This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

WinZip Registry Optimizer [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone, I'm Cody.

Recently I've been having issues with my computer. Specifically one program, WinZip Regristry Optimizer.
I start up my PC, wait for everything to load, and then WinZip pops up and tells me that I have "X" amount of registry errors.
So the issue is that I CANNOT uninstall this program like normal via the Control Panel. Any advice/help would be greatly appreciated!

Here is the OTL:

OTL logfile created on: 3/17/2013 10:59:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\CodyKari\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.55 Gb Available Physical Memory | 81.88% Memory free
16.00 Gb Paging File | 14.48 Gb Available in Paging File | 90.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 205.68 Gb Free Space | 44.17% Space Free | Partition Type: NTFS
Drive D: | 108.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 9.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: CODYKARI-PC | User Name: CodyKari | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\CodyKari\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
PRC - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Windows\SysWOW64\schtasks.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\HD-Agent\b9c9ca061272e3efd2433fcf08555967\HD-Agent.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\JSON\238bcb309ef3ed9c743e18565fde3d4c\JSON.ni.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe ()
MOD - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
MOD - C:\Program Files (x86)\Steam\sdl.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e71959f4ec6eb386889050ac139835c7\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (TeamViewer8) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (BstHdLogRotatorSvc) – C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
SRV - (BstHdAndroidSvc) – C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
SRV - (BrowserProtect) – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe ()
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (IHA_MessageCenter) – C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mcaudrv_simple) – C:\Windows\SysNative\drivers\mcaudrv_x64.sys (ManyCam LLC)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (ManyCam) – C:\Windows\SysNative\drivers\mcvidrv_x64.sys (ManyCam LLC)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (BstHdDrv) – C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys (BlueStack Systems)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3220468
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT3220468
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 81 C9 0D 77 D9 F3 CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…000bcaec51a56c8
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.bing.com/search?FORM=UP22DF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{F7C16FAF-7949-4A90-840A-4FEE28CCD0EC}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{58bd07eb-0ee0-4df0-8121-dc9b693373df}: C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension [2013/01/28 00:35:40 | 000,000,000 | —D | M]

[2013/01/24 06:56:42 | 000,000,000 | —D | M] (No name found) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions
[2013/01/24 06:56:43 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2013/01/28 00:35:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://search.babylon.com/?affID=117023&am;…000bcaec51a56c8
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - Extension: Turn Off the Lights = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.1.0.30_0\
CHR - Extension: YouTube = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: Google Search = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: TinEye Reverse Image Search = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.2_0\
CHR - Extension: BrowserProtect = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0\
CHR - Extension: Gmail = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4D594333-0076-A76A-76A7-7A786E7484D7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Spybot-S&D Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C4B02A1-85B3-49F9-9A94-E6340C7FC35A}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/03/15 17:58:00 | 000,000,027 | R— | M] () - D:\Autorun.inf – [ UDF ]
O32 - AutoRun File - [2013/03/04 19:43:48 | 000,000,057 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell - "" = AutoRun
O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell\AutoRun\command - "" = E:\Setup.exe – [2013/03/04 19:43:48 | 001,013,399 | R— | M] (SQUARE ENIX )
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/03/17 22:58:01 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe
[2013/03/17 18:54:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon
[2013/03/17 00:05:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
[2013/03/17 00:05:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\BlueStacks
[2013/03/17 00:04:44 | 000,000,000 | —D | C] – C:\ProgramData\BlueStacksSetup
[2013/03/17 00:04:43 | 000,000,000 | —D | C] – C:\ProgramData\BlueStacks
[2013/03/15 03:08:31 | 000,000,000 | —D | C] – C:\Users\CodyKari\Documents\Diablo III
[2013/03/15 02:51:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
[2013/03/15 02:51:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Diablo III
[2013/03/15 02:47:04 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Audacity
[2013/03/15 02:43:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/03/10 22:05:42 | 000,741,480 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\HPDiscoPM9311.dll
[2013/03/10 22:05:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\Program Files\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\HP
[2013/03/10 22:05:08 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\HP
[2013/03/10 20:17:11 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Adobe
[2013/03/10 20:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2013/03/10 20:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2013/03/09 01:15:30 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\SKIDROW
[2013/03/09 01:00:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX
[2013/03/09 00:53:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\SQUARE ENIX
[2013/03/08 21:15:31 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\vlc
[2013/03/08 21:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/03/08 21:15:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2013/03/08 19:04:08 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/08 19:04:03 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/08 19:04:03 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/08 19:04:03 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/08 19:03:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/03/08 18:00:45 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Verizon
[2013/03/08 18:00:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon Media Manager
[2013/03/08 18:00:31 | 000,000,000 | —D | C] – C:\ProgramData\Verizon
[2013/03/06 05:30:18 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\SCE
[2013/03/06 05:29:57 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/03/02 00:47:17 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Malwarebytes
[2013/03/02 00:47:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/02 00:47:09 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/03/02 00:47:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/03/02 00:47:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/03/02 00:32:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2013/02/28 16:51:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TortoiseSVN
[2013/02/21 05:15:34 | 001,085,344 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013/02/21 05:15:34 | 000,963,488 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/02/21 05:15:34 | 000,310,688 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/02/21 05:15:31 | 000,188,832 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/02/21 05:15:31 | 000,188,320 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/02/21 05:15:31 | 000,108,448 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013/02/21 05:15:22 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/02/21 04:57:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ask.com
[2013/02/20 06:39:23 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/02/20 06:39:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/02/20 06:39:00 | 000,017,272 | —- | C] (Safer Networking Limited) – C:\Windows\SysNative\sdnclean64.exe
[2013/02/20 06:38:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/02/20 06:38:26 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Programs
[2013/02/20 04:19:25 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\CrashRpt
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Producer
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Livestream for Producers
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Livestream for Producers
[2013/02/20 04:03:44 | 000,000,000 | —D | C] – C:\ProgramData\APN
[2013/02/20 04:03:19 | 000,044,928 | —- | C] (ManyCam LLC) – C:\Windows\SysNative\drivers\mcvidrv_x64.sys
[2013/02/20 04:03:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\ManyCam
[2013/02/19 04:36:23 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2013/02/19 04:34:53 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sierra
[2013/02/19 04:34:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2013/02/19 04:30:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sierra
[2013/02/19 04:29:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2013/02/19 04:28:07 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\LogMeIn Hamachi
[2013/02/19 04:27:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013/02/19 04:27:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2013/02/19 00:48:48 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Diagnostics
[2013/02/19 00:47:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Verizon
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/03/17 22:58:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe
[2013/03/17 22:55:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/17 22:48:18 | 000,781,298 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/17 22:48:18 | 000,661,656 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/17 22:48:18 | 000,121,524 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/17 22:48:06 | 000,010,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/17 22:48:06 | 000,010,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/17 22:42:10 | 000,001,956 | —- | M] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series.lnk
[2013/03/17 22:42:02 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/17 22:41:47 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/17 22:41:45 | 2146,836,479 | -HS- | M] () – C:\hiberfil.sys
[2013/03/17 19:25:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/17 15:02:14 | 000,000,302 | —- | M] () – C:\Windows\tasks\Registry Optimizer_DEFAULT.job
[2013/03/15 17:46:59 | 000,069,429 | —- | M] () – C:\Users\CodyKari\Documents\https___myaccountportal.sprint.com_servlet_ecare_inf_template=_include_prin
t_page.jsp&inf_current_template=_billing_pay_bill_debit_success_body.pdf
[2013/03/15 02:39:04 | 000,000,106 | —- | M] () – C:\Windows\VaultMediaClient.INI
[2013/03/13 17:44:02 | 000,178,457 | —- | M] () – C:\Users\CodyKari\Documents\Walmart blinds (4).pdf
[2013/03/13 10:55:09 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/13 10:55:09 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/10 22:05:12 | 000,000,057 | —- | M] () – C:\ProgramData\Ament.ini
[2013/03/08 19:03:55 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/08 19:03:54 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/03/08 19:03:54 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/03/08 19:03:54 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/08 19:03:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/08 19:03:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/08 18:01:00 | 000,003,584 | —- | M] () – C:\Users\CodyKari\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/06 03:56:12 | 000,000,310 | —- | M] () – C:\Windows\tasks\Registry Optimizer_UPDATES.job
[2013/02/28 15:21:43 | 000,062,987 | —- | M] () – C:\Users\CodyKari\Documents\Verizon 2-28-2013.pdf
[2013/02/28 15:18:51 | 000,142,242 | —- | M] () – C:\Users\CodyKari\Documents\sprint bill 2-28-2013.pdf
[2013/02/21 05:15:23 | 001,085,344 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013/02/21 05:15:23 | 000,963,488 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/02/21 05:15:23 | 000,310,688 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/02/21 05:15:23 | 000,188,832 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/02/21 05:15:23 | 000,188,320 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/02/21 05:15:23 | 000,108,448 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013/02/19 04:12:25 | 000,091,894 | —- | M] () – C:\Users\CodyKari\Documents\Order Confirmation - Kohls.pdf
[2013/02/19 00:48:06 | 000,000,260 | —- | M] () – C:\Windows\SysWow64\cmdVBS.vbs
[2013/02/19 00:48:06 | 000,000,256 | —- | M] () – C:\Windows\SysWow64\MSIevent.bat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/03/15 17:46:59 | 000,069,429 | —- | C] () – C:\Users\CodyKari\Documents\https___myaccountportal.sprint.com_servlet_ecare_inf_template=_include_prin
t_page.jsp&inf_current_template=_billing_pay_bill_debit_success_body.pdf
[2013/03/15 02:43:17 | 000,001,023 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/03/13 17:44:02 | 000,178,457 | —- | C] () – C:\Users\CodyKari\Documents\Walmart blinds (4).pdf
[2013/03/10 22:06:38 | 000,001,956 | —- | C] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series.lnk
[2013/03/10 22:05:12 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/03/10 20:14:03 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/03/08 19:02:56 | 000,000,106 | —- | C] () – C:\Windows\VaultMediaClient.INI
[2013/03/08 18:01:00 | 000,003,584 | —- | C] () – C:\Users\CodyKari\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/28 15:21:43 | 000,062,987 | —- | C] () – C:\Users\CodyKari\Documents\Verizon 2-28-2013.pdf
[2013/02/28 15:18:51 | 000,142,242 | —- | C] () – C:\Users\CodyKari\Documents\sprint bill 2-28-2013.pdf
[2013/02/20 06:39:04 | 000,002,189 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/02/19 04:12:25 | 000,091,894 | —- | C] () – C:\Users\CodyKari\Documents\Order Confirmation - Kohls.pdf
[2013/02/19 00:48:06 | 000,000,260 | —- | C] () – C:\Windows\SysWow64\cmdVBS.vbs
[2013/02/19 00:48:06 | 000,000,256 | —- | C] () – C:\Windows\SysWow64\MSIevent.bat
[2013/01/27 23:40:44 | 000,703,117 | —- | C] () – C:\Users\CodyKari\AppData\Roaming\technic-launcher.jar
[2013/01/18 16:56:53 | 000,757,660 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2009/07/13 21:41:54 | 014,161,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2009/07/13 21:16:14 | 012,866,560 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/13 21:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/03/16 22:44:27 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\.minecraft
[2013/02/24 02:34:38 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\.techniclauncher
[2013/03/16 21:51:39 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Audacity
[2013/01/28 00:35:47 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\DAEMON Tools Lite
[2013/02/24 02:34:35 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\logs
[2013/02/13 01:33:22 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Nico Mak Computing
[2013/02/15 00:54:34 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Origin
[2013/02/06 20:37:26 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Subversion
[2013/03/17 22:44:16 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\TeamViewer
[2013/03/17 16:35:10 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\TS3Client
[2013/03/15 02:48:54 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\SysWOW64\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2012/11/13 18:07:52 | 003,906,584 | —- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 – C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/03/17 00:03:30 | 000,026,026 | —- | M] () MD5=DAF996406C2790F86C089561EEA054C4 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 15:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011/03/01 12:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\SysNative\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/03/17 22:41:45 | 2146,836,479 | -HS- | M] () – C:\hiberfil.sys
[2013/03/17 22:41:48 | 4294,107,135 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/01/16 07:05:55 | 000,000,221 | -HS- | M] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/03/17 22:58:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:82F50D1C

< End of report >
And the Extras log!

OTL Extras logfile created on: 3/17/2013 10:59:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\CodyKari\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.55 Gb Available Physical Memory | 81.88% Memory free
16.00 Gb Paging File | 14.48 Gb Available in Paging File | 90.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 205.68 Gb Free Space | 44.17% Space Free | Partition Type: NTFS
Drive D: | 108.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 9.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: CODYKARI-PC | User Name: CodyKari | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{057668A8-5ED6-448F-ACCC-A8F1D77DB3AA}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{115EA61B-E774-4172-B7E4-DAB988882AB8}" = lport=50000 | protocol=17 | dir=in | name=iha_messagecenter |
"{24329637-0F9D-4F60-AD1F-744520072622}" = lport=137 | protocol=17 | dir=in | app=system |
"{26698BA5-A198-40A7-8FED-A1AB285EF096}" = lport=10243 | protocol=6 | dir=in | app=system |
"{2B427832-2600-4E63-8970-329D66DEE3A9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{30ED5442-E825-4A57-A5C1-D9C8DA379236}" = rport=139 | protocol=6 | dir=out | app=system |
"{3528653F-44EE-4B14-8CCB-62EFD922B042}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3576777C-C721-4C8F-899D-A9175884CE3B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{44504804-FB69-46D4-936A-3B78AE4DF4E6}" = lport=50000 | protocol=17 | dir=in | name=iha_messagecenter |
"{474BE3C8-0472-4938-960C-C11B9CB5A72C}" = rport=138 | protocol=17 | dir=out | app=system |
"{48897849-8860-4601-87EA-4685EBF50ECC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4A46AA4D-B53F-49AA-98A2-87A3E620F25A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7728A2CE-EAF4-4747-8DFD-4A512E5FEB51}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{79B4264A-E8C0-45BE-8C96-556BC1BCFB2E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7B5ED844-0B94-44FC-92AA-3556F4AF745F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{9367716D-4C51-4A87-87F8-B282FCF4B872}" = lport=138 | protocol=17 | dir=in | app=system |
"{9C02AD47-91FA-4299-B8CB-9EDAEE380B30}" = lport=139 | protocol=6 | dir=in | app=system |
"{A2904B96-62CE-4FA8-BC0D-164861AAA42C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AE66E2C8-CDE4-41A2-BB13-E3DC93D35D86}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C3B576FB-F3C1-4749-AF7E-50A93F10652B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CEEDA402-B3C6-4EED-8EDB-296A74355AEB}" = rport=445 | protocol=6 | dir=out | app=system |
"{D0724656-21DB-4CC7-8CCE-57EF8FEBA87E}" = lport=445 | protocol=6 | dir=in | app=system |
"{DE7DE5F4-613E-4B51-B377-F3852F442401}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E50F437C-9786-4DB6-BCB7-58D5100F87F8}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FBB3FAFE-CB70-4C8F-B7F4-801219C30654}" = rport=137 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{016EED21-506C-4519-A95C-675E9BC051FF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{020DB8B1-ECA7-428A-9211-7C90C53E33C1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{0625B176-41E4-4895-9CFE-342C4DA73D6F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wizardry online\launchpad.exe |
"{0C7FD89D-3BDF-4CD4-8475-CB779C3CF092}" = dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicatorcom.exe |
"{12AF58F6-E721-4B69-932A-70CA18BA120D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{22B34A04-43C2-4C73-9548-CCB42AFA523F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{3122EC7B-43CD-45BF-B88A-229BCD4AC063}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{33C04D4D-1E3C-42C2-A7D1-E378664BA9C6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{398E252D-F1EF-4131-A65C-883CEF2DE681}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{3A29ABB4-2E45-42DB-8F0F-F7D3DCDBF238}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{3C3AB2E2-B0E2-4FB4-ADFB-FE10C882E9D5}" = dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"{3E42A037-3D7B-4D92-B892-0326AEF23DA8}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{3FA3C64E-9C71-43CE-83E6-11F42894EF11}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{48FC5680-CCED-41F4-AF4B-87C6B0367C1F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\numnumsthesupaskulk\garrysmod\hl2.exe |
"{4B6C0AA8-5457-40BC-827A-370205B7DFF3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{4E4D8580-1339-4A67-AC7E-7291AD635C67}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\dead space 3\deadspace3.exe |
"{50136174-AA3A-4994-B73F-4CB1BDCD7CBF}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{549D9F83-76B4-4B49-A8ED-A47A53132B59}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{55831A3B-3B8B-4ECE-8A50-D8D0471779A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{5ED86C66-0198-453D-86A5-606CC9D1BA3B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5F09A7BB-219D-44AD-9A17-82767B6722CA}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\dead space 3\deadspace3.exe |
"{625E63F7-63F0-40CD-AC7F-3DD9F14D97B5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{67ABADF0-3531-497E-80E3-4793DBDD1A66}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6DC57578-8846-4010-BF6B-6AED28FEDCA8}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{6DEDD8FC-5058-415F-B4E0-1D449F15E885}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{73913AB2-93B7-4856-8424-74FF23DA2884}" = protocol=6 | dir=out | app=system |
"{7C16AB99-6A09-49DD-A66B-78DD95490200}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D8EB9F3-E817-43C7-90A5-44EC55C9BC07}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{7FB38F87-76ED-4BCC-93C9-DAAECE7F1F85}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{831DFCE7-0CC4-4F8D-95A7-AA71B6913927}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{84E4B664-A049-4D53-B1B2-1E7D741EB244}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{85F8C02A-A6FF-4BE8-8003-F23549699CA4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{871B2A4C-1E66-4708-A128-CF5F28DBAC50}" = dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{875C6371-88DC-4D02-834C-A99D64A6F937}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{87670A94-6592-44DB-B5E1-2C6D8C5C2605}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{885BC2F4-65CA-449C-947C-E658E6B24F69}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wizardry online\launchpad.exe |
"{88F2AE22-8541-445A-99D2-4F86F3738EDE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8E5AE5E1-D04F-4DB2-9967-3BF610455262}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{928771E2-70B8-4319-9381-21CB9AA0B842}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{94012C3A-C83F-4346-9BB6-6630157ADA47}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{9474BF02-73C7-49E9-B8EA-E55F616A8067}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A1336362-BBCE-4C23-AC1A-FBE7295CA868}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A4D98C4E-EFD8-404B-B491-0234950DF1C9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A6BACFED-593C-4446-946F-ACBB23CD6AF5}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{ABFECE10-D92B-461D-92EB-B46A22EC676B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{AFA9B26C-894C-4675-B64A-7E29633C78E6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{B8170A87-9DAB-4896-84E3-25715F23DF2A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\numnumsthesupaskulk\garrysmod\hl2.exe |
"{BA8AD720-E18E-4885-BF9E-435EB1200EC0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{C081D51A-64FF-4E45-B275-745583BA57AB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C23650E9-957B-44EE-9D06-1BF060F18417}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{C2EA9986-39CF-43CD-8095-A0A78DD2440B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{C6724365-A101-4EE4-869B-3151EB930C5B}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{C70FD029-8F99-4070-A13F-4ECDC3D176E4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D25D9F27-6597-4284-AF18-CABE3F2F2838}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{D384A847-E4B6-4490-B19D-DFCE0C51B02D}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{D7526105-1874-4198-B3DD-F2FB2949B21F}" = protocol=58 | dir=in | app=system |
"{DDC5B6E8-C35E-4D7B-A7E3-4DD26BB9548C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E34523A5-2FA0-4C85-A45B-20161BBB5FFA}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{E4970424-80F6-4C7D-828B-4D34A64C5684}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F664D734-D2E4-4BCC-A6BF-92A0362D1324}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{FE6F3220-532F-4A93-843F-9991BFB21E0F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{00373A4E-7396-40A4-B755-9FDC4670E83F}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |
"TCP Query User{100A598C-C20A-4AC6-898F-E2013A224687}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"TCP Query User{2C71C104-39A4-41CA-8534-CAA733CEF793}C:\program files (x86)\spybot - search & destroy 2\sdfiles.exe" = protocol=6 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdfiles.exe |
"TCP Query User{664F1B7C-521E-42B3-957A-EE8AF2E5265D}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{891F0985-5CB3-4278-BF53-9CE100DE7D44}C:\program files (x86)\verizon\verizon media manager\release\verizon media manager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\verizon\verizon media manager\release\verizon media manager.exe |
"TCP Query User{A28F6289-E1D4-4A0F-A1CD-EB15D23E4827}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{B34632D1-CF17-43AD-8D73-7E4E62CA6286}C:\program files (x86)\heroes of newerth\hon.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of newerth\hon.exe |
"TCP Query User{DC780C45-3D37-432C-9D36-5DAB6EF979AD}C:\program files (x86)\ea games\need for speed most wanted\nfs13.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\need for speed most wanted\nfs13.exe |
"TCP Query User{EAF03EF0-F112-4996-90B0-EAE3F7945A26}C:\program files (x86)\steam\steamapps\numnumsthesupaskulk\garrysmod\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\numnumsthesupaskulk\garrysmod\hl2.exe |
"UDP Query User{6193A60F-AC03-47AC-83DD-7F3A830817D1}C:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"UDP Query User{A86710F4-5B48-428A-AF92-9F5D2FD8B334}C:\program files (x86)\steam\steamapps\numnumsthesupaskulk\garrysmod\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\numnumsthesupaskulk\garrysmod\hl2.exe |
"UDP Query User{A9B7BB48-DE5B-4773-9473-6409E2B62345}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{B818FA89-A5DE-4817-BB83-12250CA84297}C:\program files (x86)\heroes of newerth\hon.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of newerth\hon.exe |
"UDP Query User{BE544E26-92A1-4755-BCCC-AC504055ADCD}C:\program files (x86)\verizon\verizon media manager\release\verizon media manager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\verizon\verizon media manager\release\verizon media manager.exe |
"UDP Query User{C14460BD-E7B2-4917-A502-5EFB81D87930}C:\program files (x86)\ea games\need for speed most wanted\nfs13.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\need for speed most wanted\nfs13.exe |
"UDP Query User{C86F0747-30D5-495E-A9AC-FA47D2D43415}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{E15BB355-226D-4B46-8282-391F3BCFC17F}C:\program files (x86)\spybot - search & destroy 2\sdfiles.exe" = protocol=17 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdfiles.exe |
"UDP Query User{F38B6B66-BFC8-4883-9FD2-7D9A93D3431F}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417015FF}" = Java 7 Update 15 (64-bit)
"{6457BD83-98CF-4267-93D7-F173FF3E7C25}" = HP Deskjet 3050 J610 series Basic Device Software
"{6B13A3F1-F66A-42FB-9E62-98952D582187}" = TortoiseSVN 1.7.11.23600 (64 bit)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.18.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0F052922-4BCE-4763-A540-00857554336D}" = Redist
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = BrowserProtect
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{40D36ECF-FA05-4077-B836-C439CD0DDEF1}" = Vz In Home Agent
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{834265C4-CDF4-44D3-BD24-31531617EFB8}" = IHA_MessageCenter
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B531332-0D5D-4B3B-A22C-8330DEA695A7}" = LogMeIn Hamachi
"{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A5BB86DF-EE99-41EB-9446-B4623A725E2A}" = Livestream for Producers
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.02)
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{CD9D0827-A6D6-4E2C-B31E-23F01577E27B}" = BlueStacks Notification Center
"{D4329609-4102-4F8C-B83F-7FE024EEA314}" = Dead Space™ 3
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Audacity_is1" = Audacity 2.0.3
"BlueStacks App Player" = BlueStacks App Player
"DAEMON Tools Lite" = DAEMON Tools Lite
"Diablo III" = Diablo III
"Fraps" = Fraps (remove only)
"Google Chrome" = Google Chrome
"hon" = Heroes of Newerth
"InstallShield_{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Need for Speed Most Wanted_is1" = Need for Speed Most Wanted
"Origin" = Origin
"Steam App 221360" = Wizardry Online
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 440" = Team Fortress 2
"Steam App 49520" = Borderlands 2
"Steam App 570" = Dota 2
"Steam App 620" = Portal 2
"TeamViewer 8" = TeamViewer 8
"Tombraider_is1" = Tombraider
"uTorrent" = µTorrent
"uTorrentControl_v2 Toolbar" = uTorrentControl_v2 Toolbar
"Verizon Media Manager" = Verizon Media Manager
"VLC media player" = VLC media player 2.0.5
"WinZip Registry Optimizer_is1" = WinZip Registry Optimizer
"World of Warcraft" = World of Warcraft

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"TeamSpeak 3 Client" = TeamSpeak 3 Client

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/4/2013 3:54:44 AM | Computer Name = CodyKari-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7600.16385,
time stamp: 0x4a5bc9bb Faulting module name: ntdll.dll, version: 6.1.7600.16385,
time stamp: 0x4a5be02b Exception code: 0xc015000f Fault offset: 0x000000000006edda
Faulting
process id: 0x680 Faulting application start time: 0x01ce188a81042230 Faulting application
path: C:\Windows\Explorer.EXE Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: c6d0b7ad-84a0-11e2-af29-bcaec51a56c8

Error - 3/6/2013 5:33:59 AM | Computer Name = CodyKari-PC | Source = Application Error | ID = 1000
Description = Faulting application name: WizardryOnline.exe, version: 0.0.0.0, time
stamp: 0x512733a8 Faulting module name: WizardryOnline.exe, version: 0.0.0.0, time
stamp: 0x512733a8 Exception code: 0xc0000005 Fault offset: 0x0013cae1 Faulting process
id: 0x2c4 Faulting application start time: 0x01ce1a4db7d3da2c Faulting application
path: C:\Program Files (x86)\Steam\steamapps\common\Wizardry Online\WizardryOnline.exe
Faulting
module path: C:\Program Files (x86)\Steam\steamapps\common\Wizardry Online\WizardryOnline.exe
Report
Id: f8a2a804-8640-11e2-8d2f-bcaec51a56c8

Error - 3/13/2013 12:30:01 PM | Computer Name = CodyKari-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 3/13/2013 12:30:02 PM | Computer Name = CodyKari-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 3/13/2013 12:30:02 PM | Computer Name = CodyKari-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 3/13/2013 12:30:03 PM | Computer Name = CodyKari-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 3/13/2013 12:30:03 PM | Computer Name = CodyKari-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 3/13/2013 12:30:03 PM | Computer Name = CodyKari-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 3/13/2013 12:30:05 PM | Computer Name = CodyKari-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 3/16/2013 6:30:18 PM | Computer Name = CodyKari-PC | Source = Application Error | ID = 1000
Description = Faulting application name: hamachi-2.exe, version: 2.1.0.296, time
stamp: 0x50cafa9f Faulting module name: hamachi-2.exe, version: 2.1.0.296, time
stamp: 0x50cafa9f Exception code: 0xc0000005 Fault offset: 0x000000000014294b Faulting
process id: 0x774 Faulting application start time: 0x01ce20e437b40656 Faulting application
path: C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe Faulting module path:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe Report Id: 141a15a4-8e89-11e2-8f31-bcaec51a56c8

[ Spybot - Search and Destroy Events ]
Error - 2/20/2013 7:21:40 AM | Computer Name = CodyKari-PC | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions

[ System Events ]
Error - 3/14/2013 2:46:12 PM | Computer Name = CodyKari-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:33:21 PM on ?3/?14/?2013 was unexpected.

Error - 3/16/2013 6:30:18 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7034
Description = The LogMeIn Hamachi Tunneling Engine service terminated unexpectedly.
It has done this 1 time(s).

Error - 3/17/2013 2:41:20 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 3/17/2013 2:41:20 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 3/17/2013 10:41:59 PM | Computer Name = CodyKari-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 7:59:17 PM on ?3/?17/?2013 was unexpected.

Error - 3/17/2013 10:43:25 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7034
Description = The BingBar Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/17/2013 10:44:06 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7031
Description = The TeamViewer 8 service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 2000 milliseconds:
Restart the service.

Error - 3/17/2013 10:44:14 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7034
Description = The IHA_MessageCenter service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/17/2013 10:44:15 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7031
Description = The TeamViewer 8 service terminated unexpectedly. It has done this
2 time(s). The following corrective action will be taken in 2000 milliseconds:
Restart the service.

Error - 3/17/2013 10:44:25 PM | Computer Name = CodyKari-PC | Source = Service Control Manager | ID = 7034
Description = The TeamViewer 8 service terminated unexpectedly. It has done this
3 time(s).


< End of report >
Hello Codycctx and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your logs now and will reply with instructions shortly.

Satchfan
Hello again Codycctx

We do indeed have a bit of cleaning up to do here but with a bit of work on your part we should be able to sort it out. :)


Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.
Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.
Please post the contents of the RKreport.txt in your next reply.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
===================================================

Download and run Junkware Removal Tool

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.
Please also post a new OTL log.

Logs to include in the next post:

RKreport.txt
AdwCleaner log
JRT.txt
New OTL log


Thanks

Satchfan
RogueKiller Log:

RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User : CodyKari [Admin rights]
Mode : Scan – Date : 03/19/2013 22:31:26
| ARK || FAK || MBR |

¤¤¤ Bad processes : 4 ¤¤¤
[BLACKLIST] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[BLACKLIST] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]

¤¤¤ Registry Entries : 8 ¤¤¤
[Services][BLACKLIST] HKLM\[…]\ControlSet001\Services\BrowserProtect (C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [7] -> FOUND
[Services][BLACKLIST] HKLM\[…]\ControlSet002\Services\BrowserProtect (C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [7] -> FOUND
[HJ] HKLM\[…]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[…]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[…]\Wow6432Node\System : EnableLUA (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Hitachi HDP725050GLA360 ATA Device +++++
— User —
[MBR] b1a70560021fb85403f0260cc796389b
[BSP] 4585ca7477a9a5654f1071dc5b4ee50d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 476836 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1]_S_03192013_02d2231.txt >>
RKreport[1]_S_03192013_02d2231.txt

ADWCleaner log:

# AdwCleaner v2.115 - Logfile created 03/19/2013 at 22:32:25
# Updated 17/03/2013 by Xplode
# Operating system : Windows 7 Ultimate (64 bits)
# User : CodyKari - CODYKARI-PC
# Boot Mode : Normal
# Running from : C:\Users\CodyKari\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : BrowserProtect

***** [Files / Folders] *****

Deleted on reboot : C:\Program Files (x86)\Ask.com
Deleted on reboot : C:\Program Files (x86)\Conduit
Deleted on reboot : C:\Program Files (x86)\uTorrentControl_v2
Deleted on reboot : C:\ProgramData\APN
Deleted on reboot : C:\ProgramData\BrowserProtect
Deleted on reboot : C:\Users\CodyKari\AppData\Local\Conduit
Deleted on reboot : C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Deleted on reboot : C:\Users\CodyKari\AppData\Local\Temp\APN
Deleted on reboot : C:\Users\CodyKari\AppData\LocalLow\Conduit
Deleted on reboot : C:\Users\CodyKari\AppData\LocalLow\PriceGong
Deleted on reboot : C:\Users\CodyKari\AppData\LocalLow\uTorrentControl_v2
Deleted on reboot : C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserProtect
File Deleted : C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
File Deleted : C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences

***** [Registry] *****

Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKCU\Software\968dd9b13beb41
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\BabylonToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\b
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\Software\Classes\Installer\Products\6207E55EA2FE71A4AA7ABD89AEF31D1B
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\uTorrentControl_v2
Key Deleted : HKLM\SOFTWARE\Wow6432Node\968dd9b13beb41
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79B3E313-A1F5-4780-A669-7B34B3575D2D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8F7D794C-4B88-4123-A4B5-AD75680C612D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Key Deleted : HKU\S-1-5-21-1986973749-1006168639-1003531894-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKCU\Software\Mozilla\Firefox\extensions [{58BD07EB-0EE0-4DF0-8121-DC9B693373DF}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7600.16385

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid;=CT3220468 –> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=117023&babsrc;=NT_ss&mntrId;=b0c05770000000000000bcaec51a56c8 –> hxxp://www.google.com

-\\ Google Chrome v25.0.1364.172

File : C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.2089] : homepage = "hxxp://search.babylon.com/?affID=117023&babsrc;=HP_ss&mntrId;=b0c05770000000000000bcae[…]

*************************

AdwCleaner[S1].txt - [10288 octets] - [19/03/2013 22:32:25]

########## EOF - C:\AdwCleaner[S1].txt - [10349 octets] ##########

JRT log:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.7.2 (03.15.2013:1)
OS: Windows 7 Ultimate x64
Ran by [removed] on Tue 03/19/2013 at 22:39:34.35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\windows nt\currentversion\windows\\AppInit_DLLs



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_local_machine\software\babylontoolbar
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{97f2ff5b-260c-4ccf-834a-2dda4e29e39e}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{b8276a94-891d-453c-9ff3-715c042a2575}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Program Files (x86)\winzip registry optimizer"



~~~ Chrome

Successfully deleted: [Registry Key] hkey_local_machine\software\policies\google\chrome\extensioninstallforcelist
Successfully deleted: [Registry Key] hkey_current_user\software\google\chrome\extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ejpbbhjlbipncjklfjjaedaieimbmdda



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 03/19/2013 at 22:44:04.61
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

New OTL log:

OTL logfile created on: 3/19/2013 10:54:48 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\CodyKari\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 5.57 Gb Available Physical Memory | 69.67% Memory free
16.00 Gb Paging File | 13.47 Gb Available in Paging File | 84.19% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 203.43 Gb Free Space | 43.69% Space Free | Partition Type: NTFS
Drive D: | 108.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 9.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: CODYKARI-PC | User Name: CodyKari | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\CodyKari\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe (BlueStack Systems)
PRC - C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe (BlueStack Systems)
PRC - C:\Program Files (x86)\BlueStacks\HD-Network.exe (BlueStack Systems)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ffmpegsumo.dll ()
MOD - C:\Program Files\TortoiseSVN\bin\libsasl32.dll ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (TeamViewer8) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (BstHdLogRotatorSvc) – C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
SRV - (BstHdAndroidSvc) – C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (IHA_MessageCenter) – C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mcaudrv_simple) – C:\Windows\SysNative\drivers\mcaudrv_x64.sys (ManyCam LLC)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (ManyCam) – C:\Windows\SysNative\drivers\mcvidrv_x64.sys (ManyCam LLC)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (BstHdDrv) – C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys (BlueStack Systems)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 81 C9 0D 77 D9 F3 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{F7C16FAF-7949-4A90-840A-4FEE28CCD0EC}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.15.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2013/01/24 06:56:42 | 000,000,000 | —D | M] (No name found) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions
[2013/01/24 06:56:43 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2013/01/28 00:35:32 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://search.babylon.com/?affID=117023&am;…000bcaec51a56c8
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - Extension: Turn Off the Lights = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.1.0.30_0\
CHR - Extension: YouTube = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: Google Search = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: TinEye Reverse Image Search = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.2_0\
CHR - Extension: Gmail = C:\Users\CodyKari\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4D594333-0076-A76A-76A7-7A786E7484D7} - No CLSID value found.
O4 - HKLM..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Spybot-S&D; Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C4B02A1-85B3-49F9-9A94-E6340C7FC35A}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/03/15 17:58:00 | 000,000,027 | R— | M] () - D:\Autorun.inf – [ UDF ]
O32 - AutoRun File - [2013/03/04 19:43:48 | 000,000,057 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell - "" = AutoRun
O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell\AutoRun\command - "" = E:\Setup.exe – [2013/03/04 19:43:48 | 001,013,399 | R— | M] (SQUARE ENIX )
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/03/19 22:43:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon
[2013/03/19 22:39:32 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/03/19 22:39:27 | 000,000,000 | —D | C] – C:\JRT
[2013/03/19 22:37:44 | 000,549,920 | —- | C] (Oleg N. Scherbakov) – C:\Users\CodyKari\Desktop\JRT (1).exe
[2013/03/19 22:29:32 | 000,000,000 | —D | C] – C:\Users\CodyKari\Desktop\RK_Quarantine
[2013/03/17 22:58:01 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe
[2013/03/17 00:05:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
[2013/03/17 00:05:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\BlueStacks
[2013/03/17 00:04:44 | 000,000,000 | —D | C] – C:\ProgramData\BlueStacksSetup
[2013/03/17 00:04:43 | 000,000,000 | —D | C] – C:\ProgramData\BlueStacks
[2013/03/15 03:08:31 | 000,000,000 | —D | C] – C:\Users\CodyKari\Documents\Diablo III
[2013/03/15 02:51:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
[2013/03/15 02:51:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Diablo III
[2013/03/15 02:47:04 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Audacity
[2013/03/15 02:43:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/03/10 22:05:42 | 000,741,480 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\HPDiscoPM9311.dll
[2013/03/10 22:05:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\Program Files\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\HP
[2013/03/10 22:05:08 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\HP
[2013/03/10 20:17:11 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Adobe
[2013/03/10 20:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2013/03/10 20:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2013/03/09 01:15:30 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\SKIDROW
[2013/03/09 01:00:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX
[2013/03/09 00:53:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\SQUARE ENIX
[2013/03/08 21:15:31 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\vlc
[2013/03/08 21:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/03/08 21:15:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2013/03/08 19:04:08 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/08 19:04:03 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/08 19:04:03 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/08 19:04:03 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/08 19:03:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/03/08 18:00:45 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Verizon
[2013/03/08 18:00:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon Media Manager
[2013/03/08 18:00:31 | 000,000,000 | —D | C] – C:\ProgramData\Verizon
[2013/03/06 05:30:18 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\SCE
[2013/03/06 05:29:57 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/03/02 00:47:17 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Malwarebytes
[2013/03/02 00:47:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/02 00:47:09 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/03/02 00:47:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/03/02 00:47:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/03/02 00:32:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2013/02/28 16:51:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TortoiseSVN
[2013/02/21 05:15:34 | 001,085,344 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013/02/21 05:15:34 | 000,963,488 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/02/21 05:15:34 | 000,310,688 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/02/21 05:15:31 | 000,188,832 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/02/21 05:15:31 | 000,188,320 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/02/21 05:15:31 | 000,108,448 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013/02/21 05:15:22 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/02/20 06:39:23 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/02/20 06:39:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/02/20 06:39:00 | 000,017,272 | —- | C] (Safer Networking Limited) – C:\Windows\SysNative\sdnclean64.exe
[2013/02/20 06:38:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/02/20 06:38:26 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Programs
[2013/02/20 04:19:25 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\CrashRpt
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Producer
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Livestream for Producers
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Livestream for Producers
[2013/02/20 04:03:19 | 000,044,928 | —- | C] (ManyCam LLC) – C:\Windows\SysNative\drivers\mcvidrv_x64.sys
[2013/02/20 04:03:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\ManyCam
[2013/02/19 04:36:23 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2013/02/19 04:34:53 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sierra
[2013/02/19 04:34:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2013/02/19 04:30:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sierra
[2013/02/19 04:29:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2013/02/19 04:28:07 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\LogMeIn Hamachi
[2013/02/19 04:27:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013/02/19 04:27:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2013/02/19 00:48:48 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Diagnostics
[2013/02/19 00:47:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Verizon
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/03/19 22:55:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/19 22:40:00 | 000,781,298 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/19 22:40:00 | 000,661,656 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/19 22:40:00 | 000,121,524 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/19 22:39:03 | 000,010,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/19 22:39:03 | 000,010,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/19 22:37:50 | 000,549,920 | —- | M] (Oleg N. Scherbakov) – C:\Users\CodyKari\Desktop\JRT (1).exe
[2013/03/19 22:35:39 | 000,001,956 | —- | M] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series.lnk
[2013/03/19 22:33:52 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/19 22:33:38 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/19 22:33:36 | 2146,836,479 | -HS- | M] () – C:\hiberfil.sys
[2013/03/19 22:32:11 | 000,609,993 | —- | M] () – C:\Users\CodyKari\Desktop\adwcleaner.exe
[2013/03/19 22:28:19 | 000,791,040 | —- | M] () – C:\Users\CodyKari\Desktop\RogueKillerX64.exe
[2013/03/19 22:25:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/19 21:05:19 | 000,000,302 | —- | M] () – C:\Windows\tasks\Registry Optimizer_DEFAULT.job
[2013/03/17 22:58:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe
[2013/03/15 17:46:59 | 000,069,429 | —- | M] () – C:\Users\CodyKari\Documents\https___myaccountportal.sprint.com_servlet_ecare_inf_template=_include_prin
t_page.jsp&inf;_current_template=_billing_pay_bill_debit_success_body.pdf
[2013/03/15 02:39:04 | 000,000,106 | —- | M] () – C:\Windows\VaultMediaClient.INI
[2013/03/13 17:44:02 | 000,178,457 | —- | M] () – C:\Users\CodyKari\Documents\Walmart blinds (4).pdf
[2013/03/13 10:55:09 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/13 10:55:09 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/10 22:05:12 | 000,000,057 | —- | M] () – C:\ProgramData\Ament.ini
[2013/03/08 19:03:55 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/08 19:03:54 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/03/08 19:03:54 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/03/08 19:03:54 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/08 19:03:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/08 19:03:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/08 18:01:00 | 000,003,584 | —- | M] () – C:\Users\CodyKari\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/06 03:56:12 | 000,000,310 | —- | M] () – C:\Windows\tasks\Registry Optimizer_UPDATES.job
[2013/02/28 15:21:43 | 000,062,987 | —- | M] () – C:\Users\CodyKari\Documents\Verizon 2-28-2013.pdf
[2013/02/28 15:18:51 | 000,142,242 | —- | M] () – C:\Users\CodyKari\Documents\sprint bill 2-28-2013.pdf
[2013/02/21 05:15:23 | 001,085,344 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013/02/21 05:15:23 | 000,963,488 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/02/21 05:15:23 | 000,310,688 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2013/02/21 05:15:23 | 000,188,832 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2013/02/21 05:15:23 | 000,188,320 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2013/02/21 05:15:23 | 000,108,448 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2013/02/19 04:12:25 | 000,091,894 | —- | M] () – C:\Users\CodyKari\Documents\Order Confirmation - Kohls.pdf
[2013/02/19 00:48:06 | 000,000,260 | —- | M] () – C:\Windows\SysWow64\cmdVBS.vbs
[2013/02/19 00:48:06 | 000,000,256 | —- | M] () – C:\Windows\SysWow64\MSIevent.bat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/03/19 22:32:06 | 000,609,993 | —- | C] () – C:\Users\CodyKari\Desktop\adwcleaner.exe
[2013/03/19 22:28:18 | 000,791,040 | —- | C] () – C:\Users\CodyKari\Desktop\RogueKillerX64.exe
[2013/03/15 17:46:59 | 000,069,429 | —- | C] () – C:\Users\CodyKari\Documents\https___myaccountportal.sprint.com_servlet_ecare_inf_template=_include_prin
t_page.jsp&inf;_current_template=_billing_pay_bill_debit_success_body.pdf
[2013/03/15 02:43:17 | 000,001,023 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/03/13 17:44:02 | 000,178,457 | —- | C] () – C:\Users\CodyKari\Documents\Walmart blinds (4).pdf
[2013/03/10 22:06:38 | 000,001,956 | —- | C] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series.lnk
[2013/03/10 22:05:12 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/03/10 20:14:03 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/03/08 19:02:56 | 000,000,106 | —- | C] () – C:\Windows\VaultMediaClient.INI
[2013/03/08 18:01:00 | 000,003,584 | —- | C] () – C:\Users\CodyKari\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/28 15:21:43 | 000,062,987 | —- | C] () – C:\Users\CodyKari\Documents\Verizon 2-28-2013.pdf
[2013/02/28 15:18:51 | 000,142,242 | —- | C] () – C:\Users\CodyKari\Documents\sprint bill 2-28-2013.pdf
[2013/02/20 06:39:04 | 000,002,189 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
[2013/02/19 04:12:25 | 000,091,894 | —- | C] () – C:\Users\CodyKari\Documents\Order Confirmation - Kohls.pdf
[2013/02/19 00:48:06 | 000,000,260 | —- | C] () – C:\Windows\SysWow64\cmdVBS.vbs
[2013/02/19 00:48:06 | 000,000,256 | —- | C] () – C:\Windows\SysWow64\MSIevent.bat
[2013/01/27 23:40:44 | 000,703,117 | —- | C] () – C:\Users\CodyKari\AppData\Roaming\technic-launcher.jar
[2013/01/18 16:56:53 | 000,757,660 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2009/07/13 21:41:54 | 014,161,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2009/07/13 21:16:14 | 012,866,560 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/13 21:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/03/16 23:56:47 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\.minecraft
[2013/02/24 02:34:38 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\.techniclauncher
[2013/03/16 21:51:39 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Audacity
[2013/01/28 00:35:47 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\DAEMON Tools Lite
[2013/02/24 02:34:35 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\logs
[2013/02/13 01:33:22 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Nico Mak Computing
[2013/02/15 00:54:34 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Origin
[2013/02/06 20:37:26 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Subversion
[2013/03/17 22:44:16 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\TeamViewer
[2013/03/19 08:06:30 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\TS3Client
[2013/03/15 02:48:54 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\SysWOW64\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2012/11/13 18:07:52 | 003,906,584 | —- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 – C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/03/19 22:41:08 | 000,128,346 | —- | M] () MD5=98D786B3B452746F555C68AC572E1938 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.BAT >
[2013/01/04 16:58:30 | 000,031,067 | —- | M] () MD5=709A62B22C7BA09D875F765341E0FFFC – C:\JRT\iexplore.bat

< MD5 for: IEXPLORE.EXE >
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 15:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.DAT >
[2013/02/12 17:45:04 | 000,001,529 | —- | M] () MD5=E8685F466FABD90B42D32D7898417207 – C:\JRT\services.dat

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011/03/01 12:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\SysNative\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/03/19 22:33:36 | 2146,836,479 | -HS- | M] () – C:\hiberfil.sys
[2013/03/19 22:33:38 | 4294,107,135 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/01/16 07:05:55 | 000,000,221 | -HS- | M] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/03/19 22:32:11 | 000,609,993 | —- | M] () – C:\Users\CodyKari\Desktop\adwcleaner.exe
[2013/03/19 22:37:50 | 000,549,920 | —- | M] (Oleg N. Scherbakov) – C:\Users\CodyKari\Desktop\JRT (1).exe
[2013/03/17 22:58:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe
[2013/03/19 22:28:19 | 000,791,040 | —- | M] () – C:\Users\CodyKari\Desktop\RogueKillerX64.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:82F50D1C

< End of report >


Thank you for taking the time to help me with my computer problems!

Thank you for taking the time to help me with my computer problems!

You're welcome. :)

You have brought this situation on yourself I’m afraid.

Observations:
  • you have no antivirus installed
  • you have Spybot Search & Destroy v2 installed which is still being tested and has no real-time spyware protection
  • you have installed uTorrent which has also installed a “rogue” program on your computer.
We’ll work through this but I suggest that you don’t use the Internet unless it is to download the programs that I suggest.

When we are finished I’ll advise you of good free antivirus programs that you can choose from.


P2P – As I mentioned, I see you have (uTorrent) installed on your machine.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don'’t use it until we have finished up here.

===================================================

Uninstall the following programs, if present:

WinZip Registry Optimizer
Java 7 Update 15 (64-bit)
which is out-of-date1. Click Start, Control Panel, Programs, and then Programs and Features.
2. Click on WinZip Registry Optimizer and then Uninstall.

Repeat this for Java 7 Update (64-bit) .

If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

===================================================

Uninstall Google Chrome

For the time being I would like for you to uninstall Google Chrome and only use Firefox or Internet Explorer. You can reinstall it later if you like. We need to remove some entries and that is the easiest way to do so with Google Chrome.

If asked about user data or settings, don’t check the box that asks to remember settings. We need to remove those also.

====================================================

Run RogueKiller

Please do another scan with RogueKiller.

When it shows the results, under the “Processes” tab, check all the boxes next to these:

[BLACKLIST] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[BLACKLIST] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]
[RESIDUE] BrowserProtect.exe – C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [7] -> KILLED [TermProc]


Click on the “Registry” tab, make sure these are checked:

[Services][BLACKLIST] HKLM\[…]\ControlSet001\Services\BrowserProtect (C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [7] -> FOUND
[Services][BLACKLIST] HKLM\[…]\ControlSet002\Services\BrowserProtect (C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [7] -> FOUND


Press the Delete button and post the log it produces.

====================================================

Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\..\SearchScopes\{F7C16FAF-7949-4A90-840A-4FEE28CCD0EC}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
    [2013/01/24 06:56:43 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
    CHR - homepage: http://search.babylon.com/?affID=117023&am…000bcaec51a56c8
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4D594333-0076-A76A-76A7-7A786E7484D7} - No CLSID value found
    O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
    O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell\AutoRun\command - "" = E:\Setup.exe – [2013/03/04 19:43:48 | 001,013,399 | R— | M] (SQUARE ENIX )
    [2013/03/19 21:05:19 | 000,000,302 | —- | M] () – C:\Windows\tasks\Registry Optimizer_DEFAULT.job
    [2013/03/06 03:56:12 | 000,000,310 | —- | M] () – C:\Windows\tasks\Registry Optimizer_UPDATES.job
    [2013/03/15 02:48:54 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\uTorrent
    @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:82F50D1C
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log and new OTL log.
Logs to include in the next post:

RogueKiller report
OTL fix log
New OTL log


Thanks

Satchfan
I uninstalled said programs, along with the Peer-to-Peer program. However, when I ran RogueKiller, there were no entries under the tab "processes" and nothing similar in the "registry" tab.
Maybe I am just not understanding the directions/program.

RogueKiller Registry tab:
[external image: Posted Image]
New OTL log:

OTL logfile created on: 3/20/2013 10:17:48 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\CodyKari\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.14 Gb Available Physical Memory | 76.81% Memory free
16.00 Gb Paging File | 13.78 Gb Available in Paging File | 86.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 196.16 Gb Free Space | 42.12% Space Free | Partition Type: NTFS
Drive D: | 108.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 9.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: CODYKARI-PC | User Name: CodyKari | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\CodyKari\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\TechSmith\Snagit 11\SnagPriv.exe (TechSmith Corporation)
PRC - C:\Program Files (x86)\TechSmith\Snagit 11\SnagitEditor.exe (TechSmith Corporation)
PRC - C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe (TechSmith Corporation)
PRC - C:\Program Files (x86)\TechSmith\Snagit 11\TscHelp.exe (TechSmith Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\sdl2.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\cc4d9093563dadee370788bbc3ecf4fb\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\22ae167d586450ad3a9b9a9ee43ebc86\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\72269ea7cc6281139e4d155e7c57dc67\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\e7d92730b571b31e62c2cf257f04a974\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\97e6b67983d07a066b68b3ae8be2f53d\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b52bc540630c3aa5de542c382af35c20\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\cd235caf797fb017f140016be88f33b7\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\b9f7adbc90a2bcbe8eb9e6e8d2bb975b\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\e40da7a49f8c3f0108e7c835b342f382\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\51e2934144ba15628ba5a31be2dae7dc\mscorlib.ni.dll ()
MOD - C:\Program Files\TortoiseSVN\bin\libsasl32.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files (x86)\TechSmith\Snagit 11\PDFNetC.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (TeamViewer8) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (IHA_MessageCenter) – C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mcaudrv_simple) – C:\Windows\SysNative\drivers\mcaudrv_x64.sys (ManyCam LLC)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (ManyCam) – C:\Windows\SysNative\drivers\mcvidrv_x64.sys (ManyCam LLC)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 81 C9 0D 77 D9 F3 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {F7C16FAF-7949-4A90-840A-4FEE28CCD0EC}
IE - HKCU\..\SearchScopes\{F7C16FAF-7949-4A90-840A-4FEE28CCD0EC}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B582195F5-92E7-40a0-A127-DB71295901D7%7D:0.6.4.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/20 11:00:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/03/20 11:00:41 | 000,000,000 | —D | M] (No name found) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Extensions
[2013/01/24 06:56:42 | 000,000,000 | —D | M] (No name found) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions
[2013/01/24 06:56:43 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2013/03/20 16:28:51 | 000,000,000 | —D | M] (No name found) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\Profiles\byb8nn66.default\extensions
[2013/03/20 16:28:51 | 000,242,709 | —- | M] () (No name found) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\Profiles\byb8nn66.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}.xpi
[2013/03/20 11:00:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/07 10:31:00 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/03/07 10:30:20 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/07 10:30:20 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4D594333-0076-A76A-76A7-7A786E7484D7} - No CLSID value found.
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Spybot-S&D Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C4B02A1-85B3-49F9-9A94-E6340C7FC35A}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/03/15 17:58:00 | 000,000,027 | R— | M] () - D:\Autorun.inf – [ UDF ]
O32 - AutoRun File - [2013/03/04 19:43:48 | 000,000,057 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell - "" = AutoRun
O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell\AutoRun\command - "" = E:\Setup.exe – [2013/03/04 19:43:48 | 001,013,399 | R— | M] (SQUARE ENIX )
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/03/20 20:57:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon
[2013/03/20 17:32:03 | 000,000,000 | —D | C] – C:\Users\CodyKari\Desktop\Under the Ocean
[2013/03/20 16:33:36 | 000,000,000 | —D | C] – C:\Users\CodyKari\Documents\Under the Ocean Alpha 4
[2013/03/20 13:02:41 | 000,000,000 | —D | C] – C:\Users\CodyKari\Documents\Snagit
[2013/03/20 13:02:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
[2013/03/20 13:02:03 | 000,000,000 | —D | C] – C:\ProgramData\TechSmith
[2013/03/20 13:01:57 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\TechSmith
[2013/03/20 13:01:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\TechSmith
[2013/03/20 11:12:11 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Macromedia
[2013/03/20 11:00:37 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Mozilla
[2013/03/20 11:00:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/03/20 11:00:31 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/03/19 22:39:32 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/03/19 22:39:27 | 000,000,000 | —D | C] – C:\JRT
[2013/03/19 22:37:44 | 000,549,920 | —- | C] (Oleg N. Scherbakov) – C:\Users\CodyKari\Desktop\JRT (1).exe
[2013/03/19 22:29:32 | 000,000,000 | —D | C] – C:\Users\CodyKari\Desktop\RK_Quarantine
[2013/03/17 22:58:01 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe
[2013/03/17 00:04:44 | 000,000,000 | —D | C] – C:\ProgramData\BlueStacksSetup
[2013/03/15 03:08:31 | 000,000,000 | —D | C] – C:\Users\CodyKari\Documents\Diablo III
[2013/03/15 02:51:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
[2013/03/15 02:51:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Diablo III
[2013/03/15 02:47:04 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Audacity
[2013/03/15 02:43:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Audacity
[2013/03/10 22:05:42 | 000,741,480 | —- | C] (Hewlett-Packard Co.) – C:\Windows\SysNative\HPDiscoPM9311.dll
[2013/03/10 22:05:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\Program Files\HP
[2013/03/10 22:05:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\HP
[2013/03/10 22:05:08 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\HP
[2013/03/10 20:17:11 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Adobe
[2013/03/10 20:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2013/03/10 20:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2013/03/09 01:15:30 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\SKIDROW
[2013/03/09 01:00:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX
[2013/03/09 00:53:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\SQUARE ENIX
[2013/03/08 21:15:31 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\vlc
[2013/03/08 21:15:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/03/08 21:15:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2013/03/08 19:04:08 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/08 19:04:03 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/08 19:04:03 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/08 19:04:03 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/08 19:03:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/03/08 18:00:45 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Verizon
[2013/03/08 18:00:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon Media Manager
[2013/03/08 18:00:31 | 000,000,000 | —D | C] – C:\ProgramData\Verizon
[2013/03/06 05:30:18 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\SCE
[2013/03/06 05:29:57 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/03/02 00:47:17 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Malwarebytes
[2013/03/02 00:47:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/02 00:47:09 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/03/02 00:47:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/03/02 00:47:09 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/03/02 00:32:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2013/02/28 16:51:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TortoiseSVN
[2013/02/21 05:15:34 | 001,085,344 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013/02/21 05:15:34 | 000,963,488 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/02/20 06:39:23 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/02/20 06:39:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/02/20 06:39:00 | 000,017,272 | —- | C] (Safer Networking Limited) – C:\Windows\SysNative\sdnclean64.exe
[2013/02/20 06:38:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/02/20 06:38:26 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Programs
[2013/02/20 04:19:25 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\CrashRpt
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Producer
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Livestream for Producers
[2013/02/20 04:19:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Livestream for Producers
[2013/02/20 04:03:19 | 000,044,928 | —- | C] (ManyCam LLC) – C:\Windows\SysNative\drivers\mcvidrv_x64.sys
[2013/02/20 04:03:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\ManyCam
[2013/02/19 04:36:23 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2013/02/19 04:34:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
[2013/02/19 04:29:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2013/02/19 04:28:07 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\LogMeIn Hamachi
[2013/02/19 04:27:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013/02/19 04:27:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2013/02/19 00:48:48 | 000,000,000 | —D | C] – C:\Users\CodyKari\AppData\Local\Diagnostics
[2013/02/19 00:47:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Verizon
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/03/20 21:55:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/20 17:13:42 | 153,443,359 | —- | M] () – C:\Users\CodyKari\Desktop\UTO_Alpha_4_PC.zip
[2013/03/20 15:01:00 | 000,000,302 | —- | M] () – C:\Windows\tasks\Registry Optimizer_DEFAULT.job
[2013/03/20 14:52:04 | 000,781,298 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/20 14:52:04 | 000,661,656 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/20 14:52:04 | 000,121,524 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/20 14:50:10 | 000,010,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/20 14:50:10 | 000,010,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/20 14:45:35 | 000,001,956 | —- | M] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series.lnk
[2013/03/20 14:44:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/20 14:44:49 | 2146,836,479 | -HS- | M] () – C:\hiberfil.sys
[2013/03/20 13:02:06 | 000,001,176 | —- | M] () – C:\Users\Public\Desktop\Snagit 11 Editor.lnk
[2013/03/20 13:02:06 | 000,001,156 | —- | M] () – C:\Users\CodyKari\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 11.lnk
[2013/03/20 13:02:05 | 000,001,132 | —- | M] () – C:\Users\Public\Desktop\Snagit 11.lnk
[2013/03/20 11:12:21 | 000,791,040 | —- | M] () – C:\Users\CodyKari\Desktop\RogueKillerX64.exe
[2013/03/20 02:56:00 | 000,000,310 | —- | M] () – C:\Windows\tasks\Registry Optimizer_UPDATES.job
[2013/03/19 22:37:50 | 000,549,920 | —- | M] (Oleg N. Scherbakov) – C:\Users\CodyKari\Desktop\JRT (1).exe
[2013/03/19 22:32:11 | 000,609,993 | —- | M] () – C:\Users\CodyKari\Desktop\adwcleaner.exe
[2013/03/17 22:58:02 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\CodyKari\Desktop\OTL.exe
[2013/03/15 17:46:59 | 000,069,429 | —- | M] () – C:\Users\CodyKari\Documents\https___myaccountportal.sprint.com_servlet_ecare_inf_template=_include_prin
t_page.jsp&inf_current_template=_billing_pay_bill_debit_success_body.pdf
[2013/03/15 02:39:04 | 000,000,106 | —- | M] () – C:\Windows\VaultMediaClient.INI
[2013/03/13 17:44:02 | 000,178,457 | —- | M] () – C:\Users\CodyKari\Documents\Walmart blinds (4).pdf
[2013/03/13 10:55:09 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/13 10:55:09 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/10 22:05:12 | 000,000,057 | —- | M] () – C:\ProgramData\Ament.ini
[2013/03/08 19:03:55 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/08 19:03:54 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/03/08 19:03:54 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/03/08 19:03:54 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/08 19:03:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/08 19:03:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/08 18:01:00 | 000,003,584 | —- | M] () – C:\Users\CodyKari\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/28 15:21:43 | 000,062,987 | —- | M] () – C:\Users\CodyKari\Documents\Verizon 2-28-2013.pdf
[2013/02/28 15:18:51 | 000,142,242 | —- | M] () – C:\Users\CodyKari\Documents\sprint bill 2-28-2013.pdf
[2013/02/21 05:15:23 | 001,085,344 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\npDeployJava1.dll
[2013/02/21 05:15:23 | 000,963,488 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2013/02/19 04:12:25 | 000,091,894 | —- | M] () – C:\Users\CodyKari\Documents\Order Confirmation - Kohls.pdf
[2013/02/19 00:48:06 | 000,000,260 | —- | M] () – C:\Windows\SysWow64\cmdVBS.vbs
[2013/02/19 00:48:06 | 000,000,256 | —- | M] () – C:\Windows\SysWow64\MSIevent.bat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/03/20 17:13:24 | 153,443,359 | —- | C] () – C:\Users\CodyKari\Desktop\UTO_Alpha_4_PC.zip
[2013/03/20 13:02:06 | 000,001,176 | —- | C] () – C:\Users\Public\Desktop\Snagit 11 Editor.lnk
[2013/03/20 13:02:06 | 000,001,156 | —- | C] () – C:\Users\CodyKari\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 11.lnk
[2013/03/20 13:02:05 | 000,001,132 | —- | C] () – C:\Users\Public\Desktop\Snagit 11.lnk
[2013/03/20 11:00:33 | 000,001,163 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/03/19 22:32:06 | 000,609,993 | —- | C] () – C:\Users\CodyKari\Desktop\adwcleaner.exe
[2013/03/19 22:28:18 | 000,791,040 | —- | C] () – C:\Users\CodyKari\Desktop\RogueKillerX64.exe
[2013/03/15 17:46:59 | 000,069,429 | —- | C] () – C:\Users\CodyKari\Documents\https___myaccountportal.sprint.com_servlet_ecare_inf_template=_include_prin
t_page.jsp&inf_current_template=_billing_pay_bill_debit_success_body.pdf
[2013/03/15 02:43:17 | 000,001,023 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2013/03/13 17:44:02 | 000,178,457 | —- | C] () – C:\Users\CodyKari\Documents\Walmart blinds (4).pdf
[2013/03/10 22:06:38 | 000,001,956 | —- | C] () – C:\Users\CodyKari\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series.lnk
[2013/03/10 22:05:12 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/03/10 20:14:03 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/03/08 19:02:56 | 000,000,106 | —- | C] () – C:\Windows\VaultMediaClient.INI
[2013/03/08 18:01:00 | 000,003,584 | —- | C] () – C:\Users\CodyKari\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/28 15:21:43 | 000,062,987 | —- | C] () – C:\Users\CodyKari\Documents\Verizon 2-28-2013.pdf
[2013/02/28 15:18:51 | 000,142,242 | —- | C] () – C:\Users\CodyKari\Documents\sprint bill 2-28-2013.pdf
[2013/02/20 06:39:04 | 000,002,189 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/02/19 04:12:25 | 000,091,894 | —- | C] () – C:\Users\CodyKari\Documents\Order Confirmation - Kohls.pdf
[2013/02/19 00:48:06 | 000,000,260 | —- | C] () – C:\Windows\SysWow64\cmdVBS.vbs
[2013/02/19 00:48:06 | 000,000,256 | —- | C] () – C:\Windows\SysWow64\MSIevent.bat
[2013/01/27 23:40:44 | 000,703,117 | —- | C] () – C:\Users\CodyKari\AppData\Roaming\technic-launcher.jar
[2013/01/18 16:56:53 | 000,757,660 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2009/07/13 21:41:54 | 014,161,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2009/07/13 21:16:14 | 012,866,560 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/07/13 21:15:20 | 000,605,696 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/03/20 11:30:30 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\.minecraft
[2013/02/24 02:34:38 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\.techniclauncher
[2013/03/16 21:51:39 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Audacity
[2013/01/28 00:35:47 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\DAEMON Tools Lite
[2013/02/24 02:34:35 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\logs
[2013/02/13 01:33:22 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Nico Mak Computing
[2013/02/15 00:54:34 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Origin
[2013/02/06 20:37:26 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\Subversion
[2013/03/17 22:44:16 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\TeamViewer
[2013/03/19 08:06:30 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\TS3Client

========== Purity Check ==========



========== Custom Scans ==========

< :Services >
[2009/07/14 01:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009/07/14 01:08:49 | 000,015,148 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2013/01/24 06:56:46 | 000,000,310 | —- | C] () – C:\Windows\Tasks\Registry Optimizer_UPDATES.job
[2013/01/24 06:56:47 | 000,000,302 | —- | C] () – C:\Windows\Tasks\Registry Optimizer_DEFAULT.job
[2013/01/28 05:39:07 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job

< >

< :OTL >

< IE - HKCU\..\SearchScopes\{F7C16FAF-7949-4A90-840A-4FEE28CCD0EC}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468 >

< [2013/01/24 06:56:43 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6} >
Invalid Switch: 24 06:56:43 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}

< CHR - homepage: http://search.babylon.com/?affID=117023&am…000bcaec51a56c8 >
Invalid Switch: ?affID=117023&am…000bcaec51a56c8

< O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4D594333-0076-A76A-76A7-7A786E7484D7} - No CLSID value found >

< O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found >

< O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell - "" = AutoRun >

< O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell\AutoRun\command - "" = E:\Setup.exe – [2013/03/04 19:43:48 | 001,013,399 | R— | M] (SQUARE ENIX ) >

< [2013/03/19 21:05:19 | 000,000,302 | —- | M] () – C:\Windows\tasks\Registry Optimizer_DEFAULT.job >
Invalid Switch: 19 21:05:19 | 000,000,302 | —- | M] () – C:\Windows\tasks\Registry Optimizer_DEFAULT.job

< [2013/03/06 03:56:12 | 000,000,310 | —- | M] () – C:\Windows\tasks\Registry Optimizer_UPDATES.job >
Invalid Switch: 06 03:56:12 | 000,000,310 | —- | M] () – C:\Windows\tasks\Registry Optimizer_UPDATES.job

< [2013/03/15 02:48:54 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\uTorrent >
Invalid Switch: 15 02:48:54 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\uTorrent

< @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:82F50D1C >

< >

< :Commands >

< [purity] >

< [emptytemp] >

< [Reboot] >

========== Alternate Data Streams ==========

@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:82F50D1C

< End of report >
Thank you for the log but it appears that some of my previous instructions have been incorporated into an OTL log.

I’m not quite sure how that happened but I need you to try and follow these instructions carefully.

If any of these steps is unclear, please let me know and I’ll try to explain further.


Uninstall the following programs, if present:

WinZip Registry Optimizer
Java 7 Update 15 (64-bit)
which is out-of-date1. Click Start, Control Panel, Programs, and then Programs and Features.
2. Click on WinZip Registry Optimizer and then Uninstall.
Repeat this for Java 7 Update (64-bit) .

If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

===================================================

Uninstall Google Chrome

For the time being I would like for you to uninstall Google Chrome and only use Firefox or Internet Explorer. You can reinstall it later if you like. We need to remove some entries and that is the easiest way to do so with Google Chrome.

If asked about user data or settings, don’t check the box that asks to remember settings. We need to remove those also.

====================================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\..\SearchScopes\{F7C16FAF-7949-4A90-840A-4FEE28CCD0EC}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3220468
    [2013/01/24 06:56:43 | 000,000,000 | —D | M] (uTorrentControl_v2) – C:\Users\CodyKari\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
    CHR - homepage: http://search.babylon.com/?affID=117023&am…000bcaec51a56c8
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4D594333-0076-A76A-76A7-7A786E7484D7} - No CLSID value found
    O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
    O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{e87c8a25-6457-11e2-8af1-bcaec51a56c8}\Shell\AutoRun\command - "" = E:\Setup.exe – [2013/03/04 19:43:48 | 001,013,399 | R— | M] (SQUARE ENIX )
    [2013/03/19 21:05:19 | 000,000,302 | —- | M] () – C:\Windows\tasks\Registry Optimizer_DEFAULT.job
    [2013/03/06 03:56:12 | 000,000,310 | —- | M] () – C:\Windows\tasks\Registry Optimizer_UPDATES.job
    [2013/03/15 02:48:54 | 000,000,000 | —D | M] – C:\Users\CodyKari\AppData\Roaming\uTorrent
    @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:82F50D1C
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log and new OTL log.
Logs to include in the next post:

OTL fix log
New OTL log


Thanks

Satchfan
Hi Codycctx It has been several days since I sent my last set of instructions to help with your computer problem. Please let me know if you are having problems. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI