This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Overheating CPU - cmdagent.exe, WmiPrvSE.exe main culprits [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi -

My laptop has overheated several times, shutting down the screen and then itself off completely. I took the battery out and am running it through the plug, but other troubleshooting websites have led me to believe that it's my CPU (which is constantly running at 100%). Main culprits are cmdagent.exe and WmiPrvSE.exe.

Thanks,

Chaz



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:49:24 PM, on 4/11/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Users\Chaz\AppData\Local\Google\Update\1.3.21.135\GoogleCrashHandler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Users\Chaz\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.yahoo.com?fr=fp-comodo
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.*.*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [IntelliType Pro] "c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Chaz\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO System Utilities Service (CSUService) - Comodo Security Solutions, Inc. - C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\STacSV.exe

–
End of file - 11016 bytes
Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any antivirus programs during the scan (If you have difficulty properly disabling your protective programs, refer to this link here )
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Thanks for your prompt reply, Jeff.

I want to apologize in advance for meddling a bit after posting the HijackThis file - nothing was deleted from the list, but I did reinstall two programs. I'm applying for jobs and needed to use my laptop for a bit last night. Sorry. I have reposted a new HijackThis file and here's a list of what I did:

1. I reinstalled a newer version of Comodo A/V - which has helped tremendously. The Quickscan did not detect anything.

2. Allowed Skype and VodBurner to update (required for meeting).

I promise not to do anything else until instructed.

What I'm hoping to accomplish is that I'd like to cull the autostart processes of programs I don't need on all the time and other junk from my HijackThis list to help lessen the strain on my CPU (my laptop is 4 years old, and I need it to last another 6-8 months).

Thanks,

Chaz


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:51:51 PM, on 4/12/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Users\Chaz\AppData\Local\Google\Update\1.3.21.135\GoogleCrashHandler.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Chaz\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.yahoo.com?fr=fp-comodo
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.*.*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IntelliType Pro] "c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [gbrspcontrol] "C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Chaz\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [AppVodBurner] C:\Program Files\vodburner\vodburner.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Start GeekBuddy.lnk = C:\Program Files\COMODO\GeekBuddy\launcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: COMODO LPS Launcher (CLPSLauncher) - Comodo Security Solutions Inc. - C:\Program Files\Common Files\COMODO\launcher_service.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: COMODO System Utilities Service (CSUService) - Comodo Security Solutions, Inc. - C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files\Comodo\Dragon\dragon_updater.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: GeekBuddyRSP Service (GeekBuddyRSP) - Comodo Security Solutions, Inc. - C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\STacSV.exe

–
End of file - 12057 bytes

###

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16476 BrowserJavaVersion: 10.17.2
Run by [removed] at 15:54:17 on 2013-04-12
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2814.1441 [GMT -4:00]
.
AV: COMODO Antivirus *Disabled/Updated* {458BB331-2324-0753-3D5F-1472EB102AC0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Antivirus *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Common Files\COMODO\launcher_service.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\STacSV.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe
C:\Program Files\COMODO\COMODO System Utilities\CSU_CLI.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\conhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Users\Chaz\AppData\Local\Google\Update\1.3.21.135\GoogleCrashHandler.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\COMODO\GeekBuddy\unit.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chaz\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Users\Chaz\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://us.yahoo.com?fr=fp-comodo
uProxyOverride = 192.168.*.*
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} -
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - LocalServer32 -
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - LocalServer32 -
TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - LocalServer32 -
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [Google Update] "c:\users\chaz\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [GoogleDriveSync] "c:\program files\google\drive\googledrivesync.exe" /autostart
uRun: [AppVodBurner] c:\program files\vodburner\vodburner.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [UpdatePRCShortCut] "c:\program files\hewlett-packard\recovery\muitransfer\muistartmenu.exe" "c:\program files\hewlett-packard\recovery" updatewithcreateonce "software\cyberlink\PowerRecover"
mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IntelliType Pro] "c:\program files\microsoft mouse and keyboard center\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft mouse and keyboard center\ipoint.exe"
mRun: [COMODO Internet Security] c:\program files\comodo\comodo internet security\cistray.exe
mRun: [gbrspcontrol] "c:\program files\common files\comodo\GeekBuddyRSP.exe" -controlservice -slave
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\chaz\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\start geekbuddy.lnk - c:\program files\comodo\geekbuddy\launcher.exe
uPolicies-System: WallpaperStyle = 2
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: HideFastUserSwitching = dword:0
mPolicies-System: WallpaperStyle = 2
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvLsp.dll
TCP: NameServer = 208.59.247.45 208.59.247.46 192.168.1.1
TCP: Interfaces\{16D5C419-B39F-442A-B9CF-0558A20254A2} : DHCPNameServer = [removed] [removed] 192.168.1.1
TCP: Interfaces\{39149679-C7E5-4725-B007-DD4D0FB93D4D} : DHCPNameServer = [removed] [removed] 192.168.1.1
TCP: Interfaces\{39149679-C7E5-4725-B007-DD4D0FB93D4D}\241627461636B6D2445637B647F607D275962756C6563737 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{39149679-C7E5-4725-B007-DD4D0FB93D4D}\3596475636F6D6632473531383 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{39149679-C7E5-4725-B007-DD4D0FB93D4D}\A456E6024456C696 : DHCPNameServer = 192.168.2.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs=
SSODL: WebCheck -
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\chaz\appdata\roaming\mozilla\firefox\profiles\be6x5764.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://us.yahoo.com?fr=fp-comodo
FF - prefs.js: keyword.URL - hxxp://us.search.yahoo.com/search?fr=ytff-comodo&p=
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBook.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBookDB.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpNeoLogger.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSaturn.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSeymour.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartSelect.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSWPOperation.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPLogging.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTC.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTL.dll
FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXREStub.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npWebLaunch.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll
FF - plugin: c:\programdata\realnetworks\realdownloader\browserplugins\npdlplugin.dll
FF - plugin: c:\users\chaz\appdata\local\google\update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: c:\users\chaz\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\chaz\appdata\roaming\electronic arts\game face\npGameFacePlugin.dll
FF - plugin: c:\users\chaz\appdata\roaming\mozilla\firefox\profiles\be6x5764.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: c:\users\chaz\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\chaz\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\users\chaz\appdata\roaming\mozilla\plugins\npo1d.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - ExtSQL: 2013-04-08 14:27; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\programdata\realnetworks\realdownloader\browserplugins\firefox\Ext
FF - ExtSQL: !HIDDEN! 2010-01-20 20:26; [removed]; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys [2012-10-6 15680]
R1 archlp;archlp;c:\windows\system32\drivers\ArcHlp.sys [2009-6-3 131584]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [2012-9-3 35064]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2013-1-16 20072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2013-1-16 576768]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\AEstSrv.exe [2012-3-22 81920]
R2 CLPSLauncher;COMODO LPS Launcher;c:\program files\common files\comodo\launcher_service.exe [2013-3-29 70352]
R2 CSUService;COMODO System Utilities Service;c:\program files\comodo\comodo system utilities\CSUService.exe [2012-2-24 261952]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\comodo\dragon\dragon_updater.exe [2013-3-28 2074768]
R2 GeekBuddyRSP;GeekBuddyRSP Service;c:\program files\common files\comodo\GeekBuddyRSP.exe [2013-3-13 1851088]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files\hewlett-packard\hp support framework\HPSA_Service.exe [2012-9-27 86528]
R3 pmkbdfltr;PenMount Keyboard Device Filter Driver;c:\windows\system32\drivers\pmkbdfltr.sys [2012-10-6 15248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\comodo\comodo internet security\cmdvirth.exe [2013-1-24 127184]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-25 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2011-5-13 1492840]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2013-1-2 197224]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-7 52224]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== File Associations ===============
.
ShellExec: DigitalTheatre.exe: open="c:\program files\arcsoft\totalmedia theatre 3\uDTStart.exe" "%1"
.
=============== Created Last 30 ================
.
2013-04-12 15:36:35 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-12 15:15:16 47368 —-a-w- c:\windows\system32\certsentry.dll
2013-04-12 15:13:32 ——– d—–w- c:\program files\common files\COMODO
2013-04-12 03:40:30 ——– d—–r- c:\program files\Skype
2013-04-12 03:34:11 ——– d—–w- c:\program files\VodBurner
2013-04-11 23:43:11 ——– d-s—w- c:\programdata\Shared Space
2013-04-11 23:38:51 ——– d—–w- c:\programdata\COMODO
2013-04-11 23:38:07 ——– d—–w- c:\users\chaz\appdata\local\Comodo
2013-04-11 23:36:45 ——– d—–w- c:\programdata\Comodo Downloader
2013-04-10 17:34:06 60872 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{c7fa53dd-2fac-4331-963b-edfb1f84d1cc}\offreg.dll
2013-04-10 15:29:24 2347008 —-a-w- c:\windows\system32\win32k.sys
2013-04-10 15:29:18 196328 —-a-w- c:\windows\system32\drivers\fvevol.sys
2013-04-10 15:29:11 3913560 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 15:29:10 3968856 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-10 15:29:00 69632 —-a-w- c:\windows\system32\smss.exe
2013-04-10 15:28:59 38912 —-a-w- c:\windows\system32\csrsrv.dll
2013-04-10 15:28:44 3217408 —-a-w- c:\windows\system32\mstscax.dll
2013-04-10 15:28:42 131584 —-a-w- c:\windows\system32\aaclient.dll
2013-04-10 15:28:40 7108640 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{c7fa53dd-2fac-4331-963b-edfb1f84d1cc}\mpengine.dll
2013-04-10 15:28:40 36864 —-a-w- c:\windows\system32\tsgqec.dll
2013-04-10 15:28:14 1212264 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 15:16:03 ——– d—–w- c:\users\chaz\appdata\roaming\RealNetworks
2013-04-08 18:27:08 ——– d—–w- c:\program files\RealNetworks
2013-04-08 18:27:04 ——– d—–w- c:\programdata\RealNetworks
2013-04-03 03:21:42 ——– d—–w- c:\programdata\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
2013-03-26 11:54:47 15872 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-22 19:05:19 ——– d—–w- c:\users\chaz\appdata\roaming\GlarySoft
2013-03-22 18:07:22 ——– d—–w- c:\program files\Glary Utilities
.
==================== Find3M ====================
.
2013-04-12 15:36:19 861088 —-a-w- c:\windows\system32\npdeployJava1.dll
2013-04-12 15:36:19 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-04-08 18:19:55 499712 —-a-w- c:\windows\system32\msvcp71.dll
2013-04-08 18:19:55 348160 —-a-w- c:\windows\system32\msvcr71.dll
2013-03-13 00:26:33 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-13 00:26:33 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-12 05:10:56 237088 ——w- c:\windows\system32\MpSigStub.exe
2013-02-22 03:46:00 1800704 —-a-w- c:\windows\system32\jscript9.dll
2013-02-22 03:38:00 1129472 —-a-w- c:\windows\system32\wininet.dll
2013-02-22 03:37:50 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2013-02-22 03:34:17 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2013-02-22 03:34:03 420864 —-a-w- c:\windows\system32\vbscript.dll
2013-02-22 03:31:46 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2013-02-12 04:48:31 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll
2013-02-08 05:28:14 4126720 —-a-w- c:\program files\GUT5A4F.tmp
2013-01-25 02:43:02 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 02:43:02 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 02:42:50 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 02:42:50 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-16 23:51:44 43728 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-16 23:51:42 576768 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2013-01-16 23:51:42 20072 —-a-w- c:\windows\system32\drivers\cmderd.sys
.
============= FINISH: 16:01:07.89 ===============

#####


ATTACH.TXT
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 1/9/2010 3:03:28 PM
System Uptime: 4/12/2013 3:44:08 PM (1 hours ago)
.
Motherboard: Quanta | | 3651
Processor: Intel® Atom™ CPU N280 @ 1.66GHz | CPU | 1666/667mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 287 GiB total, 128.709 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 1.827 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP527: 3/26/2013 7:55:06 AM - Windows Update
RP528: 3/26/2013 11:21:07 AM - Windows Update
RP529: 3/29/2013 1:58:39 PM - Windows Update
RP530: 4/2/2013 12:39:36 PM - Windows Update
RP531: 4/2/2013 11:03:49 PM - HPSF Applying updates
RP532: 4/2/2013 11:23:28 PM - Installed HP Support Assistant
RP533: 4/8/2013 10:24:13 AM - Windows Update
RP534: 4/10/2013 11:38:48 AM - Windows Update
RP535: 4/10/2013 12:56:35 PM - Removed Bonjour
RP536: 4/10/2013 1:11:13 PM - Removed Ask Toolbar.
RP537: 4/10/2013 4:57:38 PM - Removed COMODO livePCsupport
RP538: 4/11/2013 4:31:55 PM - Removed COMODO livePCsupport
RP539: 4/12/2013 11:33:34 AM - Removed Java™ 6 Update 37
RP540: 4/12/2013 11:35:41 AM - Installed Java 7 Update 17
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
32 Bit HP CIO Components Installer
3D SexVilla CRACK (oxin)
7-Zip 9.20
AC3Filter 1.63b
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.6)
Adobe Shockwave Player
ALPS Touch Pad Driver
Amazon Kindle
Amazon Send to Kindle
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft TotalMedia
ArcSoft WebCam Companion 3
BCL easyConverter SDK 1.0.0 Module
BitTorrent
Broadcom 802.11 Wireless LAN Adapter
BufferChm
Bulent's Screen Recorder
calibre
Camfrog Video Chat 6.2
CCleaner
Comodo Dragon
COMODO Internet Security
COMODO System Utilities
Copy
CyberLink DVD Suite
D3DX10
Destinations
DeviceDiscovery
DivX Setup
DJ_AIO_06_F2400_SW_Min
EA SPORTS Game Face Browser Plugin [removed]
EPUB to MOBI
F2400
Family Tree Maker 2008
Flash Favorite 2.0
focus booster
GeekBuddy
GIMP 2.6.10
Glary Utilities 2.54.0.1759
Google Chrome
Google Drive
Google Talk Plugin
Google Update Helper
GPBaseService2
GPL MPEG-1/2 DirectShow Decoder Filter
Hewlett-Packard ACLM.NET v1.2.1.1
HijackThis 2.0.2
HP Customer Experience Enhancements
HP QuickSync
HP Setup
HP Support Assistant
HP Update
HP User Guides 0150
HP Wireless Assistant
HPPhotoGadget
hpPrintProjects
HPProductAssistant
HPSSupply
hpWLPGInstaller
IDT Audio
ImgBurn
iTunes
Java 7 Update 17
Java Auto Updater
jZip
Malwarebytes Anti-Malware version 1.70.0.1100
ManyCam 2.5.48 (remove only)
MarketResearch
Matroska Pack - Lazy Man's MKV 0.9.9
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Mouse and Keyboard Center
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Primary Interoperability Assemblies 2005
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ Run Time Lib Setup
Microsoft WSE 3.0
Mobipocket Creator 4.2
MotoHelper 2.1.32 Driver 5.4.0
MotoHelper MergeModules
Motorola Mobile Drivers Installation 5.4.0
Mozilla Firefox 18.0.2 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NVIDIA Control Panel 310.70
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Install Application
OGA Notifier 2.0.0048.0
Power2Go
PowerRecover
PVSonyDll
QuickTime
RealDownloader
Realtek USB 2.0 Card Reader
Scan
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Skype™ 6.3
SmartWebPrinting
SolutionCenter
SPG MP3 Recorder 1.0
Status
STDU Viewer version 1.5.597.0
Synaptics Pointing Device Driver
Toolbox
TrayApp
Trillian
TrueCrypt
TweetDeck
UMPlayer 0.98 [P4]
Uniblue SystemTweaker
Unity Web Player
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.6195
Veetle TV 0.9.18
VodBurner
vShare Plugin
WebReg
WinDirStat 1.1.2
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin
XnView 1.97.8
Xvid 1.2.2 final uninstall
Yahoo! Messenger
.
==== Event Viewer Messages From Past Week ========
.
4/12/2013 3:44:59 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
4/12/2013 3:44:56 PM, Error: Service Control Manager [7001] - The Windows Image Acquisition (WIA) service depends on the Shell Hardware Detection service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
4/12/2013 3:44:39 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000004a (0x8328573a, 0xc0000001, 0x00000000, 0x00000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 041213-26052-01.
4/11/2013 8:23:17 PM, Error: Service Control Manager [7034] - The COMODO LPS Launcher service terminated unexpectedly. It has done this 1 time(s).
4/11/2013 8:22:56 PM, Error: Service Control Manager [7031] - The GeekBuddyRSP Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
4/11/2013 8:22:38 PM, Error: Service Control Manager [7034] - The COMODO Dragon Update Service service terminated unexpectedly. It has done this 1 time(s).
4/11/2013 8:18:11 PM, Error: Microsoft-Windows-HAL [12] - The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
4/11/2013 7:16:47 PM, Error: Service Control Manager [7000] - The MotoHelper Service service failed to start due to the following error: The system cannot find the file specified.
4/11/2013 10:14:49 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the nvsvc service.
.
==== End Of File ===========================

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-04-12 16:03:37
—————————–
16:03:37.908 OS Version: Windows 6.1.7601 Service Pack 1
16:03:37.909 Number of processors: 2 586 0x1C02
16:03:37.914 ComputerName: CP166 UserName: Chaz
16:03:40.914 Initialize success
16:05:59.883 AVAST engine defs: 13041201
16:11:00.578 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000063
16:11:00.593 Disk 0 Vendor: ST932032 0005 Size: 305245MB BusType: 11
16:11:00.774 Disk 0 MBR read successfully
16:11:00.784 Disk 0 MBR scan
16:11:00.803 Disk 0 unknown MBR code
16:11:00.819 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
16:11:00.840 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 293927 MB offset 409600
16:11:00.896 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 11117 MB offset 602372096
16:11:00.922 Disk 0 scanning sectors +625139712
16:11:01.129 Disk 0 scanning C:\Windows\system32\drivers
16:11:32.073 Service scanning
16:12:46.080 Modules scanning
16:13:00.422 Disk 0 trace - called modules:
16:13:00.897 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll storport.sys nvstor32.sys
16:13:00.921 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86716ac8]
16:13:00.946 3 CLASSPNP.SYS[8b26659e] -> nt!IofCallDriver -> [0x86608440]
16:13:00.971 5 ACPI.sys[8aab33d4] -> nt!IofCallDriver -> \Device\00000063[0x86608568]
16:13:02.871 AVAST engine scan C:\Windows
16:13:07.197 AVAST engine scan C:\Windows\system32
16:25:13.482 AVAST engine scan C:\Windows\system32\drivers
16:25:58.195 AVAST engine scan C:\Users\Chaz
16:26:34.588 Disk 0 MBR has been saved successfully to "C:\Users\Chaz\Desktop\MBR.dat"
16:26:34.617 The log file has been saved successfully to "C:\Users\Chaz\Desktop\aswMBR.txt"
Hi,

Are you aware that your system is set to run from a proxy?

ComboFix

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 13-04-14.01 - Chaz 04/14/2013 12:35:01.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2814.1783 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: COMODO Antivirus *Disabled/Updated* {458BB331-2324-0753-3D5F-1472EB102AC0} SP: COMODO Antivirus *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Chaz\Documents\~WRL0001.tmp c:\users\Chaz\Documents\~WRL0003.tmp c:\users\Chaz\Documents\~WRL0005.tmp . . ((((((((((((((((((((((((( Files Created from 2013-03-14 to 2013-04-14 ))))))))))))))))))))))))))))))) . . 2013-04-14 17:09 . 2013-04-14 17:09 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-04-12 15:42 . 2013-04-12 15:42 ——– d—–w- c:\program files\Common Files\Java 2013-04-12 15:36 . 2013-04-12 15:36 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-04-12 15:15 . 2013-04-12 15:15 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\Comodo 2013-04-12 15:15 . 2013-04-12 15:15 47368 —-a-w- c:\windows\system32\certsentry.dll 2013-04-12 15:13 . 2013-04-12 15:13 ——– d—–w- c:\program files\Common Files\COMODO 2013-04-12 03:40 . 2013-04-12 03:40 ——– d—–w- c:\program files\Common Files\Skype 2013-04-12 03:40 . 2013-04-12 03:40 ——– d—–r- c:\program files\Skype 2013-04-12 03:34 . 2013-04-12 03:34 ——– d—–w- c:\program files\VodBurner 2013-04-11 23:43 . 2013-04-11 23:44 ——– d-s—w- c:\programdata\Shared Space 2013-04-11 23:38 . 2013-04-11 23:39 ——– d—–w- c:\programdata\COMODO 2013-04-11 23:38 . 2013-04-11 23:38 ——– d—–w- c:\users\Chaz\AppData\Local\Comodo 2013-04-11 23:36 . 2013-04-11 23:36 ——– d—–w- c:\programdata\Comodo Downloader 2013-04-10 17:34 . 2013-04-10 17:34 60872 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C7FA53DD-2FAC-4331-963B-EDFB1F84D1CC}\offreg.dll 2013-04-10 15:29 . 2013-03-01 03:09 2347008 —-a-w- c:\windows\system32\win32k.sys 2013-04-10 15:29 . 2013-01-24 04:47 196328 —-a-w- c:\windows\system32\drivers\fvevol.sys 2013-04-10 15:29 . 2013-03-19 05:04 3913560 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-04-10 15:29 . 2013-03-19 05:04 3968856 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-04-10 15:29 . 2013-03-19 02:49 69632 —-a-w- c:\windows\system32\smss.exe 2013-04-10 15:28 . 2013-03-19 04:48 38912 —-a-w- c:\windows\system32\csrsrv.dll 2013-04-10 15:28 . 2013-02-15 04:37 3217408 —-a-w- c:\windows\system32\mstscax.dll 2013-04-10 15:28 . 2013-02-15 04:34 131584 —-a-w- c:\windows\system32\aaclient.dll 2013-04-10 15:28 . 2013-03-15 07:21 7108640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C7FA53DD-2FAC-4331-963B-EDFB1F84D1CC}\mpengine.dll 2013-04-10 15:28 . 2013-02-15 03:25 36864 —-a-w- c:\windows\system32\tsgqec.dll 2013-04-10 15:28 . 2013-03-02 05:07 1212264 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 15:16 . 2013-04-10 15:16 ——– d—–w- c:\users\Chaz\AppData\Roaming\RealNetworks 2013-04-08 18:27 . 2013-04-08 18:27 ——– d—–w- c:\program files\RealNetworks 2013-04-08 18:27 . 2013-04-08 18:27 ——– d—–w- c:\programdata\RealNetworks 2013-04-03 03:21 . 2013-04-03 03:21 ——– d—–w- c:\programdata\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF} 2013-03-26 11:54 . 2013-02-12 03:32 15872 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-03-22 19:05 . 2013-03-22 19:05 ——– d—–w- c:\users\Chaz\AppData\Roaming\GlarySoft 2013-03-22 18:07 . 2013-03-22 18:07 ——– d—–w- c:\program files\Glary Utilities . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-12 15:36 . 2012-07-05 20:02 861088 —-a-w- c:\windows\system32\npdeployJava1.dll 2013-04-12 15:36 . 2010-05-23 13:51 782240 —-a-w- c:\windows\system32\deployJava1.dll 2013-04-08 18:19 . 2009-03-20 03:38 499712 —-a-w- c:\windows\system32\msvcp71.dll 2013-04-08 18:19 . 2009-03-20 03:38 348160 —-a-w- c:\windows\system32\msvcr71.dll 2013-03-13 00:26 . 2012-05-14 19:54 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-03-13 00:26 . 2011-08-28 16:45 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-03-12 05:10 . 2010-01-10 23:40 237088 ——w- c:\windows\system32\MpSigStub.exe 2013-02-12 04:48 . 2013-03-13 13:41 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-13 13:41 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll 2013-02-08 05:28 . 2013-02-08 05:28 4126720 —-a-w- c:\program files\GUT5A4F.tmp 2013-01-25 02:43 . 2013-01-25 02:43 35488 —-a-w- c:\windows\system32\cmdcsr.dll 2013-01-25 02:43 . 2013-01-25 02:43 354752 —-a-w- c:\windows\system32\guard32.dll 2013-01-25 02:42 . 2013-01-25 02:42 40656 —-a-w- c:\windows\system32\cmdkbd32.dll 2013-01-25 02:42 . 2013-01-25 02:42 263888 —-a-w- c:\windows\system32\cmdvrt32.dll 2013-01-16 23:51 . 2013-01-16 23:51 84416 —-a-w- c:\windows\system32\drivers\inspect.sys 2013-01-16 23:51 . 2013-01-16 23:51 43728 —-a-w- c:\windows\system32\drivers\cmdhlp.sys 2013-01-16 23:51 . 2013-01-16 23:51 576768 —-a-w- c:\windows\system32\drivers\cmdguard.sys 2013-01-16 23:51 . 2013-01-16 23:51 20072 —-a-w- c:\windows\system32\drivers\cmderd.sys 2013-04-03 20:33 . 2013-04-03 20:33 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2013-03-07 20:31 576976 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}] 2013-03-07 20:31 576976 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2013-03-07 20:31 576976 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2013-03-07 20:31 576976 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2013-03-07 19357112] "AppVodBurner"="c:\program files\vodburner\vodburner.exe" [2013-04-05 4688896] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2012-10-25 233472] "UpdatePRCShortCut"="c:\program files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-12-14 824232] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2012-03-22 2282792] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2012-03-22 495708] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1093232] "IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 1668720] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2013-01-25 1430736] "gbrspcontrol"="c:\program files\Common Files\COMODO\GeekBuddyRSP.exe" [2013-03-13 1851088] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\users\Chaz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] Start GeekBuddy.lnk - c:\program files\COMODO\GeekBuddy\launcher.exe [2013-3-29 49360] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system] "WallpaperStyle"= 2 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x] R3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x] R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [x] S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [x] S1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [x] S1 CFRMD;CFRMD;c:\windows\system32\DRIVERS\CFRMD.sys [x] S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\aestsrv.exe [x] S2 CLPSLauncher;COMODO LPS Launcher;c:\program files\Common Files\COMODO\launcher_service.exe [x] S2 CSUService;COMODO System Utilities Service;c:\program files\COMODO\COMODO System Utilities\CSUService.exe [x] S2 DragonUpdater;COMODO Dragon Update Service;c:\program files\Comodo\Dragon\dragon_updater.exe [x] S2 GeekBuddyRSP;GeekBuddyRSP Service;c:\program files\Common Files\COMODO\GeekBuddyRSP.exe [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [x] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [x] S3 pmkbdfltr;PenMount Keyboard Device Filter Driver;c:\windows\system32\DRIVERS\pmkbdfltr.sys [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2013-04-14 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-14 00:26] . 2013-04-14 c:\windows\Tasks\GlaryInitialize.job - c:\program files\Glary Utilities\initialize.exe [2013-03-22 04:41] . 2013-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-09-13 17:26] . 2013-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-09-13 17:26] . 2013-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438872117-3210986945-3872544021-1001Core.job - c:\users\Chaz\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-09 22:54] . 2013-04-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438872117-3210986945-3872544021-1001UA.job - c:\users\Chaz\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-09 22:54] . 2013-04-03 c:\windows\Tasks\HPCeeScheduleForChaz.job - c:\program files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 02:15] . . ——- Supplementary Scan ——- . uStart Page = hxxp://us.yahoo.com?fr=fp-comodo uInternet Settings,ProxyOverride = 192.168.*.* IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000 LSP: c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll TCP: DhcpNameServer = [removed] [removed] 192.168.1.1 FF - ProfilePath - c:\users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://us.yahoo.com?fr=fp-comodo FF - prefs.js: keyword.URL - hxxp://us.search.yahoo.com/search?fr=ytff-comodo&p;= FF - ExtSQL: 2013-04-08 14:27; {DAC3F861-B30D-40dd-9166-F4E75327FAC7}; c:\programdata\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF - ExtSQL: !HIDDEN! 2010-01-20 20:26; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . - - - - ORPHANS REMOVED - - - - . SafeBoot-Wdf01000.sys . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'lsass.exe'(576) c:\windows\system32\guard32.dll . Completion time: 2013-04-14 13:17:02 ComboFix-quarantined-files.txt 2013-04-14 17:17 . Pre-Run: 137,479,311,360 bytes free Post-Run: 138,040,307,712 bytes free . - - End Of File - - 053428A3688AC6EEE5724A17137D3BE8
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


    ClearJavaCache::

    File::
    c:\program files\GUT5A4F.tmp

    DDS::
    uInternet Settings,ProxyOverride = 192.168.*.*

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Post the new ComboFix log and let me know how your system is running now. :)
Jeff - I created the .txt file as you directed and dropped it into the ComboFix icon, but when it began to ran, it gave me repeated "Error opening file for writing" warnings for a string of files in folder C:/32788R22FWJFW. This happened 30-40 times (I clicked 'ignore' to get through to the end) - and then afterwards, a message popped up stating "The contents of folder C:\Windows\erdnt\Hiv-backup could not be completely deleted!". It "finished", and closed itself, with no log. I had to run ComboFix 3 or 4 times the first time before it would finish and open up the logfile. Thoughts?
[external image: Posted Image]
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-
OTL logfile created on: 4/14/2013 8:17:42 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chaz\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 70.58% Memory free
5.49 Gb Paging File | 4.38 Gb Available in Paging File | 79.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.04 Gb Total Space | 127.91 Gb Free Space | 44.56% Space Free | Partition Type: NTFS
Drive D: | 10.86 Gb Total Space | 1.83 Gb Free Space | 16.83% Space Free | Partition Type: NTFS

Computer Name: CP166 | User Name: Chaz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Chaz\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\COMODO\GeekBuddy\unit_manager.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\COMODO\GeekBuddy\unit.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\Common Files\COMODO\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\COMODO\Dragon\dragon_updater.exe ()
PRC - C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cis.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (COMODO)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\COMODO\COMODO System Utilities\CSU_CLI.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()


========== Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (CLPSLauncher) – C:\Program Files\Common Files\COMODO\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (DragonUpdater) – C:\Program Files\COMODO\Dragon\dragon_updater.exe ()
SRV - (GeekBuddyRSP) – C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (cmdvirth) – C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (COMODO)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (HP Support Assistant Service) – C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (CSUService) – C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe (Comodo Security Solutions, Inc.)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (USBCCID) – system32\DRIVERS\RtsUCcid.sys File not found
DRV - (RtsUIR) – system32\DRIVERS\Rts516xIR.sys File not found
DRV - (catchme) – C:\Users\Chaz\AppData\Local\Temp\catchme.sys File not found
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdguard.sys (COMODO)
DRV - (cmderd) – C:\Windows\System32\drivers\cmderd.sys (COMODO)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (iusb3hcs) – C:\Windows\System32\drivers\iusb3hcs.sys (Intel Corporation)
DRV - (pmkbdfltr) – C:\Windows\System32\drivers\pmkbdfltr.sys (PenMount)
DRV - (CFRMD) – C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (truecrypt) – C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmf6232.sys (NVIDIA Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (archlp) – C:\Windows\System32\drivers\ArcHlp.sys ()
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {04E00A45-571F-44F6-9584-214FCD2768C4}
IE - HKLM\..\SearchScopes\{04E00A45-571F-44F6-9584-214FCD2768C4}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{1C9B8834-03E4-463C-8489-41216564E9C6}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://us.yahoo.com?fr=fp-comodo
IE - HKCU\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolbarhome.com/search.aspx?…s}&srch;=dsp
IE - HKCU\..\SearchScopes\{04E00A45-571F-44F6-9584-214FCD2768C4}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{112A7E09-6595-D1C3-2C4E-CDFD9E56B66C}: "URL" = http://bing.zugo.com/s/?q={searchTerms}&am;…fg=2-76-0-16Mj6
IE - HKCU\..\SearchScopes\{1C9B8834-03E4-463C-8489-41216564E9C6}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTe…mp;fr=chr-i3752
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.*.*

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://us.yahoo.com?fr=fp-comodo"
FF - prefs.js..extensions.enabledAddons: amznUWL%40amazon.com:2.17
FF - prefs.js..extensions.enabledAddons: support%40ancestry.com:1.0.0.1
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:2.5.9.20130409112616
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.12
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: {ccc4ed03-bc79-16e0-71c8-c70e7a75ab9e}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: [removed]:1.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@thrixxx.com/WebLaunch: C:\Program Files\thriXXX\WebLaunch\Binaries\npWebLaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@thrixxx.com/WebLaunch: C:\Program Files\thriXXX\WebLaunch\Binaries\npWebLaunch.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Chaz\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Chaz\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Chaz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\Chaz\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/20 21:26:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AutocompletePro\[removed]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/04/08 14:27:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2013/01/04 13:01:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/08/13 12:52:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/04/08 14:27:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 00:09:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/12 00:09:13 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/20 21:26:28 | 000,000,000 | —D | M]

[2010/01/09 16:56:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Chaz\AppData\Roaming\Mozilla\Extensions
[2013/04/10 13:21:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions
[2013/04/10 13:21:18 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/03/05 17:12:23 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/03/17 08:37:20 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\[removed]
[2012/10/17 04:24:26 | 000,257,103 | —- | M] () (No name found) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\[removed]
[2010/05/14 01:53:20 | 000,001,836 | —- | M] () – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\searchplugins\bing-ff.xml
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/04/12 00:09:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{ccc4ed03-bc79-16e0-71c8-c70e7a75ab9e}
[2013/04/12 00:09:24 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2006/08/09 06:16:08 | 000,030,408 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npWebLaunch.dll
[2013/04/03 16:33:40 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/12 00:09:23 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com/calendar/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: thriXXX WebLaunch (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npWebLaunch.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks™ RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks™ RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Chaz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Game Face Plugin (Enabled) = C:\Users\Chaz\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Chaz\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Lucidchart: Diagramming = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apboafhkiegglekeafbckfjldecefkhn\16_0\
CHR - Extension: Google Drive = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Sumo Paint = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpgjihldbpodlmnjolekemlfbcajnmod\3.7_0\
CHR - Extension: DoNotTrackMe = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd\2.2.8.109_0\
CHR - Extension: Dark atmosphere = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfpikgkkfdoabncoileilaglepbpdhek\1.0_0\
CHR - Extension: Stopwatch = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggnidjbcahhbnleinchgobfnabopeioh\3.6_0\
CHR - Extension: Feedly - Your News, RSS, Google Reader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob\14.0.479_0\
CHR - Extension: Feedly - Your News, RSS, Google Reader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob\14.0.480_0\
CHR - Extension: Crackle = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: RealDownloader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.1_0\
CHR - Extension: telety.pe = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikijikcfedekifbolhamdccnhnlkhfpf\8_0\
CHR - Extension: Disconnect = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo\4.4.0_0\
CHR - Extension: StayFocusd = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji\1.3.10_0\
CHR - Extension: FVD Video Downloader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp\5.0.4_0\
CHR - Extension: Word\u00B2 = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: Google Play Books = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.8_0\
CHR - Extension: Micro Expression Recognition Application = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngkcbihjelakpbponjhpmkkmopghnpip\1.0_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_1\
CHR - Extension: Gmail = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/04/14 13:09:53 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
O4 - HKLM..\Run: [gbrspcontrol] C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
O4 - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelliType Pro] c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [AppVodBurner] C:\Program Files\VodBurner\vodburner.exe ()
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon: AllowMultipleTSSessions = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16D5C419-B39F-442A-B9CF-0558A20254A2}: DhcpNameServer = [removed] [removed] 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{39149679-C7E5-4725-B007-DD4D0FB93D4D}: DhcpNameServer = [removed] [removed] 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/04/14 20:15:21 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Chaz\Desktop\OTL.exe
[2013/04/14 16:31:31 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/04/14 16:30:30 | 000,000,000 | —D | C] – C:\Users\Chaz\Archer.2009.S04E12.Sea.Tunt.Part.1.WEB-DL.XviD.MP3
[2013/04/14 16:27:04 | 000,000,000 | —D | C] – C:\Users\Chaz\Archer.2009.S04E13.Sea.Tunt.Part.2.WEB-DL.x264.AAC
[2013/04/14 15:12:22 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2013/04/14 13:17:08 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Local\temp
[2013/04/14 12:25:06 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/04/14 12:25:06 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/04/14 12:25:06 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/04/14 12:24:11 | 000,000,000 | —D | C] – C:\ComboFix
[2013/04/14 12:17:36 | 000,000,000 | —D | C] – C:\Qoobox
[2013/04/14 12:13:33 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/04/14 12:12:21 | 005,052,676 | R— | C] (Swearware) – C:\Users\Chaz\Desktop\ComboFix.exe
[2013/04/12 11:42:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/04/12 11:37:12 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/04/12 11:36:35 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/04/12 11:36:35 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/04/12 11:36:35 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/04/12 11:15:16 | 000,047,368 | —- | C] (COMODO CA Limited) – C:\Windows\System32\certsentry.dll
[2013/04/12 11:13:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\COMODO
[2013/04/12 00:09:08 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/04/11 23:40:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/04/11 23:40:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2013/04/11 23:40:30 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2013/04/11 23:34:11 | 000,000,000 | —D | C] – C:\Program Files\VodBurner
[2013/04/11 19:43:11 | 000,000,000 | –SD | C] – C:\ProgramData\Shared Space
[2013/04/11 19:38:51 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2013/04/11 19:38:07 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Local\Comodo
[2013/04/11 19:36:45 | 000,000,000 | —D | C] – C:\ProgramData\Comodo Downloader
[2013/04/10 13:20:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
[2013/04/10 11:47:09 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/04/10 11:47:07 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/04/10 11:47:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/04/10 11:47:05 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/04/10 11:47:05 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/04/10 11:47:03 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/04/10 11:47:02 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/04/10 11:47:00 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/04/10 11:29:24 | 002,347,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/04/10 11:29:11 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/04/10 11:29:10 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/04/10 11:28:59 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/04/10 11:28:42 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/04/10 11:28:40 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/04/10 11:16:03 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Roaming\RealNetworks
[2013/04/08 14:27:08 | 000,000,000 | —D | C] – C:\Program Files\RealNetworks
[2013/04/08 14:27:04 | 000,000,000 | —D | C] – C:\ProgramData\RealNetworks
[2013/04/03 16:33:10 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox.bak
[2013/04/02 23:37:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
[2013/04/02 23:21:42 | 000,000,000 | —D | C] – C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
[2013/04/02 23:20:06 | 000,000,000 | —D | C] – C:\Users\Chaz\Desktop\ebook 2
[2013/03/26 07:54:47 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/03/22 15:05:19 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Roaming\GlarySoft
[2013/03/22 14:07:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities
[2013/03/22 14:07:22 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2013/03/19 15:57:19 | 000,000,000 | —D | C] – C:\Users\Chaz\Desktop\Transfer
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/14 20:26:04 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/14 20:15:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Chaz\Desktop\OTL.exe
[2013/04/14 20:09:53 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2013/04/14 19:58:09 | 000,023,248 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/14 19:58:09 | 000,023,248 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/14 19:55:07 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2438872117-3210986945-3872544021-1001UA.job
[2013/04/14 19:50:33 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/14 19:50:24 | 000,000,310 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2013/04/14 19:50:06 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/04/14 19:49:56 | 2212,999,168 | -HS- | M] () – C:\hiberfil.sys
[2013/04/14 16:48:01 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/14 14:09:56 | 000,001,994 | —- | M] () – C:\Users\Chaz\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/14 13:09:53 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/04/14 12:12:32 | 005,052,676 | R— | M] (Swearware) – C:\Users\Chaz\Desktop\ComboFix.exe
[2013/04/12 16:26:34 | 000,000,512 | —- | M] () – C:\Users\Chaz\Desktop\MBR.dat
[2013/04/12 15:44:26 | 335,858,565 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/04/12 15:11:29 | 000,628,554 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/04/12 15:11:29 | 000,108,700 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/04/12 11:36:20 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/04/12 11:36:20 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/04/12 11:36:20 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/04/12 11:36:20 | 000,094,112 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/04/12 11:36:19 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\System32\npdeployJava1.dll
[2013/04/12 11:36:19 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2013/04/12 11:15:16 | 000,047,368 | —- | M] (COMODO CA Limited) – C:\Windows\System32\certsentry.dll
[2013/04/12 11:13:42 | 000,001,892 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/04/11 16:45:16 | 000,007,594 | —- | M] () – C:\Users\Chaz\AppData\Local\Resmon.ResmonCfg
[2013/04/10 12:38:02 | 000,318,944 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/04/05 13:23:59 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2438872117-3210986945-3872544021-1001Core.job
[2013/04/03 19:15:28 | 000,000,316 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForChaz.job
[2013/03/30 17:32:15 | 114,681,267 | —- | M] () – C:\Users\Chaz\Desktop\Archer S04E11 - The Papal Chase.mp4
[2013/03/19 01:04:13 | 003,968,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/03/19 01:04:10 | 003,913,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/03/19 00:48:45 | 000,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/14 12:25:06 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/04/14 12:25:06 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/04/14 12:25:06 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/04/14 12:25:06 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/04/14 12:25:06 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/04/12 16:26:34 | 000,000,512 | —- | C] () – C:\Users\Chaz\Desktop\MBR.dat
[2013/04/12 11:13:42 | 000,001,892 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/04/11 16:45:16 | 000,007,594 | —- | C] () – C:\Users\Chaz\AppData\Local\Resmon.ResmonCfg
[2013/04/03 15:24:31 | 000,000,316 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForChaz.job
[2013/03/30 16:55:49 | 114,681,267 | —- | C] () – C:\Users\Chaz\Desktop\Archer S04E11 - The Papal Chase.mp4
[2013/03/22 14:08:03 | 000,000,310 | —- | C] () – C:\Windows\tasks\GlaryInitialize.job
[2013/01/29 17:29:21 | 000,001,554 | —- | C] () – C:\Users\Chaz\.recently-used.xbel
[2012/04/28 17:37:28 | 001,490,999 | —- | C] () – C:\Windows\System32\tkbtnpn1.dll
[2011/06/25 20:01:21 | 000,819,200 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/06/25 20:01:21 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/08/03 17:41:57 | 000,012,288 | —- | C] () – C:\Users\Chaz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/05/03 04:12:16 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\acccore
[2010/04/14 16:11:58 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Amazon
[2013/04/14 16:34:05 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\BitTorrent
[2012/01/14 17:08:25 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\calibre
[2012/04/24 23:07:48 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Camfrog
[2012/07/18 10:24:25 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\com.focusboosterapp.focusbooster.8E5F79C899747AD22E21DB62AA496926DA6BBC64.1
[2012/09/18 13:29:01 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\CompuClever
[2012/08/28 11:34:22 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Electronic Arts
[2013/03/22 15:05:19 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\GlarySoft
[2013/01/29 17:29:21 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\gtk-2.0
[2010/03/07 15:57:29 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\ImgBurn
[2011/03/12 20:50:30 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Leawo
[2010/07/27 20:32:54 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\ManyCam
[2012/05/22 15:48:30 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Motorola
[2013/04/10 13:23:47 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Octoshape
[2011/05/24 14:32:30 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Pamela
[2011/12/17 14:20:13 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Registry Mechanic
[2011/02/08 18:27:42 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\thriXXX
[2010/08/31 20:01:43 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Trillian
[2012/07/03 19:50:56 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\TrueCrypt
[2010/09/06 23:50:42 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2013/03/06 17:14:20 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Uniblue

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
OTL Extras logfile created on: 4/14/2013 8:17:42 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chaz\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 70.58% Memory free
5.49 Gb Paging File | 4.38 Gb Available in Paging File | 79.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.04 Gb Total Space | 127.91 Gb Free Space | 44.56% Space Free | Partition Type: NTFS
Drive D: | 10.86 Gb Total Space | 1.83 Gb Free Space | 16.83% Space Free | Partition Type: NTFS

Computer Name: CP166 | User Name: Chaz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistUMP] – "C:\Program Files\UMPlayer\umplayer.exe" -add-to-playlist "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithUMP] – "C:\Program Files\UMPlayer\umplayer.exe" -play-dir "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{115605EE-F779-442E-9618-E9318407D48F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{2142A0B8-6200-4768-A15D-8F4AD6C0A95F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{374AE5E2-482D-464C-BFD1-9F4A7376AA74}" = lport=55335 | protocol=6 | dir=in | name=akamai netsession interface |
"{3FA890C6-63E5-4994-9A6E-944753E443CD}" = lport=10243 | protocol=6 | dir=in | app=system |
"{6E646981-D3B3-4441-BD8A-4E2AAD9C9138}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{76CDF850-C588-4902-BD99-272528DD291B}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{8FA191D8-AB4C-4C6D-9A51-A4093D26135B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{96EF7BAA-FC58-4698-ACF8-4ECB65AE9FD6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A6B78F30-9334-4D81-99D5-91A03B130253}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A90A6950-A0E7-475B-92F6-CE5F296FD7AA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ACB99657-1CC5-4F9B-9CEA-E298E2955CEF}" = rport=10243 | protocol=6 | dir=out | app=system |
"{CA47E361-F556-49B1-ADB7-137FFD54DC36}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D0E6D908-0FA9-48E5-AD6E-AAAE624088E8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F3F90812-728D-4A28-9CD5-F0E24C0AF75B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F41E09C2-2C78-41E4-B920-4C010DEEBA9F}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{028D6B26-340D-4DB2-B7DE-F27E45D7FAE7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{04A32D95-FD80-41F2-B303-3DD2ABAAEEE3}" = protocol=6 | dir=in | app=c:\program files\common files\comodo\geekbuddyrsp.exe |
"{09B2141D-AC8B-489A-B5A4-4686E1385082}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{0E96F678-CE77-4A16-9FB0-C2184D7921D3}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{0FADCC6C-DB9E-49E2-B777-E8605F3DB39B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{12C57D95-AC07-411A-82F1-C2E5BE6DB025}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{155B3AD4-B864-4C3D-960B-6AB8E38E7A4C}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{29EC8168-6302-425E-849F-06C6D6275A37}" = protocol=6 | dir=in | app=c:\users\chaz\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{2ADF1262-91F2-4CB3-B901-4E65536350F3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2B203E5D-87B8-4D0A-B219-37EDE8C68FE4}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{2B95C5CE-1ECD-4B00-B026-CAAD99B2ADCD}" = protocol=17 | dir=in | app=c:\program files\common files\comodo\geekbuddyrsp.exe |
"{38E08197-3E43-4572-8143-4E3ABF9699AB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4887580A-FE8D-44DE-9711-02D9D65E985B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{52FE3257-8753-4D76-A4F4-C287E777753A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{58E4C3EC-0E40-4FDE-8B3B-54EA58CE799B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{5DABE86B-D873-4C4D-BAFA-9A41D8D9DDB7}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{5FDEDC64-4343-44AC-A885-737E97F8560A}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{68AAAC4B-9B69-4062-8F50-DE7010B4F6E2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6B351372-9FD8-4CA9-8ACB-1761F50373F0}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{74FFAB44-1522-4067-9256-02C3A0CB5DBC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{7C78A2DA-6665-4E80-AE47-AD9DDDD87DEF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8E37F9DD-10C0-4E57-A818-F0E2FFFF4EE2}" = protocol=6 | dir=in | app=c:\users\chaz\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{990EC465-31C6-45DE-9363-25CF0604CE34}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9A86D484-EDB6-4E68-972B-C0CD540436AE}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{9D708245-E41A-4AA3-A345-6276FE63B148}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{AD8A5FB2-04A5-4FAC-86FB-FC1916FBAF46}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{B1C3F992-BC48-4637-9039-607409757A64}" = protocol=6 | dir=out | app=system |
"{B2BC34CF-8FC6-4C9A-956A-FFF94AE77202}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{B58EF1A3-C043-4107-AC55-A622691D8E23}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B8DEA581-F21A-40CD-9B09-9CE0BFB95516}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{BC270A7A-7C17-40A7-9CD4-717F7BEDA483}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{C9651256-3998-4692-B214-E54BA662193B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{C9F803BB-EF1E-46DB-947E-BDBDD967A2E5}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{CB24522D-D763-429D-B6D3-F356B2E94C7A}" = protocol=17 | dir=in | app=c:\users\chaz\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{D6586EC1-77FB-4CAC-93D9-DB11D7335123}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{D8A41F1D-F5AC-43D4-8F6A-F57D5054688B}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{DBB704DF-D7DC-4430-9ED7-7732C16EE6C7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{DEBB0023-9925-4209-A950-323424A3F21C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{EA913291-CC3D-4D4B-8661-79C04B1D312F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EB744400-43B5-4E9D-978F-F03879611109}" = protocol=17 | dir=in | app=c:\users\chaz\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{EC1F6B67-FE0F-49E3-9F14-8C32829A5C71}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{EC7616DC-54C0-44F6-8574-9C5EE63D35F6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{EE4C4E16-E4D3-4244-9C1D-003BDF99D844}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{EE54E6F1-9E21-4530-837A-161F569FFF51}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe |
"{EF9FCE47-5872-45D1-81A1-7B3E2F827053}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{F4AA88E2-3A82-4B86-BBEE-3D441155B373}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{F5DE2FEF-8699-4BAF-BDFE-179999AC78BD}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{F7B430D9-BFBF-45D4-B8D4-3064113212BA}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{FB84F117-84DC-45E2-A45A-5BD689F05758}" = protocol=17 | dir=in | app=c:\users\chaz\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{FCC30BF5-30F5-4BB2-8CC3-4F6BBCC9A43D}" = protocol=6 | dir=in | app=c:\users\chaz\appdata\local\google\google talk plugin\googletalkplugin.exe |
"TCP Query User{0A2A8CAF-9548-4956-8468-2084D27010CA}C:\program files\camfrog\camfrog video chat\camfrog video chat.exe" = protocol=6 | dir=in | app=c:\program files\camfrog\camfrog video chat\camfrog video chat.exe |
"TCP Query User{1DFCC7AC-EC1F-4765-B053-4454F87C5D20}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{1E2BAF6A-83E0-4C59-AA4D-EA21309E7236}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{5D3BE7C8-ABFB-49C1-8730-4E047BD8F7F3}C:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe |
"TCP Query User{62180375-3454-4397-85BF-381A6985F70A}C:\program files\camfrog\camfrog video chat\camfrog video chat.exe" = protocol=6 | dir=in | app=c:\program files\camfrog\camfrog video chat\camfrog video chat.exe |
"TCP Query User{7A984421-8017-43E8-921F-4D689D15A483}C:\users\chaz\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\chaz\appdata\local\google\chrome\application\chrome.exe |
"TCP Query User{7EC18BC0-8239-47C0-954D-9AD754916979}C:\program files\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"TCP Query User{80FD727D-F7D6-4EB5-9644-F26F84F37435}C:\program files\trillian\trillian.exe" = protocol=6 | dir=in | app=c:\program files\trillian\trillian.exe |
"TCP Query User{9A1AB1D9-F69C-4518-B030-E85DEA83EEB4}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{A26906DF-68CB-4D76-A2AA-96F74E04D842}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{B8076DC9-5841-4A92-A239-A17CAD47526B}C:\program files\trillian\trillian.exe" = protocol=6 | dir=in | app=c:\program files\trillian\trillian.exe |
"TCP Query User{CA096327-4927-41CB-ABA9-77471F49976C}C:\users\chaz\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\chaz\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"TCP Query User{D0CD8F82-760A-44B9-BEA9-559B56DFEAE0}C:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe |
"TCP Query User{E294B3C0-249C-4A92-9FB4-FFD4492129AE}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{07BE5853-B45D-4CC2-ABE9-C75108F36550}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{16853E35-3866-44C5-9F12-015EC6CA08BE}C:\program files\camfrog\camfrog video chat\camfrog video chat.exe" = protocol=17 | dir=in | app=c:\program files\camfrog\camfrog video chat\camfrog video chat.exe |
"UDP Query User{1B88F3D0-E5DE-404E-BD1A-909878896BF2}C:\users\chaz\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\chaz\appdata\local\google\chrome\application\chrome.exe |
"UDP Query User{434F3BC5-6694-42A3-96AE-8F7332FBF92F}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{5A476E59-B896-4B11-A2F1-E9FFCE8025A2}C:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe |
"UDP Query User{5BFA75A9-F321-4746-894B-5B579F4AC36A}C:\program files\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"UDP Query User{629166B8-182B-4B95-B866-10066E1617D7}C:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\hewlett-packard\hp quicksync\jre\bin\javaw.exe |
"UDP Query User{6B0BB7EB-7725-4145-A947-09CE57FBF123}C:\users\chaz\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\chaz\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"UDP Query User{72BC3430-BD3E-4404-9498-AB0E52FDC89F}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{A11665B1-AA2D-472E-95C7-B7C1E355C8A9}C:\program files\trillian\trillian.exe" = protocol=17 | dir=in | app=c:\program files\trillian\trillian.exe |
"UDP Query User{ADC2D31A-8E2E-4F28-ADB4-5B5222347BFE}C:\program files\camfrog\camfrog video chat\camfrog video chat.exe" = protocol=17 | dir=in | app=c:\program files\camfrog\camfrog video chat\camfrog video chat.exe |
"UDP Query User{CAD0185D-BCE4-43C4-B47F-D3FE5345E370}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{E5AE4862-EB2D-4916-BB1D-F99A052DC2AF}C:\program files\trillian\trillian.exe" = protocol=17 | dir=in | app=c:\program files\trillian\trillian.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06ED8674-1191-5DF4-88E9-5732C927ADF7}" = focus booster
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0ABBF310-94E4-4AE8-A6BD-10345A3F6439}" = Google Drive
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34985F59-8F6F-46F4-9AD5-53E2714294D2}" = ArcSoft WebCam Companion 3
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3598D33E-AF4E-4423-ABDD-9EA32D03D3DC}" = ArcSoft TotalMedia
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{42E2EEB2-D48E-4A47-B181-32ECA031D93B}" = DJ_AIO_06_F2400_SW_Min
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5AF4B3C4-C393-48D7-AC7E-8E7615579548}" = Adobe AIR
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{656957B8-41DB-4E43-AAA1-B128C2213D50}" = VodBurner
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BAA71B6-8F43-4C72-931A-3354ABB0258A}" = F2400
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6C12B6BF-3891-497B-B5CA-3D64DA093947}" = Motorola Mobile Drivers Installation 5.4.0
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74F3FA7F-233B-47DF-A0E0-28520D03B992}" = HP User Guides 0150
"{759142E8-25B0-42AE-B408-4215065D3F4B}" = Windows Live Family Safety
"{76EA46DB-14BD-43CB-92CD-F25CE66D5279}" = calibre
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84374A47-1DF5-4013-90D4-1288819869B1}" = Microsoft Mouse and Keyboard Center
"{870815CA-6B60-47B6-88DD-A67F42D2F03E}" = GPL MPEG-1/2 DirectShow Decoder Filter
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{986E4BDF-EFF6-463E-BB7E-738F448CB2C0}" = GeekBuddy
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A7DA4247-9F22-4d4a-974A-DD455CCF43B6}" = COMODO System Utilities
"{A8C3083C-A1C1-4248-B0E2-14A7D9F2E9EF}" = BCL easyConverter SDK 1.0.0 Module
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9CE0266-6801-3B33-94AD-00520085CF4B}" = Google Talk Plugin
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{AFE499B5-FCC4-45E6-A1A5-3C51AE0E539B}" = Mobipocket Creator 4.2
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 310.70
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{BCC0552D-76C0-4130-BFBD-49BE49ACC594}" = COMODO Internet Security
"{BCF16F16-AC0E-4ABE-A9EF-412CF484BA51}" = Windows Live Family Safety
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C65AA5AE-8B80-46B6-ADFC-BBF1EFF2AD98}_is1" = EPUB to MOBI
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{CA503A7B-10B3-474E-9F73-719D2C66953D}" = 3D SexVilla CRACK (oxin)
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CE246151-F0E8-ABC8-AEB2-7F3E188EFBF5}" = TweetDeck
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CECB5CA0-6908-45EA-B18E-64C61B11DA99}" = Family Tree Maker 2008
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{DBB1F4ED-3212-4F58-A427-9C01DE4A24A5}_is1" = Uniblue SystemTweaker
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}" = RealDownloader
"{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}" = Microsoft WSE 3.0
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{EEA95E6C-6847-49BE-83C9-ED92D8E18983}" = HP QuickSync
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 9.20
"AC3Filter_is1" = AC3Filter 1.63b
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"BitTorrent" = BitTorrent
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"Camfrog 6.2" = Camfrog Video Chat 6.2
"CCleaner" = CCleaner
"com.focusboosterapp.focusbooster.8E5F79C899747AD22E21DB62AA496926DA6BBC64.1" = focus booster
"Comodo Dragon" = Comodo Dragon
"DivX Setup" = DivX Setup
"Flash Favorite_is1" = Flash Favorite 2.0
"Glary Utilities_is1" = Glary Utilities 2.54.0.1759
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ImgBurn" = ImgBurn
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"InstallShield_{CECB5CA0-6908-45EA-B18E-64C61B11DA99}" = Family Tree Maker 2008
"jZip" = jZip
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"ManyCam" = ManyCam 2.5.48 (remove only)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
"MKV Minimum Set (LD-Anime) - MatroskaSplitter & VSFilter_is1" = Matroska Pack - Lazy Man's MKV 0.9.9
"MotoHelper" = MotoHelper 2.1.32 Driver 5.4.0
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"ScreenRecorder" = Bulent's Screen Recorder
"SendToKindle" = Amazon Send to Kindle
"SPG MP3 Recorder_is1" = SPG MP3 Recorder 1.0
"STDU Viewer_is1" = STDU Viewer version 1.5.597.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Trillian" = Trillian
"TrueCrypt" = TrueCrypt
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"UMPlayer" = UMPlayer 0.98 [P4]
"Veetle TV" = Veetle TV 0.9.18
"vShare" = vShare Plugin
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite" = Windows Live Essentials
"XnView_is1" = XnView 1.97.8
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"EA SPORTS Game Face Browser Plugin" = EA SPORTS Game Face Browser Plugin [removed]
"Google Chrome" = Google Chrome
"UnityWebPlayer" = Unity Web Player
"WinDirStat" = WinDirStat 1.1.2

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/11/2013 4:47:22 PM | Computer Name = cp166 | Source = Application Hang | ID = 1002
Description = The program HiJackThis.exe version 2.0.0.4 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 7ec Start
Time: 01ce36f4cb25a870 Termination Time: 0 Application Path: C:\Users\Chaz\Downloads\HiJackThis.exe

Report
Id: f4e30031-a2e8-11e2-938a-00268238b60d

Error - 4/11/2013 7:22:43 PM | Computer Name = cp166 | Source = Application Hang | ID = 1002
Description = The program HiJackThis.exe version 2.0.0.4 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1794 Start
Time: 01ce370afb77ad00 Termination Time: 94 Application Path: C:\Users\Chaz\Downloads\HiJackThis.exe

Report
Id: 8dfe6ab1-a2fe-11e2-84bf-00269eb70d06

Error - 4/11/2013 7:29:46 PM | Computer Name = cp166 | Source = Application Hang | ID = 1002
Description = The program HiJackThis.exe version 2.0.0.4 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1554 Start
Time: 01ce370c242087d0 Termination Time: 0 Application Path: C:\Users\Chaz\Downloads\HiJackThis.exe

Report
Id: a1ac9ae1-a2ff-11e2-8a22-88840198cc2d

Error - 4/11/2013 7:29:56 PM | Computer Name = cp166 | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 4/11/2013 7:29:56 PM | Computer Name = cp166 | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 4/11/2013 7:29:56 PM | Computer Name = cp166 | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 4/11/2013 8:02:05 PM | Computer Name = cp166 | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 4/11/2013 8:02:05 PM | Computer Name = cp166 | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 4/11/2013 11:31:43 PM | Computer Name = cp166 | Source = MsiInstaller | ID = 11706
Description =

Error - 4/14/2013 12:26:39 PM | Computer Name = cp166 | Source = System Restore | ID = 8193
Description =

[ Hewlett-Packard Events ]
Error - 11/12/2012 4:16:45 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 11/19/2012 4:55:46 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 1/7/2013 4:58:47 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 1/14/2013 4:38:34 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 2/11/2013 4:29:53 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 2/28/2013 12:01:08 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 3/11/2013 5:42:50 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 3/18/2013 4:45:49 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 3/25/2013 3:06:45 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 4/1/2013 3:15:13 PM | Computer Name = cp166 | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files\Hewlett-Packard\HP Support
Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options) at
System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

[ HP Software Framework Events ]
Error - 4/2/2013 11:46:35 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:34.839|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

Error - 4/2/2013 11:46:35 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:35.448|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

Error - 4/2/2013 11:46:35 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:35.807|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

Error - 4/2/2013 11:46:35 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:35.916|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

Error - 4/2/2013 11:46:36 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:36.009|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

Error - 4/2/2013 11:46:36 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:36.072|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

Error - 4/2/2013 11:46:36 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:36.134|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

Error - 4/2/2013 11:46:36 PM | Computer Name = cp166 | Source = CaslSmBios | ID = 5
Description = 2013/04/02 23:46:36.181|0000053C|Error |[CaslWmi]CommandDiags::C{bool()}|Error,
eRet: e_BIOS_INVALID_COMMAND_TYPE

[ Media Center Events ]
Error - 12/14/2010 11:58:04 AM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 10:58:04 AM - Failed to retrieve SportsSchedule (Error: The remote
name could not be resolved: 'data.tvdownload.microsoft.com')

Error - 12/14/2010 11:58:04 AM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 10:58:04 AM - Failed to retrieve SportsV2 (Error: The remote name
could not be resolved: 'data.tvdownload.microsoft.com')

Error - 12/14/2010 11:58:04 AM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 10:58:04 AM - Failed to retrieve Broadband (Error: The remote name
could not be resolved: 'data.tvdownload.microsoft.com')

Error - 12/14/2010 12:58:26 PM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 11:58:23 AM - Error connecting to the internet. 11:58:23 AM - Unable
to contact server..

Error - 12/16/2010 10:36:03 AM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 9:34:54 AM - Error connecting to the internet. 9:34:54 AM - Unable
to contact server..

Error - 12/16/2010 11:36:12 AM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 10:36:10 AM - Error connecting to the internet. 10:36:10 AM - Unable
to contact server..

Error - 12/16/2010 12:38:09 PM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 11:38:06 AM - Error connecting to the internet. 11:38:06 AM - Unable
to contact server..

Error - 12/16/2010 1:38:19 PM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 12:38:17 PM - Error connecting to the internet. 12:38:17 PM - Unable
to contact server..

Error - 12/17/2010 10:54:17 AM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 9:54:17 AM - Error connecting to the internet. 9:54:17 AM - Unable
to contact server..

Error - 12/17/2010 10:54:52 AM | Computer Name = cp166 | Source = MCUpdate | ID = 0
Description = 9:54:46 AM - Error connecting to the internet. 9:54:46 AM - Unable
to contact server..

[ System Events ]
Error - 4/12/2013 3:44:59 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 4/14/2013 12:05:11 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7001
Description = The Windows Image Acquisition (WIA) service depends on the Shell Hardware
Detection service which failed to start because of the following error: %%1058

Error - 4/14/2013 12:05:18 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 4/14/2013 12:33:44 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 4/14/2013 12:54:27 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 4/14/2013 1:10:06 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 4/14/2013 3:16:06 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7034
Description = The COMODO Internet Security Helper Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 4/14/2013 3:16:16 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7034
Description = The COMODO System Utilities Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 4/14/2013 7:50:32 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7001
Description = The Windows Image Acquisition (WIA) service depends on the Shell Hardware
Detection service which failed to start because of the following error: %%1058

Error - 4/14/2013 7:50:40 PM | Computer Name = cp166 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom


< End of report >
Hi,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\SearchScopes\{1C9B8834-03E4-463C-8489-41216564E9C6}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
    IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolbarhome.com/search.aspx?…s}&srch;=dsp
    IE - HKCU\..\SearchScopes\{1C9B8834-03E4-463C-8489-41216564E9C6}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 192.168.*.*
    FF - HKLM\Software\MozillaPlugins\@thrixxx.com/WebLaunch: C:\Program Files\thriXXX\WebLaunch\Binaries\npWebLaunch.dll File not found
    FF - HKCU\Software\MozillaPlugins\@thrixxx.com/WebLaunch: C:\Program Files\thriXXX\WebLaunch\Binaries\npWebLaunch.dll File not found
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AutocompletePro\[removed]
    [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
    [2010/08/03 17:41:57 | 000,012,288 | —- | C] () – C:\Users\Chaz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/02/08 18:27:42 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\thriXXX
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Post the new OTL log and let me know how your system is running now. :)
OTL logfile created on: 4/14/2013 9:50:25 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chaz\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 50.87% Memory free
5.49 Gb Paging File | 3.78 Gb Available in Paging File | 68.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.04 Gb Total Space | 128.17 Gb Free Space | 44.65% Space Free | Partition Type: NTFS
Drive D: | 10.86 Gb Total Space | 1.83 Gb Free Space | 16.83% Space Free | Partition Type: NTFS

Computer Name: CP166 | User Name: Chaz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Chaz\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\COMODO\GeekBuddy\unit_manager.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\COMODO\GeekBuddy\unit.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\Common Files\COMODO\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\COMODO\Dragon\dragon_updater.exe ()
PRC - C:\Users\Chaz\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cis.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (COMODO)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\COMODO\COMODO System Utilities\CSU_CLI.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe (Comodo Security Solutions, Inc.)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll ()
MOD - C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\libglesv2.dll ()
MOD - C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\libegl.dll ()
MOD - C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()


========== Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (CLPSLauncher) – C:\Program Files\Common Files\COMODO\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (DragonUpdater) – C:\Program Files\COMODO\Dragon\dragon_updater.exe ()
SRV - (GeekBuddyRSP) – C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (cmdvirth) – C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (COMODO)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (HP Support Assistant Service) – C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_d5cfa0b8f21ea198\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (CSUService) – C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe (Comodo Security Solutions, Inc.)
SRV - (MotoHelper) – C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (USBCCID) – system32\DRIVERS\RtsUCcid.sys File not found
DRV - (RtsUIR) – system32\DRIVERS\Rts516xIR.sys File not found
DRV - (catchme) – C:\Users\Chaz\AppData\Local\Temp\catchme.sys File not found
DRV - (cmdGuard) – C:\Windows\System32\drivers\cmdguard.sys (COMODO)
DRV - (cmderd) – C:\Windows\System32\drivers\cmderd.sys (COMODO)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (iusb3hcs) – C:\Windows\System32\drivers\iusb3hcs.sys (Intel Corporation)
DRV - (pmkbdfltr) – C:\Windows\System32\drivers\pmkbdfltr.sys (PenMount)
DRV - (CFRMD) – C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (truecrypt) – C:\Windows\System32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVNET) – C:\Windows\System32\drivers\nvmf6232.sys (NVIDIA Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (archlp) – C:\Windows\System32\drivers\ArcHlp.sys ()
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\..\SearchScopes,DefaultScope = {04E00A45-571F-44F6-9584-214FCD2768C4}
IE - HKLM\..\SearchScopes\{04E00A45-571F-44F6-9584-214FCD2768C4}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://us.yahoo.com?fr=fp-comodo
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKCU\..\SearchScopes\{04E00A45-571F-44F6-9584-214FCD2768C4}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{112A7E09-6595-D1C3-2C4E-CDFD9E56B66C}: "URL" = http://bing.zugo.com/s/?q={searchTerms}&am;…fg=2-76-0-16Mj6
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTe…mp;fr=chr-i3752
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;192.168.*.*

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-comodo"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://us.yahoo.com?fr=fp-comodo"
FF - prefs.js..extensions.enabledAddons: amznUWL%40amazon.com:2.17
FF - prefs.js..extensions.enabledAddons: support%40ancestry.com:1.0.0.1
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:2.5.9.20130409112616
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: {8545daff-ad1e-493f-a37e-eed1ac79682b}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: [removed]:2.12
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {7BA52691-1876-45ce-9EE6-54BCB3B04BBC}:3.7.2
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: {ccc4ed03-bc79-16e0-71c8-c70e7a75ab9e}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: [removed]:1.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Chaz\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Chaz\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Chaz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\Chaz\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/20 21:26:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/04/08 14:27:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2013/01/04 13:01:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/08/13 12:52:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/04/08 14:27:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 00:09:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/12 00:09:13 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/20 21:26:28 | 000,000,000 | —D | M]

[2010/01/09 16:56:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Chaz\AppData\Roaming\Mozilla\Extensions
[2010/01/09 16:56:43 | 000,000,000 | —D | M] (No name found) – C:\Users\Chaz\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2013/04/10 13:21:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions
[2013/04/10 13:21:18 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/03/05 17:12:23 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/03/17 08:37:20 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\[removed]
[2012/10/17 04:24:26 | 000,257,103 | —- | M] () (No name found) – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\extensions\[removed]
[2010/05/14 01:53:20 | 000,001,836 | —- | M] () – C:\Users\Chaz\AppData\Roaming\Mozilla\Firefox\Profiles\be6x5764.default\searchplugins\bing-ff.xml
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/04/12 00:09:24 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/04/12 00:09:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/04/12 00:09:10 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{ccc4ed03-bc79-16e0-71c8-c70e7a75ab9e}
[2013/04/12 00:09:24 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/10 11:21:08 | 000,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2013/02/15 18:31:23 | 000,186,432 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2012/10/13 20:29:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2012/10/13 20:29:33 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2012/10/13 20:29:34 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2012/10/13 20:29:34 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2012/10/13 20:29:35 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2012/10/13 20:29:36 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2012/10/13 20:29:37 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2006/08/09 06:16:08 | 000,030,408 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npWebLaunch.dll
[2013/04/03 16:33:40 | 000,001,607 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2013/04/03 16:33:40 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/03 16:33:40 | 000,001,453 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2013/04/03 16:33:40 | 000,002,669 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2013/04/12 00:09:23 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2013/04/03 16:33:39 | 000,001,391 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2013/04/03 16:33:39 | 000,001,309 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com/calendar/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Chaz\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: thriXXX WebLaunch (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npWebLaunch.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Chaz\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks™ RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks™ RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Chaz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Game Face Plugin (Enabled) = C:\Users\Chaz\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Chaz\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Lucidchart: Diagramming = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apboafhkiegglekeafbckfjldecefkhn\16_0\
CHR - Extension: Google Drive = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Sumo Paint = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpgjihldbpodlmnjolekemlfbcajnmod\3.7_0\
CHR - Extension: DoNotTrackMe = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd\2.2.8.109_0\
CHR - Extension: Dark atmosphere = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfpikgkkfdoabncoileilaglepbpdhek\1.0_0\
CHR - Extension: Stopwatch = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggnidjbcahhbnleinchgobfnabopeioh\3.6_0\
CHR - Extension: Feedly - Your News, RSS, Google Reader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob\14.0.480_0\
CHR - Extension: Feedly - Your News, RSS, Google Reader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipbfijinpcgfogaopmgehiegacbhmob\14.0.481_0\
CHR - Extension: Crackle = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: RealDownloader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.1_0\
CHR - Extension: telety.pe = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikijikcfedekifbolhamdccnhnlkhfpf\8_0\
CHR - Extension: Disconnect = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo\4.4.0_0\
CHR - Extension: StayFocusd = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji\1.3.10_0\
CHR - Extension: FVD Video Downloader = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp\5.0.4_0\
CHR - Extension: Word\u00B2 = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: Google Play Books = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.8_0\
CHR - Extension: Micro Expression Recognition Application = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngkcbihjelakpbponjhpmkkmopghnpip\1.0_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_1\
CHR - Extension: Gmail = C:\Users\Chaz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/04/14 13:09:53 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hp\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
O4 - HKLM..\Run: [gbrspcontrol] C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
O4 - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelliType Pro] c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard)
O4 - HKCU..\Run: [AppVodBurner] C:\Program Files\VodBurner\vodburner.exe ()
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - Startup: C:\Users\Chaz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Chaz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon: AllowMultipleTSSessions = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hp\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16D5C419-B39F-442A-B9CF-0558A20254A2}: DhcpNameServer = [removed] [removed] 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{39149679-C7E5-4725-B007-DD4D0FB93D4D}: DhcpNameServer = [removed] [removed] 192.168.1.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/04/14 21:10:00 | 000,000,000 | —D | C] – C:\_OTL
[2013/04/14 21:08:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2013/04/14 21:08:52 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2013/04/14 20:51:25 | 000,000,000 | —D | C] – C:\Users\Chaz\Desktop\Computer reports
[2013/04/14 20:15:21 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Chaz\Desktop\OTL.exe
[2013/04/14 16:31:31 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/04/14 16:30:30 | 000,000,000 | —D | C] – C:\Users\Chaz\Archer.2009.S04E12.Sea.Tunt.Part.1.WEB-DL.XviD.MP3
[2013/04/14 16:27:04 | 000,000,000 | —D | C] – C:\Users\Chaz\Archer.2009.S04E13.Sea.Tunt.Part.2.WEB-DL.x264.AAC
[2013/04/14 15:12:22 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2013/04/14 13:17:08 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Local\temp
[2013/04/14 12:25:06 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/04/14 12:25:06 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/04/14 12:25:06 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/04/14 12:24:11 | 000,000,000 | —D | C] – C:\ComboFix
[2013/04/14 12:17:36 | 000,000,000 | —D | C] – C:\Qoobox
[2013/04/14 12:13:33 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/04/14 12:12:21 | 005,052,676 | R— | C] (Swearware) – C:\Users\Chaz\Desktop\ComboFix.exe
[2013/04/12 11:42:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/04/12 11:37:12 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/04/12 11:36:35 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/04/12 11:36:35 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/04/12 11:36:35 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/04/12 11:15:16 | 000,047,368 | —- | C] (COMODO CA Limited) – C:\Windows\System32\certsentry.dll
[2013/04/12 11:13:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\COMODO
[2013/04/12 00:09:08 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/04/11 23:40:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/04/11 23:40:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2013/04/11 23:40:30 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2013/04/11 23:34:11 | 000,000,000 | —D | C] – C:\Program Files\VodBurner
[2013/04/11 19:43:11 | 000,000,000 | –SD | C] – C:\ProgramData\Shared Space
[2013/04/11 19:38:51 | 000,000,000 | —D | C] – C:\ProgramData\COMODO
[2013/04/11 19:38:07 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Local\Comodo
[2013/04/11 19:36:45 | 000,000,000 | —D | C] – C:\ProgramData\Comodo Downloader
[2013/04/10 13:20:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
[2013/04/10 11:47:09 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/04/10 11:47:07 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/04/10 11:47:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/04/10 11:47:05 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/04/10 11:47:05 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/04/10 11:47:03 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/04/10 11:47:02 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/04/10 11:47:00 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/04/10 11:29:24 | 002,347,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/04/10 11:29:11 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/04/10 11:29:10 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/04/10 11:28:59 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/04/10 11:28:42 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2013/04/10 11:28:40 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2013/04/10 11:16:03 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Roaming\RealNetworks
[2013/04/08 14:27:08 | 000,000,000 | —D | C] – C:\Program Files\RealNetworks
[2013/04/08 14:27:04 | 000,000,000 | —D | C] – C:\ProgramData\RealNetworks
[2013/04/03 16:33:10 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox.bak
[2013/04/02 23:37:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
[2013/04/02 23:21:42 | 000,000,000 | —D | C] – C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
[2013/04/02 23:20:06 | 000,000,000 | —D | C] – C:\Users\Chaz\Desktop\ebook 2
[2013/03/26 07:54:47 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2013/03/22 15:05:19 | 000,000,000 | —D | C] – C:\Users\Chaz\AppData\Roaming\GlarySoft
[2013/03/22 14:07:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities
[2013/03/22 14:07:22 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2013/03/19 15:57:19 | 000,000,000 | —D | C] – C:\Users\Chaz\Desktop\Transfer

========== Files - Modified Within 30 Days ==========

[2013/04/14 22:02:48 | 001,474,832 | —- | M] () – C:\Windows\System32\drivers\sfi.dat
[2013/04/14 21:55:01 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2438872117-3210986945-3872544021-1001UA.job
[2013/04/14 21:48:01 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/14 21:26:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/14 21:21:32 | 000,023,248 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/14 21:21:32 | 000,023,248 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/14 21:13:13 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/14 21:13:11 | 000,000,310 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2013/04/14 21:12:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/04/14 21:12:51 | 2212,999,168 | -HS- | M] () – C:\hiberfil.sys
[2013/04/14 21:09:12 | 000,001,038 | —- | M] () – C:\Users\Chaz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2013/04/14 21:08:52 | 000,000,858 | —- | M] () – C:\Users\Chaz\Desktop\NTREGOPT.lnk
[2013/04/14 21:08:52 | 000,000,839 | —- | M] () – C:\Users\Chaz\Desktop\ERUNT.lnk
[2013/04/14 20:15:47 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Chaz\Desktop\OTL.exe
[2013/04/14 14:09:56 | 000,001,994 | —- | M] () – C:\Users\Chaz\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/14 13:09:53 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/04/14 12:12:32 | 005,052,676 | R— | M] (Swearware) – C:\Users\Chaz\Desktop\ComboFix.exe
[2013/04/12 15:44:26 | 335,858,565 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/04/12 15:11:29 | 000,628,554 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/04/12 15:11:29 | 000,108,700 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/04/12 11:36:20 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/04/12 11:36:20 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/04/12 11:36:20 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/04/12 11:36:20 | 000,094,112 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/04/12 11:36:19 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\System32\npdeployJava1.dll
[2013/04/12 11:36:19 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2013/04/12 11:15:16 | 000,047,368 | —- | M] (COMODO CA Limited) – C:\Windows\System32\certsentry.dll
[2013/04/12 11:13:42 | 000,001,892 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/04/11 16:45:16 | 000,007,594 | —- | M] () – C:\Users\Chaz\AppData\Local\Resmon.ResmonCfg
[2013/04/10 12:38:02 | 000,318,944 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/04/05 13:23:59 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2438872117-3210986945-3872544021-1001Core.job
[2013/04/03 19:15:28 | 000,000,316 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForChaz.job
[2013/03/19 01:04:13 | 003,968,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/03/19 01:04:10 | 003,913,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/03/19 00:48:45 | 000,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll

========== Files Created - No Company Name ==========

[2013/04/14 21:09:12 | 000,001,038 | —- | C] () – C:\Users\Chaz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2013/04/14 21:08:52 | 000,000,858 | —- | C] () – C:\Users\Chaz\Desktop\NTREGOPT.lnk
[2013/04/14 21:08:52 | 000,000,839 | —- | C] () – C:\Users\Chaz\Desktop\ERUNT.lnk
[2013/04/14 12:25:06 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/04/14 12:25:06 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/04/14 12:25:06 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/04/14 12:25:06 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/04/14 12:25:06 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/04/12 11:13:42 | 000,001,892 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2013/04/11 16:45:16 | 000,007,594 | —- | C] () – C:\Users\Chaz\AppData\Local\Resmon.ResmonCfg
[2013/04/03 15:24:31 | 000,000,316 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForChaz.job
[2013/03/22 14:08:03 | 000,000,310 | —- | C] () – C:\Windows\tasks\GlaryInitialize.job
[2013/01/29 17:29:21 | 000,001,554 | —- | C] () – C:\Users\Chaz\.recently-used.xbel
[2012/04/28 17:37:28 | 001,490,999 | —- | C] () – C:\Windows\System32\tkbtnpn1.dll
[2011/06/25 20:01:21 | 000,819,200 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/06/25 20:01:21 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2010/05/03 04:12:16 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\acccore
[2010/04/14 16:11:58 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Amazon
[2013/04/14 16:34:05 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\BitTorrent
[2012/01/14 17:08:25 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\calibre
[2012/04/24 23:07:48 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Camfrog
[2012/07/18 10:24:25 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\com.focusboosterapp.focusbooster.8E5F79C899747AD22E21DB62AA496926DA6BBC64.1
[2012/09/18 13:29:01 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\CompuClever
[2012/08/28 11:34:22 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Electronic Arts
[2013/03/22 15:05:19 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\GlarySoft
[2013/01/29 17:29:21 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\gtk-2.0
[2010/03/07 15:57:29 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\ImgBurn
[2011/03/12 20:50:30 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Leawo
[2010/07/27 20:32:54 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\ManyCam
[2012/05/22 15:48:30 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Motorola
[2013/04/10 13:23:47 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Octoshape
[2011/05/24 14:32:30 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Pamela
[2011/12/17 14:20:13 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Registry Mechanic
[2010/08/31 20:01:43 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Trillian
[2012/07/03 19:50:56 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\TrueCrypt
[2010/09/06 23:50:42 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2013/03/06 17:14:20 | 000,000,000 | —D | M] – C:\Users\Chaz\AppData\Roaming\Uniblue

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
Much better - thanks!! I did want to ask what I could delete from the HijackThis list that's causing a lot of programs I don't necessarily need to open during startup. I don't want the Geekbuddy, Google Drive, VoDburner, iTunes updater, or all that carp** to start unless I direct it to.

Much better - thanks!!

Great!!

I did want to ask what I could delete from the HijackThis list that's causing a lot of programs I don't necessarily need to open during startup. I don't want the Geekbuddy, Google Drive, VoDburner, iTunes updater, or all that carp** to start unless I direct it to.

We can work with that when we finish up checking for malware…don't let me forget. :)
———–

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI