 23:45:25 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/02/05 23:40:36 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/02/05 22:38:49 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/02/05 22:27:11 | 000,000,000 | —D | C] – C:\ComboFix
[2013/02/05 18:21:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2013/02/05 18:02:10 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2013/02/05 17:52:33 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\QuickScan
[2013/02/04 22:35:35 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/02/04 22:35:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/02/04 22:35:25 | 000,017,272 | —- | C] (Safer Networking Limited) – C:\Windows\SysNative\sdnclean64.exe
[2013/02/04 22:35:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/02/04 22:10:10 | 054,304,848 | —- | C] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\spybotsd 2.0.11.exe
[2013/02/04 22:07:07 | 055,454,464 | —- | C] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\SpybotSD2.exe
[2013/02/04 21:45:32 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[2013/02/04 16:10:27 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\libimobiledevice
[2013/02/04 11:31:49 | 000,000,000 | —D | C] – C:\Users\Matt\Documents\Malwarebytes Anti-Malware 1.70.0.1100 {2013} With Serial Key By Raj's
[2013/02/04 11:29:31 | 001,752,992 | —- | C] (Bleeping Computer, LLC) – C:\Users\Matt\Documents\rkill.exe
[2013/02/04 11:29:07 | 010,754,080 | —- | C] (McAfee Inc.) – C:\Users\Matt\Documents\Stinger.exe
[2013/02/04 11:28:51 | 000,544,360 | —- | C] (McAfee, Inc.) – C:\Users\Matt\Documents\rootkitremover.exe
[2013/01/30 08:50:34 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Local\Threat Expert
[2013/01/30 08:45:02 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/01/30 08:45:02 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/01/30 08:45:02 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/01/30 08:44:51 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/30 08:44:18 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/01/29 23:58:52 | 000,150,648 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2013/01/29 23:58:52 | 000,077,144 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTBD64.sys
[2013/01/29 23:58:51 | 002,280,568 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2013/01/29 23:58:51 | 001,690,744 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2013/01/29 23:57:50 | 000,016,392 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctBTFix64.sys
[2013/01/29 23:57:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2013/01/29 23:57:46 | 000,093,600 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsg64.sys
[2013/01/29 23:57:46 | 000,087,968 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsm64.sys
[2013/01/29 23:57:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Tools
[2013/01/29 23:55:03 | 001,096,176 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctEFA64.sys
[2013/01/29 23:55:03 | 000,453,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctDS64.sys
[2013/01/29 23:54:58 | 000,253,256 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTSD64.sys
[2013/01/29 23:54:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2013/01/29 23:53:06 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2013/01/29 23:53:05 | 000,000,000 | —D | C] – C:\Users\Matt\AppData\Roaming\TestApp
[2013/01/28 23:06:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Setup Helper
[2013/01/28 23:06:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Hobbyist Software
[2013/01/28 20:45:06 | 000,000,000 | —D | C] – C:\Users\Matt\.shsh
[2013/01/18 15:12:39 | 000,000,000 | —D | C] – C:\Users\Matt\Documents\A+ Tests
[2013/01/17 11:21:54 | 000,016,200 | —- | C] (McAfee, Inc.) – C:\Windows\stinger.sys
[2013/01/17 11:21:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\stinger
[2012/01/29 19:08:28 | 000,397,824 | —- | C] (RealWorld Graphics) – C:\Program Files (x86)\PhotoResize400.exe

========== Files - Modified Within 30 Days ==========

[2013/02/13 11:28:17 | 000,019,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/13 11:28:17 | 000,019,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/13 11:25:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/13 11:23:22 | 000,000,266 | —- | M] () – C:\Windows\tasks\AutoKMS.job
[2013/02/13 11:22:26 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/13 11:21:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/13 11:21:47 | 3165,265,920 | -HS- | M] () – C:\hiberfil.sys
[2013/02/13 11:15:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/13 10:49:35 | 000,547,384 | —- | M] (Oleg N. Scherbakov) – C:\Users\Matt\Desktop\JRT.exe
[2013/02/13 10:45:38 | 000,504,240 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/13 07:45:00 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8b4e4cde-0e0b-40fd-9c76-8f8d5b8df0b9.job
[2013/02/13 03:13:30 | 002,288,773 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2013/02/13 02:00:00 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 7c5c55eb-54b3-40f4-be83-7776230db07c.job
[2013/02/12 18:19:09 | 000,681,984 | —- | M] () – C:\Users\Matt\Desktop\CKScanner.exe
[2013/02/12 18:06:29 | 000,881,914 | —- | M] () – C:\Users\Matt\Desktop\SecurityCheck.exe
[2013/02/11 18:41:32 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Matt\Desktop\aswMBR.exe
[2013/02/11 18:08:37 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Matt\Desktop\OTL.exe
[2013/02/10 20:08:12 | 000,002,207 | —- | M] () – C:\Windows\diagwrn.xml
[2013/02/10 20:08:12 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2013/02/10 18:04:33 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2013/02/08 15:42:34 | 000,039,768 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/02/08 00:25:30 | 000,697,712 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/02/08 00:25:30 | 000,074,096 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/02/06 16:05:09 | 000,001,142 | —- | M] () – C:\Users\Matt\Documents\ComboFix - Shortcut.lnk
[2013/02/06 13:57:44 | 000,016,200 | —- | M] (McAfee, Inc.) – C:\Windows\stinger.sys
[2013/02/06 13:37:46 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Matt\Documents\aswMBR.exe
[2013/02/06 13:10:11 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Matt\Documents\OTL.exe
[2013/02/06 11:43:04 | 000,001,007 | —- | M] () – C:\Users\Matt\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/02/06 00:00:48 | 013,529,576 | —- | M] (Microsoft Corporation) – C:\Users\Matt\Documents\mseinstall.exe
[2013/02/05 22:25:46 | 005,029,686 | R— | M] (Swearware) – C:\Users\Matt\Documents\ComboFix.exe
[2013/02/05 18:00:24 | 000,807,609 | —- | M] () – C:\Users\Matt\AppData\Local\census.cache
[2013/02/05 17:59:35 | 000,102,540 | —- | M] () – C:\Users\Matt\AppData\Local\ars.cache
[2013/02/05 17:50:25 | 000,000,036 | —- | M] () – C:\Users\Matt\AppData\Local\housecall.guid.cache
[2013/02/04 22:50:52 | 055,454,464 | —- | M] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\SpybotSD2.exe
[2013/02/04 22:32:55 | 054,304,848 | —- | M] (Safer-Networking Ltd. ) – C:\Users\Matt\Documents\spybotsd 2.0.11.exe
[2013/02/04 21:55:00 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/02/04 11:29:33 | 001,752,992 | —- | M] (Bleeping Computer, LLC) – C:\Users\Matt\Documents\rkill.exe
[2013/02/04 11:29:20 | 010,754,080 | —- | M] (McAfee Inc.) – C:\Users\Matt\Documents\Stinger.exe
[2013/02/04 11:28:51 | 000,544,360 | —- | M] (McAfee, Inc.) – C:\Users\Matt\Documents\rootkitremover.exe
[2013/01/30 21:04:45 | 000,133,243 | —- | M] () – C:\Users\Matt\Documents\FTF_2013-01-30_1359597892851.pdf
[2013/01/29 23:58:48 | 000,000,814 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.umbrella
[2013/01/29 12:21:32 | 000,730,532 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/29 12:21:32 | 000,627,354 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/29 12:21:32 | 000,107,638 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/28 20:31:08 | 1037,222,452 | —- | M] () – C:\Users\Matt\Documents\iPhone5,1_6.1_10B143_Restore.ipsw
[2013/01/16 09:52:15 | 000,744,030 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== Files Created - No Company Name ==========

[2013/02/12 18:19:05 | 000,681,984 | —- | C] () – C:\Users\Matt\Desktop\CKScanner.exe
[2013/02/12 18:06:18 | 000,881,914 | —- | C] () – C:\Users\Matt\Desktop\SecurityCheck.exe
[2013/02/11 02:04:16 | 000,504,240 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/10 14:55:44 | 1037,222,452 | —- | C] () – C:\Users\Matt\Documents\iPhone5,1_6.1_10B143_Restore.ipsw
[2013/02/06 16:05:09 | 000,001,142 | —- | C] () – C:\Users\Matt\Documents\ComboFix - Shortcut.lnk
[2013/02/06 00:01:50 | 000,001,945 | —- | C] () – C:\Windows\epplauncher.mif
[2013/02/05 23:45:47 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 8b4e4cde-0e0b-40fd-9c76-8f8d5b8df0b9.job
[2013/02/05 23:45:46 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 7c5c55eb-54b3-40f4-be83-7776230db07c.job
[2013/02/05 18:00:24 | 000,807,609 | —- | C] () – C:\Users\Matt\AppData\Local\census.cache
[2013/02/05 17:59:35 | 000,102,540 | —- | C] () – C:\Users\Matt\AppData\Local\ars.cache
[2013/02/05 17:50:25 | 000,000,036 | —- | C] () – C:\Users\Matt\AppData\Local\housecall.guid.cache
[2013/02/04 22:35:32 | 000,002,147 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
[2013/01/30 21:04:42 | 000,133,243 | —- | C] () – C:\Users\Matt\Documents\FTF_2013-01-30_1359597892851.pdf
[2013/01/30 08:45:02 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/01/30 08:45:02 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/01/30 08:45:02 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/01/30 08:45:02 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/01/30 08:45:02 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/30 07:22:47 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2013/01/29 23:58:52 | 000,769,144 | —- | C] () – C:\Windows\BDTSupport.dll
[2013/01/29 23:58:52 | 000,003,488 | —- | C] () – C:\Windows\UDB.zip
[2013/01/29 23:58:52 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2013/01/29 23:58:52 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2013/01/29 23:58:52 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2013/01/29 23:55:04 | 002,288,773 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2013/01/16 09:52:15 | 000,744,030 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/10 12:54:59 | 000,193,576 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/12/01 21:04:50 | 000,013,082 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/12/01 21:04:42 | 004,022,504 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2011/12/01 21:04:42 | 000,017,950 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/12/01 19:35:21 | 000,000,000 | —- | C] () – C:\Users\Matt\AppData\Roaming\.NANotifyHere
[2011/11/30 11:23:21 | 000,021,236 | —- | C] () – C:\Users\Matt\AppData\Roaming\UserTile.png

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 00:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 178 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84

< End of report >







last otl extras


OTL Extras logfile created on: 2/13/2013 11:25:10 AM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Matt\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.93 Gb Total Physical Memory | 2.67 Gb Available Physical Memory | 67.96% Memory free
7.86 Gb Paging File | 6.39 Gb Available in Paging File | 81.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.37 Gb Total Space | 160.45 Gb Free Space | 56.03% Space Free | Partition Type: NTFS
Drive D: | 7.44 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: MATT-PC | User Name: Matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{070433D5-57DB-4981-BB3A-ABC98245BBB2}" = lport=445 | protocol=6 | dir=in | app=system |
"{0880470E-A167-48A9-A0F8-6D1961CB682F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1EF32B45-39D7-46AB-B50E-442C4B697568}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{20F35337-B3EF-4889-808E-4FB4972BD562}" = lport=2869 | protocol=6 | dir=in | app=system |
"{23867563-F137-4A89-A5E0-9C618313561C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2B487058-E229-4D2A-8BF9-77C22BC83094}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2B5D5AA7-A8F7-4745-B2E5-88A5B2A2B1AB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{31689D8C-4D78-47CE-BC0B-8073E8014E69}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{32E0B84A-AA4C-4921-885C-0BFAC75A377A}" = lport=138 | protocol=17 | dir=in | app=system |
"{360D936A-9EE5-4AFF-AD72-B410CCF9D995}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5565EF5A-3EFA-4230-A131-6C758EC55B31}" = rport=137 | protocol=17 | dir=out | app=system |
"{5A48720E-FCB8-4883-898B-0F3027AC1F7F}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{70B60D67-54E8-4465-986E-53B3F8312B18}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{84460B80-2E6F-4B41-B8AB-EF7EF7CADDF3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9B741BAC-BE46-41EC-9DA3-1E3DDA66CD4E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A47EBF00-6F99-407A-BCB0-E3B7940854E6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BCCE59B1-DDD0-42ED-B699-311BDD0B85D0}" = lport=10243 | protocol=6 | dir=in | app=system |
"{C4455FF6-958D-4482-808B-726FE1F40161}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{C49AE40B-E495-4EAB-869F-EA386315878B}" = rport=138 | protocol=17 | dir=out | app=system |
"{C6D3452D-A373-4DAA-BCBB-13EDC2C64BB1}" = rport=445 | protocol=6 | dir=out | app=system |
"{CB1FEA7F-D1C3-43E1-91CC-E93E35E53F95}" = lport=139 | protocol=6 | dir=in | app=system |
"{D4E9809A-D104-4496-B1BC-DAAB4DE5B0C5}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D5CA36DA-6DAA-47F8-92B5-9FAE0FD6E8E6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D827F9DA-64AE-4CAA-ABEE-1597478A867A}" = lport=137 | protocol=17 | dir=in | app=system |
"{ED299DEE-D6E9-4C46-AEED-4EF64C4E0CEC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F8626BA7-C456-41AF-8BDA-DF3353140115}" = rport=139 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{076D21D7-0935-4272-9A2A-C6411D5BD431}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{08F90AC0-D111-4203-9F3A-E1013D119240}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{09B5EA26-BFC8-4F1A-BC71-27897646A2D8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{10A82503-E3AD-405F-88D6-E9D82797101E}" = protocol=17 | dir=in | app=c:\users\matt\appdata\roaming\utorrent\utorrent.exe |
"{16D044C2-29F1-4BB7-AB0A-0E9D3078D2BC}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{188D1ACB-826C-43CB-91DE-3F11A4C2983C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{18ECD2CD-ED79-40D9-BF9F-D0A49445554F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2218F318-E5AA-4E47-A627-A205E4CA4E7F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{39E93102-339D-47BB-9885-9FB6311F6E0D}" = protocol=6 | dir=out | app=system |
"{3FD89447-A0F3-43FA-B770-82E97C1675A5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{447C5FD2-CF1F-44DD-9F93-5D0E41788B55}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{49858B2A-6313-4980-A26B-2172B1C97F64}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5078DD9C-5619-408C-A8D8-643C5F0772EA}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{533E9B1F-100C-40D2-A4DB-2329E637935C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6634521E-59EB-47B3-BE2F-B4F8510EC863}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{6AFAF130-5E6D-441D-AC5A-129B81D9D5FC}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{6F6AEC64-4848-4B23-900D-5CE5BAD21AA8}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8923837A-6781-40BD-9704-AA525C7C912D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{96A7D7BF-AF7F-4522-8EEF-56157CE4C6E7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A2A66999-8D19-49B9-8390-A03C2688C70C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A3C58EFD-9B23-4182-A885-751295ADD6A8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AAA7E329-BC9E-4DBC-98FA-22CBFA84887C}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{ABFB9275-8FD7-497C-A160-1999A77E3AC7}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{B17A5E27-F080-49FF-99D6-9064C30E6AD7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{B3FC62A4-5833-4F39-9613-0AE04170ED7C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BCAE81D4-A649-4ACB-99E6-249CF10EA236}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{BECEA987-4C61-4D1C-ABC9-58C5E790EF3D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C2AAEC63-DE5A-4AB7-8CC6-F0A17C8F486B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{C2F34CC0-921E-4DBE-87B2-04D3066E4A1C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CBABD266-0854-4D0E-9319-69D2F6BA8418}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{CEDD061E-06CE-4C33-994F-F91512B38937}" = protocol=6 | dir=in | app=c:\users\matt\appdata\roaming\utorrent\utorrent.exe |
"{E2193580-B8C1-4771-A726-E21F72BC4BAF}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EADA453D-6BC6-4431-96C8-E0048E1A45BA}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F35DBFB8-E2C9-4CE7-A634-1A0468F6E60A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{21EE3C26-D703-48F9-A9F5-0FD8F836644A}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"UDP Query User{E2E22E6B-0D06-45F1-BFFF-EACC8105D2CA}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9AF0B106-56F1-461B-A270-95BC1682E282}" = Broadcom Gigabit NetLink Controller
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway PowerSave Solution
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2437C5C-2D8C-40D2-8059-689AD7239FA3}" = Intel® C++ Redistributables for Windows* on Intel® 64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG Secure Search" = AVG Security Toolbar
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"Browser Defender_is1" = Browser Guard 4.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Companion Plugin" = Coupon Companion Plugin
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"Gateway Screensaver" = Gateway ScreenSaver
"Google Chrome" = Google Chrome
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Gateway MyBackup
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 18.0.2 (x86 en-US)" = Mozilla Firefox 18.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.SingleImage" = Microsoft Office Professional 2010
"PowerISO" = PowerISO
"PS3 Media Server" = PS3 Media Server
"Spyware Doctor" = PC Tools Spyware Doctor 9.1
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.3
"VLC Setup Helper_is1" = VLC Setup Helper
"WinLiveSuite" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1026007817-671561051-2026392895-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Ccleaner Business Edition x64 x86 Tom_Da_Man" = Ccleaner Business Edition x64 x86 Tom_Da_Man
"VisualBee for Microsoft PowerPoint" = VisualBee for Microsoft PowerPoint

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/13/2013 12:22:22 PM | Computer Name = Matt-PC | Source = WinMgmt | ID = 10
Description =

Error - 2/13/2013 12:22:50 PM | Computer Name = Matt-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Faulting module name: ePowerTray.exe, version: 4.1.3006.0, time
stamp: 0x49b6ac1c Exception code: 0xc0000005 Fault offset: 0x0000000000012745 Faulting
process id: 0xb50 Faulting application start time: 0x01ce0a0657059120 Faulting application
path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe Faulting
module path: C:\Program Files\Gateway\Gateway PowerSave Solution\ePowerTray.exe
Report
Id: 9c0a9b19-75f9-11e2-b6e0-001f16ab50fb

[ System Events ]
Error - 2/13/2013 12:20:47 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 2/13/2013 12:22:10 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D;
2 Scanner Service service to connect.

Error - 2/13/2013 12:22:10 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7000
Description = The Spybot-S&D; 2 Scanner Service service failed to start due to the
following error: %%1053

Error - 2/13/2013 12:22:14 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D;
2 Updating Service service to connect.

Error - 2/13/2013 12:22:14 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7000
Description = The Spybot-S&D; 2 Updating Service service failed to start due to the
following error: %%1053

Error - 2/13/2013 12:22:19 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCTSD

Error - 2/13/2013 12:32:04 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7003
Description = The PC Tools Browser Defender Driver service depends the following
service: PCTCore. This service might not be installed.

Error - 2/13/2013 12:32:34 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7003
Description = The PC Tools Browser Defender Driver service depends the following
service: PCTCore. This service might not be installed.

Error - 2/13/2013 12:33:05 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7003
Description = The PC Tools Browser Defender Driver service depends the following
service: PCTCore. This service might not be installed.

Error - 2/13/2013 12:33:35 PM | Computer Name = Matt-PC | Source = Service Control Manager | ID = 7003
Description = The PC Tools Browser Defender Driver service depends the following
service: PCTCore. This service might not be installed.


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI